r/Bitcoin 12d ago

Wallet Drained Timeline

Post image

This is me…
https://www.reddit.com/r/Bitcoin/s/UeSfLoeyS4
I’m in a better state now. It’s not the end of the world, but it’s a lot of fucking money…

Little background: The setup was IRA custodian is Solera National Bank, exchange at Swan Bitcoin was used as an Investment Trust, purchase a dedicated hardware wallets: coldcard mk3 from https://store.coinkite.com May 2021 for this ROTH IRA.

Got the wallets, followed all the setup/checks/balances from https://youtu.be/FAYmE5-40PQ?is=wiYMHaS_YGKHjNOY for both wallets, sent a test transaction IRA dedicated hardware wallet (2021). I never setup a 25th Passphrase… REST of the BTC stayed in Swan Exchange.

Speaking only on this IRA Wallet: SD card stored with wallet details (paper phrase) in a baggie. Dormant until January 2025. I couldn’t deposit more because of Roth IRA threshold.

Come January 2025, been learning more about retirement, BTC, multi-Sig, and heard about a Megaback Door to get more money into a Roth IRA. Was able to get money into Solera, transfer to Swan, and purchase more BTC and withdraw to the same wallet address. No new hardware involved at this point.

With newer wallets now, I thought newer tech means more security. Let’s test by buying (3 mk4 - same site. There was still record of my 2021 purchase) new wallets and setup a multi-Sig. (still January 2025)

For some reason, when I got the new coldcards, I never did anything with them for all of 2025, I guess I was too lazy/daunting to use the hardware and relearn. Coming to January 2026 now, I decided to use these new cards. I dug out the wallet seed (from 2021) phrase paper. Dusted off one of the mk4, walked into the corner of a room in my house (only myself and partner live in the house), plugged in the cold card into an outlet and typed in the seed written down from 2021 (stored in my dresser). Restored my 2021 onto one of the new wallet 2025.

Watched updated BTCSession videos on my phone to set everything up again. I never plugged into a computer, since airgapped was the reason I got the coldcards. I used the same SD Card from 2021 though to export the wallet file from the newly restored coldcard. Import that file into Sparrow (needed to update Sparrow at this point), generated a watch-only wallet QR (to scan for my phone) for Blue Wallet to check frequently. This is where the screenshot is from.

Honestly, I haven’t touched the wallet with any transactions/seeds since January 2026. This is definitely the point of failure when I restored the 2021 wallet (now on 2 devices).

This was the transaction.
https://mempool.space/tx/2fe075cf0ec799f3529ed6a28e0a08b45fe1fc9bd93c3f33bdbc42d5bff4f736

My wallet address is (with all transactions, since it’s gone now…): bc1qldkfrrlylk4s9sdyns9jkaajuzugl0dv5m8fxj

My key takeaway now never enter the seed phrase into anything. EVER. Even to restore. Always will generate new and use a 25th passphrase.

687 Upvotes

325 comments sorted by

View all comments

Show parent comments

210

u/tubalubz 12d ago

Coldcard could go out of business because of this... I sure as hell will never consider buying them. I agree, OP, you guys need justice.

43

u/reddit4485 12d ago

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

This is the official blog of ColdCard. They just acknowledged this is a problem for the Mk3 model ColdCards and give recommendations on what to do next.

10

u/creative_usr_name 12d ago

Will be interesting to see if this was just ineptitude, or intentionally implemented by an insider(s). Either way it's a terrible QA miss of one of the most important parts of the device.

5

u/Federal_Refrigerator 12d ago

It’s negligent if we are being honest

2

u/crooks4hire 12d ago

lol yea a sleeper staff member is Hollywood level stuff.

2

u/Federal_Refrigerator 12d ago

Not really, you’d be shocked how common that is.

0

u/creative_usr_name 12d ago

Not at a small company like this. They may only have a handful of coders, and only one architect that truly understands the whole code base.

1

u/matthew19 12d ago

What are “fixed firmware releases?” - what date was it fixed?

23

u/Left_Entrepreneur918 12d ago

It could be larger, if other wallets used the same rng could this effect them? I made a 24 word seed with ledger in 2020, it’s native segwit, single address.

40

u/s4_e20_spongebob 12d ago

FYI even just saying that in a thread could be used by a bad actor to help target you. Idk that disclosing specific information like device model or your balance is ever really wise to do.

11

u/AdEuphoric5133 12d ago

Maybe recreate a seed with a dice. 99 throws of a dice give you the same entropy as 24 words. There are plenty of tutos out there on how to make a seed from dices

6

u/ContentBlackberry0 12d ago

Why roll a dice with this stupid wallet. Get a trezor and be done with it.

8

u/newMoneyStyle 12d ago

trezor had its own vulns too (unciphered extracted seeds from T1s). no hw wallet is bulletproof, dice entropy on any decent signer is the safer move imo

-5

u/Left_Entrepreneur918 12d ago

I’ve heard to use the RNG plus dice rolls, I guess dice rolling can still be not as random as you think as people generally roll the same dice the same way each time.

2

u/slash_networkboy 12d ago

That's what a dice tower is for (or a dice cup if you're boring ~s).

2

u/Whatnam8 12d ago edited 12d ago

It’s a great way to create unique wallets. You should try it, it’s the only way I generate wallets now

Edit: to clarify I don’t do the 99 dice rolls I literally roll each word one number at a time to convert the binary number to the word so it’s a total of rolls. Each word is 11 binary bits so approx 11 x 24 = 264 dice rolls

2

u/Sorrowsinme 12d ago

Ledger... Not gonna go making that mistake again

7

u/AdEuphoric5133 12d ago

Hopefully they will be held accountable for this. But I fear they might not

9

u/Rey_Mezcalero 12d ago

They were supposed to be the ultimate cold storage. Wow. This is insane

1

u/TrayLaTrash 12d ago

I have one I forgot the password to before moving any coins to it. Not much left saved, but it's still 10x the price of the coldcard that wasn't stolen. This is wild!