Bitcoin Forum
August 08, 2026, 10:39:00 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Coldcard users have lost Bitcoin despite doing everything correctly.  (Read 47 times)
Primark (OP)
Member
**
Offline

Activity: 126
Merit: 50


View Profile
Today at 10:47:10 AM
 #1

We often say something when we discuss, "Not your keys, not your coins". And accepting this, we consider it good practice to move our Bitcoin assets from the exchange to a hardware wallet, keep the seed phrase offline, and keep our assets safe at our own risk. But you are aware of the recent Coldcard incident, right?

After this Coldcard incident, I am thinking about an uncomfortable question. Suppose, we who are users are fulfilling our responsibilities properly, but if there is a flaw in the system on which we rely to fulfill that responsibility, then who is responsible for this loss?

We do not just store Bitcoin, but at the same time, these Bitcoins contain our patience, hard work, dreams, and future security. Even after fulfilling our responsibilities properly, when our wallet is stolen, we will almost break down. Then, should we actually blame our decision, why did we start storing Bitcoin?

I read in Coldcard's own instructions that seed words, passphrases, PINs, and private keys should be kept secret and backups should be stored securely. But even if we users take proper care of our own security, most of us users cannot verify any errors within the system.
Doan9269
Hero Member
*****
Offline

Activity: 1694
Merit: 849



View Profile
Today at 01:00:08 PM
 #2

Unfortunately, they had to use Coldcard in this regard for their hardware wallet. Had Trezor or another reputable hardware wallet been considered for use, perhaps they wouldn't have been vulnerable in the same way. Still, everything stands to be a risk for every investor to consider when making a decision and trying to use a particular storage for their assets; this is not a reason to conclude that there is no safety in a non-custodial wallet, but only an eye-opener that everyone should consider their extra efforts in making additional security measures over our wallet.

Hypnotizer
Full Member
***
Offline

Activity: 350
Merit: 223



View Profile
Today at 03:47:37 PM
 #3

We often say something when we discuss, "Not your keys, not your coins". And accepting this, we consider it good practice to move our Bitcoin assets from the exchange to a hardware wallet, keep the seed phrase offline, and keep our assets safe at our own risk. But you are aware of the recent Coldcard incident, right?

The ColdCard incident has greatly increased my understanding about bitcoin security and the responsibility that comes with being your own bank more. Because buying a reputable Hardware wallet doesn’t instantly make you secured, there’s a lot to this security things like using additional security layers like passphrase or using Multisig.

Quote from: Primark
After this Coldcard incident, I am thinking about an uncomfortable question. Suppose, we who are users are fulfilling our responsibilities properly, but if there is a flaw in the system on which we rely to fulfill that responsibility, then who is responsible for this loss?

Well that’s why you don’t just trust in this space, because the flaws are from the RNG of the hardware wallet's firmware, even though we can’t really blame the users but they could have avoided this by using a truly random seed generator or even an additional random passphrase or by using Multisig.

Just as the case with this guy from Reddit..



ColdCard is responsible for this exploit because they failed to identify this issue since 2021, that's almost five years.


coinlary
Sr. Member
****
Offline

Activity: 742
Merit: 277


Make decisions without looking back


View Profile
Today at 07:47:19 PM
 #4

You're just.beign paranoid  now . Yeah,  there's  need to be careful, but that doesn't  mean every wallet  has same vulnerabilities and just I've mentioned in a similar thread that "compromised entropy is probably one of the worst things that can happen to a wallet." , consider adding your  own security and you will be just  fine.

Wallet does not log seed nor communicate your seed/other  to some sort of controlled server. Even if they have something hidden, you can easily neutralized it by using a cold storage setup.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!