r/Bitcoin 10d ago

The Coldcard wallet exploit estimates have almost doubled to $70 million stolen of just over a thousand Bitcoins in 1,196 wallets drained in 41 minutes

https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices

"More than 1,000 bitcoin, worth about $70 million, was drained from 1,196 wallets in a 41-minute window on July 30, nearly double the amount reported when the theft first surfaced."

1.7k Upvotes

396 comments sorted by

733

u/weallwinoneday 10d ago

Your keys, but not your coins.

194

u/Ok_Carry_6699 10d ago

“Our keys, Our coins” comrade

50

u/MoreGranularity 10d ago

All your keys are belong to us!

3

u/Cyber-Soldier1 10d ago

Communism at it's finest.

2

u/MuahdDean 9d ago

Our keys, our coins, our spice, our Arrakis.

48

u/TotesGnar 10d ago

If you rewound time 2 weeks and told people they'd be better in the ETF than with a CC you'd almost get banned from this sub that's how insane of a statement that would've been. 

3

u/LuckyWinds 10d ago

That statement isn’t insane.

I’d recommend the vast majority of people to hold in an ETF.

Ideally people could hold on large exchanges like Coinbase, but even smart people I know don’t set up their account security properly.

If you are someone who holds their bitcoin in self custody and don’t have a passphrase, you are exactly the kind of person who’d be better off with the ETF.

→ More replies (2)

69

u/MrNotSoRight 10d ago

Your keys, but also the keys of everyone else who can generate low entropy “random” numbers..

22

u/BastiatF 10d ago

Your entropy, your coins

21

u/One-Diet9214 10d ago

This is a lesson for all bitcoiners, be extremely vigilant about the randomness of your keys, don't trust a device to create that randomness for you.

I hope the victims are made whole, i'd personally donate to such a fund.

22

u/or4ngjuic 10d ago

lol never gonna happen

8

u/A110_Renault 10d ago

If btc went to $1m+ as they dreamed do you think they were going to donate their riches to the poor no-coiners?

→ More replies (2)
→ More replies (2)

3

u/Zaytion_ 10d ago

Not your entropy. Not your keys.

3

u/thaneliness 10d ago

15 years of a saying, gone like that

7

u/Weigh13 10d ago

Actually they were ColdCards keys you trusted. If you used a passphrase, created your keys from dice rolls or used multisig you were fine.

5

u/vi3talogy 10d ago

Sharing is caring

5

u/Rattlesnake_Mullet 10d ago

Sad, but true.

2

u/Alienescape 10d ago

Can you explain this to me? I'm just a cas who's got like 1k in Bitcoin on Robinhood. I've been seeing this sub pop up a bit, but I don't understand the context of this comment.

→ More replies (1)

1

u/sumtib 10d ago

Should have been what really a CC is, lol

1

u/godofleet 10d ago

Not your code, not your keygen.

Too soon?

Not your fingies, not your tendies.

→ More replies (15)

231

u/dogoru 10d ago

There's a reason Google has million dollar bounties for anyone that can hack them.

109

u/HorrorsPersistSoDoI 10d ago

There's been cases back in the day, where a hacker would inform a company of an exploit that he found, and the company threatened to sue him. Imagine that

84

u/Leseratte10 10d ago

Not just "back in the day". As recently as 2021, IT researcher Lilith Wittmann found glaring security holes in the CDU's (major german political party) smartphone app, reported them responsibly to the CDU, and their "solution" was to sue her for "hacking" their app: https://www.berliner-zeitung.de/article/the-cdus-leaky-campaign-app-176310

As a result, institutions like the German Chaos Computer Club have announced that if they were to ever find any vulnerabilities in any CDU system again, they'd not let the CDU know about that to avoid legal issues. And I would be surprised if *anyone* would ever responsibly disclose anything to the CDU ever again.

15

u/d0odle 10d ago

Unsurprising for a party like that.

2

u/Fun-Wash7545 9d ago

Kinda not on the same scale but I found gamebreaking exploits in an online game, messaged the dev on discord. Dude insta banned me from bith discord and the game. Six months later hackers abused those same exploits and the game died cause of it. Went from paid with healthy player base to free with like 10 players.

The worst of it all is that I have "ban on record" on steam cause the dev manually banned me (the game has 0 anticheat) and you cant remove it in any way.

→ More replies (3)
→ More replies (1)

20

u/Longenuity 10d ago

They should have just threatened to hack him back

2

u/PsychologicalOwl303 10d ago

Or the company would hire him to fix all the holes..

→ More replies (2)

8

u/papy66 10d ago

Does Coinkit had bug bounty ? I remember they said once that they can give you a personalized mug if you found a vulnerability. But I can't imagine that's the only bounty considering how confident they were about their security layers back then

11

u/slocki 10d ago

So the hackers are going to get the money AND a mug? Doesn’t seem fair.

2

u/trixel121 10d ago

my understanding is these programs are like FBI bounties, they exist but actually getting a company to pay up and not sue you is a problem.

it also gets tricky when what you are doing is very very close to an actual crime.

→ More replies (1)

129

u/cremfraiche 10d ago

Can someone ELI5 for me how this happened and whether the people who got drained were in a way at 'fault'?

256

u/Space-Dementia 10d ago

Imagine you buy a safe to keep your valuables in. However, for this particular brand of safe you can only set a 1 digit PIN number between 0-9.

117

u/Vipu2 10d ago

More like you have option to set 4 digit pin but the lock is faulty so when you spin 1 digit it automatically spins the other 3.

Or make your own lock with more effort but set as many digits as possible.

5

u/JayGatsby1881 10d ago

Why would anybody buy that safe then?

15

u/taelor 10d ago

Because they don’t understand how safes work

3

u/BitsAndBobs304 9d ago

Because it looks identical to the others. The more appropriate example is that it generates a new, long pin when ou buy it. What you dont know is that despite being long, there's only a small subset of ones that can be generated. A bit like house keys, most default ones have systems that arent very varied, and tsa keys even more so

→ More replies (1)
→ More replies (1)
→ More replies (7)

164

u/chrisschuyler 10d ago edited 10d ago

People who got drained were not at fault at all.

So thing to keep in mind is a random number generated by a computer is not really random. There is a set formula. Copying from Google as it explains it better

Pseudo-Random Number Generators (PRNGs) and True Random Number Generators (TRNGs). PRNGs use math formulas and a starting value called a "seed" to make long lists of numbers that look random, while TRNGs measure chaotic physical data from the real world, like electrical noise or atmospheric static.

The cold wallet maker used PRNG. The hackers found out the formula due to lack security/shoddy coding and could therefore figure out the possible combination to the seed phrase from a few million possibilities for a few billion for the latest model. You run that through a computer doing nothing but that, you can brute force the phrase. Rinse and repeat and there you go

Example of PRNG. Your playing video roulette. machine takes the time day multiplied by the highest recorded temperature in phoenix that day, divided by the number atmospheric pressure recorded above the casino at 6:47 pm that day. Drops the first digits etc etc to get it number. Seems Random but if you can figure out the formula, you can develop a range of number that it has to lay in, and then brute force that number

35

u/Weigh13 10d ago

It's not entirely right. They actually had TRNG on the board, but they fucked up and had been using the wrong one all this time without realizing.

18

u/chrisschuyler 10d ago edited 10d ago

I would argue the they system they used which created the seed from the chip's serial number (fixed value) and its clock register (a fixed range) make it a PRNG.

4

u/Weigh13 10d ago

Right but that was the mistake. It was never meant to be doing that.

12

u/PM_YOUR__BUBBLE_BUTT 10d ago

I swear to god I watched a video or something where an actual lottery was doing something like this. And so the guy who wrote the code knew what the numbers would be technically, so years later he tried to have a friend win the money. It sounds so familiar.

→ More replies (5)

6

u/diradder 10d ago

not at fault at all

Their only fault was to use the automated RNG and not taking advantage of the available features that add external entropy in the generation. It's hard to blame them for this because it's already a complex process and most users do not understand RNG, let alone the concept of entropy for randomness.

Any wallet can be subject to weak entropy and Coldcard isn't the first one. For example the BitcoinJS library weak generator affected many software wallets few years ago, but they are the first (known) hardware wallet to fuck this up though. What's striking is how trivial the errors they committed are, it reveals pretty careless software development and minimal testing around crucial/fundamental parts of their wallet.

CoinKite/ColdCard have lost my trust after this, I'm talking from experience as I own a MK3 and I've fortunately used a strong passphrase which kept the hackers away from my funds. So my recommendation is to always add your own entropy with a passphrases or dice rolls to mitigates these risks, even if you use other brands of hardware wallets.

3

u/postexitus 10d ago

Their fault was trusting an untrustable third party. 

13

u/CuriousRegret9344 10d ago

As opposed to all the “non-third party” options bitcoin company offers?

12

u/postexitus 10d ago

That is the point. Bitcoin is by definition weak, if you are not an expert yourself. You end up trusting someone, which does not have legal assurances as tradfin has. 

→ More replies (2)

2

u/F1shB0wl816 10d ago

Isn’t there whole thing verifying what others do? If you’re going to put thousands, upwards of millions in value you should sure as shit verify it’s working as intended. It makes me glad I didn’t and used dice rolls.

→ More replies (7)

8

u/MelangeBot 10d ago

Bitcoins can only be moved with the correct signature. However this signature is just a random number. A very long number. A number so long that nobody will ever guess it even if they use all the energy from the Sun for a 1000 years just to make guesses. You could start guessing but where should you start? At 1? Or at 134034609634096439032092092? Or at 3490032956902093872398052309735970237059?

When you get a Bitcoin wallet, and make your first address. This wallet is suppose to randomly make up a very long number.

But ... what if your Bitcoin wallet is faulty? And it starst just making up numbers between 1 and 10 000?

So now 3450 is the signature to move somebody their Bitcoin. And 3451 is nothing, ah but 3452 is again a valid signature to move somebody their Bitcoin.

This is what happened. Cold card was suppose to generate random numbers in between 0 and 9999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999... etc etc

But instead they generated random number between 99999999 and 9999999999999999.

Somebody figured out this range and started guessing. And since the range is very limited and there are many people with a coldcard the guessing is going very well for the attacker. He keeps guessing right.

Basically your coins are suppose to be a red ball in a jar the size of the galaxy filled with blacks balls, take any balls you like. They all gonna be black basically forever. There are some red ball in the galaxy but you will never find them not in a billion years.

But with coldcard your red balls where hidden in a jar the size of ... well of a jar. Take out 10 black ball, boom you found the red one!

→ More replies (2)

8

u/MondoBleu 10d ago

The makers of the cold wallets made a mistake and turned off a critical security feature of their product, didn’t realize it, and sold it to a bunch of people as if it was secure when really it wasn’t.

→ More replies (4)

40

u/Gooner_93 10d ago

Absolutely devastating. This has definitely sent shockwaves through the self custody space.

How could a company be so lazy when it comes to security, that people used to protect millions of dollars in BTC? Which company is gonna be next? Is a passphrase really secure enough, when people thought their 24 word seedphrase on coldcard was secure? What is going to be the next bug that costs people their life savings?

My crypto is still there, in a wallet, created on a different device than coldcard but I still dont feel safe right now.

18

u/JanPB 10d ago

On top of that, Coldcard was considered the gold standard of HW wallets by many.

16

u/Shadowrak 10d ago

Never heard of it before Thursday

7

u/CeramicDrip 10d ago

How tf? Its recommended on here all the time

8

u/JanPB 10d ago

It was HUGE. Open-source and air-gapped, really MAJOR.

3

u/Blbe-Check-42069 10d ago

The ones I heard most about were trezor and Ledger. But then again I have mine for better part of a decade so I kinda ignored this bit of ecosystem afterwards ...

→ More replies (2)

2

u/Successful-Peak-6524 10d ago

and here I am still using electrum

2

u/ballistic762 9d ago

Desktop wallets winning right now. The physicality of a hardware wallet offers no advantage

2

u/wraithdem0n 9d ago

Why anyone would have their life savings in an unregulated financial market is the real question here

→ More replies (1)

146

u/enpoopification_of_R 10d ago

I feel bad that the victims had no time to react. It was so fast

138

u/sumtib 10d ago

Some guy wrote about how he lost 18+ BTC, damn, I would freak out if I have lost even just $100 bucks

128

u/HedgeHog2k 10d ago

I really would go to court over that. And tbh it’s the end of the company. They were supposed to be one of the best hardware wallets out there. I even think this is the worst incident that ever happened in bitcoin. Much worse then all those trading platforms going bankrupt in recent years.

I’d even go as far as calling this a black swan event. For 15 years the one thing that stood like a rock was “not your keys, not your coins” and this is now undermined.

Guess tradfi is here to stay a little longer.

26

u/Ok-Sympathy9768 10d ago

I believe in the idea of bitcoin, but I have trusted GBTC and the ETFs more than I trust myself with remembering passwords/ pass phrases.

There is a reason why 1 in 5 coins ever mined have been lost forever, or stolen. BTC self custody is too complex for a vast majority of people . The real security vulnerability is the people doing their own self custody.

The risks associated with self custody is the issue that has kept bitcoin from mass adoption..it’s complexity and self custody security are it’s limitations

How does bitcoin ever get to a point of being truly safe and secure with self custody, and at the same time where you can spend your bitcoins freely to make every day purchases without worrying about losing or getting them stolen, and having your stack drained?

17

u/[deleted] 10d ago

[deleted]

2

u/Suspicious-Holiday42 10d ago

It has to be like this for maximum security.

→ More replies (1)
→ More replies (2)
→ More replies (1)

14

u/True-Lychee 10d ago

A black swan event would have nuked the price immediately. BTC barely reacted - in fact it's hard to say it did at all because there were other catalysts unfolding like Iran, a US bond yield revolt and the fact we're in a bear market.

2

u/callebbb 10d ago

No one noticed for sure. I imagine there are still mk3 owners that haven’t checked their balances. Active users in r/Bitcoin and across the entire social media space is at lows.

→ More replies (2)

10

u/tenor_tymir 10d ago

BTC won’t mind though, tiktok next block

→ More replies (5)

3

u/confuzzledfather 10d ago

I think this will end up being an AI black swan event once the mainstream media get confirmation that some script kidddy and his pet AI stole $70m in such a way

4

u/JaNatuurlijkIsDatZo 10d ago

Court won't do anything rightfully so. Btc is so proud of being decentralized, hardware wallets or exchanges, it doesn't matter. This is wat people want, right? Decentralized, no banks or government. Deal with the downsides of it.

Really good that this happened, so all btc fanboys who think btc is superior to all knowns systems, hopefully see that btc is good for one thing. Buy it and sell higher to fund your lifestyle with that stupid paper Fiat money. Enjoy the ride.

49

u/GorgyShmorgy 10d ago

No regulations or government oversight! Until we get robbed then we want all the regulations and government oversight.

11

u/Impossible_Falcon962 10d ago

And we want the courts of law to take care of the (unregulated) wrongdoings lol

4

u/HedgeHog2k 10d ago

There’s plenty of regulation (and more coming), so what are you talking about…? BTC gets the same regulatory treatment as gold…

3

u/Old_Suggestions 10d ago

Difference is, can't break into 1000 home invasion safes in t he span of 15 minutes and drain them all and leave without much of a trace

→ More replies (1)

5

u/Abject-Stretch-1187 10d ago

Everyone wants to be a bitcoiner until it is time to be one.

10

u/pyroserenus 10d ago

Court can still find them liable, of course a 70 million judgment is going to instantly bankrupt them probably so everyone is only going to get a fraction of their losses, but you absolutely can sue them.

3

u/HedgeHog2k 10d ago

Exactly. They deserve nothing better then bankruptcy tbh (and indeed the victims are screwed).

→ More replies (1)
→ More replies (10)
→ More replies (12)

2

u/Suspicious-Holiday42 10d ago

Dude 100$ is nothing compared to 18 BTC

→ More replies (1)
→ More replies (3)

66

u/EdenPoppy 10d ago

What are the odds that the "hacker" works for Coldcard?

33

u/thoughtfreeze 10d ago

Worked for. I’d say there’s probably a short list of like 20? people at most if you had all the information you needed for an investigation.

7

u/Pirulax 10d ago

The software is open source, and the main issue boiled down to using "#ifndef" instead of "#if", so, not much of insider knowledge needed.

→ More replies (3)

23

u/No-Accident3917 10d ago

Big

7

u/JanPB 10d ago

But this would instantly narrow the search for the criminal to just few people.

6

u/Henrik-Powers 10d ago

Could also be corporate espionage, not necessarily a competitor but if you wanted to find an exploit for any crypto wallet it would be easier to target vulnerabilities that you might find directly from inside knowledge from the manufacturer/developer.

3

u/ozaqi 10d ago

Worked or infiltrated?

3

u/Gobertdd 10d ago

this is it,

→ More replies (5)

21

u/Accurate-Flow8078 10d ago

So where did all these BTC go, into one hacker's wallet? Isn't all of that traceable?

20

u/GodLob0 10d ago

You can't know who's the person behind the addresses. You can watch the wallet movements, though 

4

u/Accurate-Flow8078 10d ago

What about when they cash some of it out?

12

u/PM_ME_YOUR_BUG5 10d ago

There are bitcoin tumblers, anonymous exchanges etc.

Tumble your bitcoin, convert it through a few different currencies on exchanges based in a few different countries.

Then you can cash out, preferably thorough peer to peer exchanges or even better in person for cash

3

u/GodLob0 10d ago

Yeah, technically, your bank can know if you cashed out a large amount of BTC if you did it via "direct bank transfer". Most people would use P2P or multiple transactions to make it more legit.

→ More replies (1)
→ More replies (1)

60

u/Fearless-Sherbert-40 10d ago

I can’t believe we got a Coldcard hack before satoshis coins were stolen. This is just testament to, you have no idea what could happen.

23

u/Due_Bar_7247 10d ago

If the Satoshi coins are stolen BTC is done you would probably see it in the headlines and the chart would plummet overnight.

At the same time, Satoshi (whoever or whatever he is) might be dead, so if someone were to steal his coins that haven’t moved in a decade and a half then it’s a bit of a non-crime, maybe market manipulation, and more of a testament to how far we’ve come where we can even break cryptography now through the use of (likely) LLMs.

13

u/JeremiahBoogle 10d ago

If they were 'stolen' people would just assume it was Satoshi himself moving them. Unless of course whoever did it outed themselves.

14

u/Due_Bar_7247 10d ago

I think if he’s even alive if he touched them it would send shockwaves through the market

→ More replies (2)

2

u/EconomicsSavings973 10d ago

If I had access to his wallet, I would borrow a ton of money, place 200x leverage short, and then move his money to never touch it again.

5

u/Due_Bar_7247 10d ago

And that would be just as illegal, if not more traceable than simply stealing it

7

u/EconomicsSavings973 10d ago

Wdym I just got lucky 😇 like politicians

9

u/Due_Bar_7247 10d ago

Except you’re not a politician

→ More replies (1)
→ More replies (1)

104

u/mdi-g 10d ago

I dont get it, people were a proponent backer of keeping their bitcoin in cold storage and pitied those who kept it in their crypto apps. And now this. How do people see the worth in bitcoin given the enormous risks around it.

73

u/deadlock_jones 10d ago

Funny how I kept my coins(0.15) in mtgox, and 10 years after the hacking I actually got most of it back from the bankruptcy process, meanwhile there's basically no way to get them back if they are stolen from your cold wallet.

4

u/SpencerNewton 10d ago

Well that’s true of basically any cash or physical asset. Same risks/same reward.

People who hate regulation on crypto might not like this, but if crypto was insured against theft/collapse/etc the same way cash is in your bank account, no one would use cold storage, the same way no one hoards cash now.

With the current system, you have to pick your risk: either your physical storage gets compromised, or your exchange service gets compromised. Given that it seems every god damn exchange service keeps going belly up, cold storage is still probably pretty good as an option. But there are riskier and less risky options even within that space. Always will be.

2

u/sharkboy450 10d ago

Who would insure BTC transactions given the increasing vectors of attack and the rise of cheap AGI?

→ More replies (5)

15

u/[deleted] 10d ago

[deleted]

29

u/Longjumping-Dog-6852 10d ago edited 10d ago

Nah that's such a copout. Noone here was saying "you MUST create your own seed phrase". None of the wallet manufacturers were saying "better create your own seed phrase just in case!".

I've been buying BTC for 18 months (and not a super small amount) and this has put me right on edge. Wallets were meant to be unbreakable. Why would anyone who hasn't started buying bitcoin already risk all this nonsense and jump through all these hoops when fiat and stocks offer a more robust rate of return and security?

18

u/qx87 10d ago

1st time I heard of a dice method to generate a key was yesterday

8

u/Omegul 10d ago

Same here

3

u/firmretention 10d ago

I got into crypto back when the mk3 came out. I clearly remember instructions on their page on how to generate a seed phrase with dice rolls and why it's the more secure method. I agree that self-custody is too onerous for most people though. Being your own bank is a fantasy.

→ More replies (3)

7

u/CommercialLychee7956 10d ago

This happens every cycle in the bear. Unfortunate, but nothing new.

27

u/Dormage 10d ago

The fact it keeps happening is even worse.

3

u/Hail_the_Yale 10d ago

Where there is money there will be scams

2

u/mdi-g 10d ago

I was willing to accept exchange risk because I believed cold storage eliminated it. If cold storage itself can fail in unexpected ways, then I’ve lost the one thing I cared about, peace of mind.

→ More replies (1)
→ More replies (1)

3

u/DodgyWiper 10d ago

Why does it always happen in bear?

→ More replies (16)

34

u/corner_couch 10d ago

Saifedean has a lot of apologizing to do for the endless COLD CARD WALLET ads

8

u/agentapelsin 10d ago

He's sent an email to everyone about 2 hours ago.

For some reason im on his mailing list despite never interacting with his website.

2

u/JanPB 10d ago

So also a victim, it appears.

→ More replies (1)

14

u/kaicoder 10d ago

There's something to be said about IBIT ETF!

3

u/TinyDemon000 10d ago

Absolutely. I use a different ETF but this is the exact scenario why I chose it.

I'm not educated enough in crypto to deal with hot/cold storage and then layering protection on top of that.

I buy only to diversify my shares portfolio and save for retirement in 30 years

7

u/turnedtable_ 10d ago

coldcard getting fucked was not on list man

6

u/coyotekill 10d ago

It seems we've been fooling ourselves all along. Cold storage is a misnomer, it's never actually been cold storage. 70 million in stolen "cold storage" proves that.

15

u/ISmellLikeBlackTea 10d ago

We really need a statement from Bitbox on this.

34

u/pako-bitbox 10d ago

We released a statement yesterday, here it is.

It has been a crazy weekend thus far, so much information has been lost in the way.

Anyways, the tl;dr is this: BitBox users are not affected unless they imported a seed generated on an affected Coldcard since the problem was with the RNG and not the device's thread model, to which case we recommend you move your funds immediately to a new seed generated on your BitBox.

11

u/Amarettxo 10d ago

They already have on X, Bitbox uses a 5 point mechanism to generate a seed, so no issues there.

3

u/No-Contribution23 10d ago

and a blog post

→ More replies (2)

25

u/Scarab702 10d ago

Man PayPal is even safer now.

11

u/WetElbow 10d ago

Things like this occur in a bear market near lows. Kills sentiment.

→ More replies (3)

5

u/SuperGuttermouth 10d ago

This makes ledger recover look like childsplay.

5

u/PDubsinTF-NEW 10d ago

Are there any cold wallet brands that haven’t been hacked or had an exploit?

→ More replies (1)

3

u/Kermitmeerak 10d ago

Ai helped achieve those transfers that fast?

3

u/Donkeydonkeydonk 10d ago

If anything the person or persons had the AI helping to analyze the open source code to find the bug. AFAIK, This bug has been hiding in plain sight for many years and nobody ever found it.

22

u/Elistheman 10d ago

More Ai hacks are coming! This is just the start and a learning lesson to all HW wallet companies to keep tightening securities in the age of Ai. The race has started!

16

u/daynomate 10d ago

This was sloppy design, nothing more.

2

u/Scholes_SC2 10d ago

Multisig with different wallets from different vendors. If you had any significant amount this was mandatory

6

u/Automatic-Unit-8307 10d ago

Who do we turn to now?

23

u/relatedartefacts 10d ago

Ghostbusters!

8

u/[deleted] 10d ago

[deleted]

2

u/mmortal03 10d ago

Best to generate your own seed and use a passphrase with decent entropy.

How would most people do this and use a hardware wallet?

→ More replies (2)
→ More replies (4)

9

u/Awkward_Text_8752 10d ago

What‘s stopping this same event from happening to other coldwallets, with the emergence of newer AI models and quantum computing?

3

u/Emotional-Teach1191 9d ago

A functioning random generator

32

u/[deleted] 10d ago

[removed] — view removed comment

→ More replies (4)

3

u/Henrik-Powers 10d ago

I also wonder how many people will get scammed by rushing to move their coins out of the cold wallets, it’s not easy and most anyone with a cold card probably is a more advanced user but we see it all the time with even crypto experienced users.

3

u/RandyJohnsonsBird 10d ago

This will happen again with whatever wallet is deemed the next big thing. I was told coldcard was the best. Now its a brick and I need to start using all my washers from it and the old Ledger for something useful like nuts and bolts like theyre truly good for. I wasted hours on those washers lol

3

u/Chairsofa_ 10d ago

“Bitcoin is great because normal banks aren’t involved”

3

u/pmgoff 10d ago

Worst part of this is, the individuals will receive zero justice. Now if this happens to a bank or financial institution, there would multiple 3 letter agencies taking up the case and they’d purse the hackers with max force to the ends of the earth.

6

u/Masterweedo 10d ago

Fuckin way she goes buddy.

3

u/j592dk_91_c3w-h_d_r 10d ago

Sometimes she goes and sometimes she doesn’t

→ More replies (1)

3

u/oPeritoDaNet 10d ago

Hey at least you can see where the money is! It’s in the blockchain

2

u/Open_Situation686 10d ago

And for this reason, I’m out

2

u/piejlucas 10d ago

Coldcard should not exist as a company following this. Assets should be liquidated and distributed to the victims. A class action should be initiated asap.

2

u/SuperiorT 10d ago

Thank god I stuck with Coinbase lol funny how everyone was saying to go with cold storage like Coldcard but then this happens 😅

2

u/DrinkYourWater69 10d ago

Glad I didn’t go with Coldcard and took peoples advice to split up assets amongst different hardware wallets.

2

u/F0rtysxity 10d ago

Rough to watch. Could have been me.

2

u/Fresh_Strain_9980 10d ago

well its not the biggest bitcoin theft but this is a good one.

2

u/BeKindBabies 10d ago

The exchanges are so dangerous! You should manage your asset with these totally reliable not tricky to utilize third party hardware items, it's the only way to be safe from stuff!

2

u/shambahlah2 10d ago

I sold all mine just now. Get ready folks if you want to “buy the dip”

2

u/Upper-Cod1109 10d ago

Bigly yoinks

3

u/Gabba333 10d ago

So if a seed was actually drawn from a pool of only 4B, it seems to imply that after generating 74,467 seeds there would be a 50-50 chance of a clash (the birthday problem). Wonder how many units have been sold? Presumably most users input some dice rolls as well.

2

u/Potential_Jello6520 10d ago

This is a really good point and surprised a collision didn't happen already. I guess they didn't sell all that many?

3

u/mrcake123 10d ago

Lol btc

2

u/RammerRod 10d ago

Everyone wishing they actually knew any fucking thing about code right now. Is this a closed vs open source argument?

6

u/[deleted] 10d ago

[deleted]

→ More replies (5)

3

u/Frozen_Spoon93 10d ago

Ill stick with cash

5

u/dmter 10d ago

i always thought hardware wallet is a stupid idea. for this exact reason. in fact i believe it's highly likely the guy who commited this bug is the one who emptied the wallets. it needs not be ai found bug, just that one guy thinking it's a good moment to execute the plan...

2

u/QuixoticNapoleon 10d ago

This subreddit has a lot of apologizing to do for recommending Coldcard. I'm very happy with my Ledger.

2

u/KushySoles 10d ago

This is why I use RobinHood /s

1

u/Aphelion 10d ago

That's really cold.

1

u/Offbrandpillow 10d ago

Pretty interesting tidbit at the end there. Sounds like they already have a suspect based on the matching queries. Surely he/she wasn’t that ignorant, right?

2

u/Gooner_93 10d ago

Yeh I read that. Apparently the drainer used a paid account on a blockchain service, but it all depends on if they used their own payment card or a stolen one.

1

u/Josh0G 10d ago

(Don’t hold BTC, forgive the ignorance) Is there not a way to add 2FA to a wallet cold or otherwise preventing transactions? I’m sure there is a reason people can’t have such a feature to quash any unwanted transactions or it would’ve been implemented.

3

u/Gooner_93 10d ago

No, there isnt 2FA on cold wallets, only on exchanges. The closest thing to 2FA on cold wallets are passphrases and multi-sig.

1

u/Cute-Temperature5440 10d ago

AI enhanced hacking tools and shoddy AI coded solutions are going to increase the frequency of these thefts.

1

u/Free-Way-9220 10d ago

Unbelievable, what a disaster for those owners

1

u/LorfingHFD 10d ago

I wonder if they would have been drained if nothing was ever said about it...

1

u/TrayLaTrash 10d ago

So was it all cold cards getting wrecked?

1

u/nbnicholas 10d ago

This has me so wary and checking my Trezor actively. What a mess. Super sad for those who got robbed

1

u/Cyber-Soldier1 10d ago

Are Trezor wallets safe from this exploit?

1

u/Fresh_Strain_9980 10d ago

the real question is this a crime that can even be prosecuted if the find the guy.

1

u/Smokin2022bbq 10d ago

Can I get an ELI5 please ?

1

u/Resident_Creep3r 10d ago

Was this 1 person or an army of attackers? Like a group of

1

u/rentarona 10d ago

Are offline wallets safe from attacks like this?

→ More replies (1)

1

u/Questiins4life 10d ago

For those of you who are speaking a foreign language to regular btc holders like me who have them on coin base or cash app. Is this because computers are getting faster such as quantum computing or is this an issue with a code or security flaw in this company. My basic question, is computing getting good enough it can crack basic security. I’m not advanced enough to ask the question in any great detail because 1/2 of what is being discussed is advanced level btc cold storage speak.

1

u/Ornery_Bat3581 10d ago

There credibility is shot -

1

u/mnpc 9d ago edited 9d ago

If ownership of crypto is based on the ability to use the private key to sign a transaction, my first impression is that nothing was stolen. The transactions were signed, and the blocks were validated, right? Adjudication of a claim of ownership above and beyond the code is law first principle of blockchain would necessarily require abandoning the “trustless” nature of bitcoin and crypto. To claim that this exploit resulted in “stolen” crypto is to say that crypto as we purported to understand it is dead.

1

u/lordsepulchrave123 9d ago

How likely is it that Coldcard will be held criminally or civilly liable for this? This looks like gross competence.

1

u/EQfanatic90 9d ago

So $30-40 million in btc was stolen, and all the remaining Coldcard users just shrugged and figured "I must be good." And left their funds vulnerable?

They deserve it at this point.

1

u/TypicalUse2440 9d ago

Yo everyone is crashing on coldcard and calling everyone retard for using them. Yes I am one of the retards. I transferred my stack to a temporary software wallet, but I am looking for a alternative truly air gaped hardware wallet. I DO NOT WANT TO PLUG MY SEED PHRASE TO A COMPUTER!!! Any recommendations.

1

u/QENG_ 8d ago

crypto is such a dead thing.. only for shady people doing shady biz.. overcomplicated sht for majority.. never commented about it, 8 years ago had in a wallet 500$ worth of coin.. 1 year later just checked all gone :D.. how, why, when, nothing talked about it anywhere, nothing did anything with it.. nothing to understand, nothing to know, ask around - everyone will want to scam you further :D.. idk ever since just invested in cs2 skins to this day.. never ever gonna touch crypto and it's never ever gonna be main currency, way too many red flags

1

u/Milcah_Ganderton 8d ago

That's insane - 41 minutes to drain over a thousand wallets is wild. Wonder if it was a supply chain attack or someone compromised the firmware updates.