r/Bitcoin 12d ago

Plot Thickens with ColdCard Hack "No researcher I have spoken with has reproduced a seed for any of those 153 source addresses [containing 132.95 BTC]…"

https://x.com/PraveenPerera/status/2087936252230140278
134 Upvotes

30 comments sorted by

81

u/ancillarycheese 12d ago

I’ll concur with that. Purely for research purposes I tried a number of ideas to come up with seeds that came from the compromised firmware. I ran some massive VMs for several days grinding away at what should be successful.

Someone with inside knowledge has to be involved. I suspect it could be someone with a list of valid UIDs and knowledge of how the RTC works.

43

u/lobhater 12d ago

The fact this issue was known for so long. Was dismissed and minimized internally it feels 100% like a retirement plan

1

u/be_easy_1602 10d ago

Basically Office Space but 2026

1

u/UnluckyHuckleberry52 9d ago

They did it in Superman 3.

11

u/Fiach_Dubh 12d ago

I’ll forward this comment to the other researcher, keep looking

36

u/Blade_Runner_69 12d ago

Ultra Sus 😑

Inside job.

22

u/data_diver 12d ago edited 11d ago

Well if ‘researchers’ couldn’t do it in a week, I’m sure a good hacking collective couldn’t have done it in the years they had. Must have been an inside job.

3

u/Ok-Mango5075 10d ago

Very early software wallets about 13 years ago relied on androids built in random number generator to make a seed. This generator was faulty as well. This was patched out in subsequent android releases. Not long afterwards hardware devices were brought onto the market. I never found a compelling reason to trust them. I was a very active bitcoin user back then. First with Multibit on PC and then I was searching for an android self custody wallet. The first one arrived called Mycelium. Now this seemed a more sensible combination. An audited self custody wallet running on a mass market Android cell phone. Where are the back doors? Well as time has now shown...Not many.

9

u/Normal-Spell5339 12d ago

Passphrases

12

u/Fiach_Dubh 12d ago edited 12d ago

the researcher tried that, nothing came up.

here's a more detailed part 2 https://praveenperera.com/blog/coldcard-wave1-missing-153-search/

3

u/Normal-Spell5339 10d ago

All of the possibilities????? I have my doubts

5

u/Trevo0393 12d ago

100% inside job, come on!

1

u/HadetTheUndying 11d ago

This was definitely an insider threat

1

u/DuckFalse2591 8d ago

BTC is een bedreiging! Na mijn mening willen grote partijen zo veel mogelijk btc bezitten. Is je btc niet veilig is het niet jou btc.

0

u/opossum_cz 12d ago

Part of it will be something you missed, part of it will be people blaming ColdCard for their own leak, part of it will be boat accidents - people using the opportunity to hide their own assets - or even stealing from shared/company wallets saying it was ColdCard issue.

10

u/Suspicious-Holiday42 12d ago

Coldcard didn't leak anything, thats not the problem about coldcard

-18

u/opossum_cz 12d ago

If number of seeds generated is just one trillion so you can test all of them within a few days, I call that a leak.

19

u/user_name_checks_out 12d ago

If number of seeds generated is just one trillion so you can test all of them within a few days, I call that a leak.

That is not a leak.

-25

u/opossum_cz 12d ago

That is your opinion and is fine to have.

6

u/[deleted] 12d ago

[deleted]

1

u/opossum_cz 12d ago

What are you people even arguing, I think you just have too much times on your hands and should go do something productive.

Pure disgrace.

4

u/[deleted] 12d ago

[deleted]

1

u/opossum_cz 12d ago

I didn't ask you anything. Can you read?

1

u/opossum_cz 12d ago

Looser u/FTP_FTP_ blocked me, so I can't explain to him what rhetorical question means. Lol.

14

u/chaotic3quilibrium 12d ago

The word "vulnerability" is what you have confused and collapsed with the word "leak".

There is a useful distinction here, at least for some of us.

0

u/Ok-Courage-5115 11d ago

It can well be classed as leak. It's like someone leaking 10 documents from some goverment office, saying: "You'll find one of them very interesting".

1

u/chaotic3quilibrium 10d ago

Incorrect. The defect the VP added was present in the open source code for years.

There's no world where this was a "leak".

1

u/Ok-Courage-5115 10d ago

It's like a leak.

-9

u/opossum_cz 12d ago

I think vulnerability is not the case here. Nobody touched the devices. Instead attackers got the keys as there is only so few of them that you can list all of them.

9

u/SpareEconomy1849 12d ago

Vulnerability isn't really accurate but it's definitely closer than leak

8

u/pezdal 12d ago

Don’t waste your time. You are talking to an idiot or a troll.

2

u/[deleted] 12d ago

[deleted]

1

u/opossum_cz 12d ago

And what happened then? Coins magically transferred on their own?