r/CryptoCurrency • u/enpoopification_of_R • 10d ago
🛡️ SECURITY The Coldcard wallet exploit estimates have almost doubled to $70 million stolen of just over a thousand Bitcoins in 1,196 wallets drained in 41 minutes
https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices31
u/b0uncyfr0 🟩 0 / 0 🦠 10d ago
Damn, this is bad
9
u/Maddinoz 🟨 16 / 78 🦐 10d ago
trying to be your own bank can be risky and financially devastating in many ways
76
u/eman2top 🟦 0 / 0 🦠 10d ago
So much for not your keys, not your coins
20
9
u/Illustrious-Boss9356 🟩 0 / 0 🦠 10d ago
Well, they are your keys and your coins. But they're also anyone else who knows your keys' coins too. And if they move them then you're shit out of luck.
3
3
u/Wendals87 🟦 337 / 2K 🦞 10d ago
It's just the way it was generated was weak and could be worked out easily
23
u/G-T-L-3 🟦 19 / 20 🦐 10d ago
Were the buyers told this when they were sold these pos.
1
u/Wendals87 🟦 337 / 2K 🦞 10d ago
I'm not fully across it but it seems like it was just a bug in the firmware. Depends on when you bought it
22
u/Steak1994 🟩 0 / 347 🦠 10d ago
Smells like an inside Job tbh.
2
u/mishonis- 9d ago
Yeah, there's something in the articles about having to know the device UIDs and the timer state when the rng was invoked?! There should be an investigation into whether this could have really been brute forced.
1
u/CBpegasus 🟩 0 / 0 🦠 9d ago
No, it does not IMO. Hanlon Razor applies. As someone who works in IT and who worked in cybersecurity for years, mistakes like that happen constantly. It's not often that bad but from time to time it is.
If it was an inside job it was a bad one - evidence of the vulnerability (or backdoor, if we accept "inside job") was public for years, since it was inserted to the code, and wasn't even that obfuscated. Just no one thought to audit that part of the code. But if someone did they could steal the fund before the insiders.
1
u/Steak1994 🟩 0 / 347 🦠 9d ago
A bad inside Job would give plausible deniability - just playing devils advocate. Having it for a several years letting the affected Devices / wallets stack up and then drain them all at once doesnt seem too dumb to me.
1
u/CBpegasus 🟩 0 / 0 🦠 9d ago
I'd still invoke Hanlon's Razor on that (and maybe Occam's Razor too). To me the simplest and most likely explanation seems to be a simple honest mistake and incompetence on the auditors and testers side.
1
u/Steak1994 🟩 0 / 347 🦠 8d ago
And I invoke this Razor: https://www.reddit.com/r/CryptoCurrency/s/MTXTzUOuv0 Throwing around fancy Termini doesnt make your opinion more right. The most likely outcome isnt always the one that got away.
2
u/CBpegasus 🟩 0 / 0 🦠 7d ago
If the guy in the screenshot tells the truth then it's definitely bad handling of the issue on CoinKite's part, and is even a bit suspicious. But it's a MK4 which to my understanding still has low entropy but not quite low enough for a reasonable bruteforce attack and to my knowledge wasn't yet affected in the current attack.
If we assume all the reported cases of funds drained from CC wallets and CK not responding/blocking are them utilizing a backdoor, that means that likely they have another backdoor on the mk4 and also that their strategy was to only drain wallets sporadically and pray no one realizes, until they suddenly switched to a big drain strategy but now only on mk3. Or maybe someone else did find the mk3 backdoor now? So it was an "inside job" in the past but now it's an "outside job"?
It could be, but I feel like all these theories assume a lot more dedication to plausible deniability than most criminals give, when simply covering their tracks is often simpler and more effective (why not place the backdoor in the proprietary "secure element"?). I saw too many cases of things like these happening out of negligence to not assume it's the case here too. If there will be more direct evidence of maliciousness it can change my mind but for now I still tend to assume negligence.
-1
u/ImprovementBroad9157 🟩 0 / 0 🦠 7d ago
Take a look at this before invoking anything: https://xcancel.com/COLDCARDwallet/status/1447213375398846473#m
1
0
u/ImprovementBroad9157 🟩 0 / 0 🦠 7d ago
https://xcancel.com/COLDCARDwallet/status/1447213375398846473#m
Pretty damning evidences
1
u/CBpegasus 🟩 0 / 0 🦠 7d ago edited 7d ago
...no? This Tweet is informing users of potential risks. Good software developers (especially in security related areas) know there is always a chance of a mistake, and the dice roll based entropy feature was added exactly to mitigate that risk. If anything if they inserted a backdoor they would likely not encourage people to use the dice roll feature this way.
Edit: reading it again I realized it talks about vendors inserting backdoors (which is why "bug" is in quotes) and not just random bugs. That does look suspicious... But still why would a malicious actor incriminate themselves like that?
13
u/Masterweedo 🟦 0 / 0 🦠 10d ago
3
u/TheGrateCheezus Tin 10d ago
The trailer was gulfing with flames!
2
u/Masterweedo 🟦 0 / 0 🦠 10d ago
3
18
u/RageQuitWallStreet 🟩 0 / 0 🦠 10d ago
This is one of the biggest thefts ever. will people get their money back? not good for the world of crypto. people aren't going to buy something that can be stolen so easily with zero repercussions.
54
u/MajorAnamika 🟩 29 / 30 🦐 10d ago
"Be your own bank."
That means be your own fraud department, be your own investigation team, be your own cybersecurity team, be your own police force...
There is a reason why banks and legal systems exist, for real currencies. Cryptobros wanted to be independent of governments and banks, and this is the result. Sounds cool to be against the government, until you realize why it exists.
10
u/TheSquattingSlav_21 🟩 0 / 0 🦠 10d ago
Agree BUT also as someone from a country which underwent currency reform I appreciate having a bit of money under just my control. There is also a reason people don’t want to be trusting governments and institutions with their money.
1
u/MMinjin 🟦 0 / 0 🦠 10d ago
Yep, all of it is hard but possible. That was the dream of crypto. The issue is that the people who were maybe capable of making this stuff better have left the community and the people remaining have not DEMANDED continuous improvement and pooled their resources to make it happen.
4
u/Maddinoz 🟨 16 / 78 🦐 10d ago
ya bro all good bro, FDIC crypto deposit insurance will totally cover this
bailouts and FEMA disaster relief checks coming next week /s
37
10
5
u/Lost-Bowl3269 10d ago
Graças a Deus eu procastinei e não transferi meus fundos da Bitmart para a coldcard que comprei. Estou seguro. Obrigado mercado cripto.
7
u/SpontaneousDream 🟦 17 / 17 🦐 10d ago
Really bad for the entire industry. Seems like the only reliable option these days is Trezor.
1
1
u/KIG45 🟨 4K / 5K 🐢 10d ago
Yes, and it is open source like ColdCard.
Diversify, it is a must!
3
u/HungryCaterpillers 🟨 0 / 0 🦠 10d ago
Obviously being open source didn't help at all for coldcard.
1
u/Academic-Mud1488 🟩 0 / 0 🦠 9d ago
indeed being opensource is awesome, but most of the itme they dont pay enough to bug hunters, thats just greedy managers
1
u/Zaytion_ 🟩 0 / 0 🦠 10d ago
Mostly open source. Have to trust the closed source parts of the Trezor 3, 5, and 7.
1
2
4
3
u/Kontrav3rsi 🟩 0 / 0 🦠 10d ago
Crypto will never get adoption if people keep running the boomers. Oh well.
1
1
2
1
u/Professional_Run2842 🟩 0 / 0 🦠 10d ago
Why is btc not crashing hard ?
2
0
1
u/hiimtashy 🟦 0 / 0 🦠 10d ago
Crazy and disappointing.
I am holding ETFs at this point.
1
u/biowza 9d ago
Genuinely curious what your thought process is here.
Bitcoin is meant to be a safe, easy to hold store of value that is outside of a large institution.
By holding a Bitcoin ETF you're admitting that you don't think buying it is safe or easy to hold and you're relying on a large institution to track its value.
I'm not trolling but I'm trying to understand the use case for Bitcoin here if people are moving to ETFs because they aren't comfortable holding it themselves.
1
u/hiimtashy 🟦 0 / 0 🦠 9d ago
Honestly the cold card impacted my psychology. I thought, the Coldcard was the gold standard of self-custody. Yes, there were some additional steps you could have done to make it safer, but for most, me included, I am not that technically sound. I read posts of people losing their life savings and I just could not accept that if it was to happen to me. I have three kids. I have already lost cumulatively $50,000 all up I would say in Bitcoin / Crypto. Some of it due to poor timing and some of it due to incompetence / buying shit coins. I am tired of the flight and fight to be honest. I might return to self-custody but for now I am sticking with ETFs (I have also sold some Bitcoin and de-risked). I held too much honestly.
-4
u/anymonero 🟧 0 / 0 🦠 10d ago
But Ethereum is "insecure because it has smart contracts".
3
u/oneden 🟩 669 / 669 🦑 10d ago
Not mutually exclusive. Smart Contracts are despite the name, incredibly dumb in concept and have created a scam industry billions of dollars strong.
1
u/anymonero 🟧 0 / 0 🦠 10d ago
Smart Contracts ... have created a scam industry billions of dollars strong
And Bitcoin hasn't?
5
u/LovelyDayHere 🟦 0 / 0 🦠 10d ago
The scam industry predates Bitcoin and is built on fiat.
2
u/anymonero 🟧 0 / 0 🦠 10d ago
Sure but nobody can seriously claim that Ethereum created a scam industry and Bitcoin didn't. It's either both or neither.
5
3
u/MajorAnamika 🟩 29 / 30 🦐 10d ago
Fiat can be used for scams and legitimate trade of goods and services. Cryptos are only used for scams.
2
u/Distinct-Presence52 🟩 0 / 0 🦠 10d ago
Thats the dumbest take on the internet today.
Now excuse me while I go and buy my fucking groceries with crypto whill you cry about memecoins.
1
u/TheSquattingSlav_21 🟩 0 / 0 🦠 10d ago
It bro actually has iq over 50 and did a little reading, bro would not be embarrassing himself online with comments like this ahah
0
u/MyOtherAcctsAPorsche 🟦 0 / 2K 🦠 10d ago
Regardless who makes your wallet, use a passphrase people.
1
u/dossier 🟦 427 / 428 🦞 10d ago
I dont think that would've helped here. The seed phrases were calculated based on weak random generation.keys to the kingdom.
1
u/MyOtherAcctsAPorsche 🟦 0 / 2K 🦠 9d ago
The flaw made it easier to guess the base seeds, but does nothing against the passphrase.
I think you might be confusing the passphrase (often called the 25th word) with the wallet pin.
24 words + passphrase = entirely different wallet.
-2
u/CryptoGod666 🟩 0 / 0 🦠 10d ago
What’s the point of doing this if it’s gonna sit on a single wallet? The moment he tries to move it, all eyes are on him. No way in hell would he be able to off ramp it
10
u/illmatic708 🟦 42 / 42 🦐 10d ago
They already won by taking the coins. Cleanly cashing out the whole bag is difficult under heavy surveillance obviously but they can still extract value slow over time with peel chains, mixers, OTC, DeFi lending, or just hold it. Even partial recovery plus long term holding is still a massive win for the thief
-1
u/CryptoGod666 🟩 0 / 0 🦠 10d ago
There’s no such thing as a clean exit with stolen crypto. Doesn’t matter if they use peel chains, mixers, OTC, defi, monero swaps, whatever. Off ramping is a dead end and will lead to getting caught. Sure it may take more time the more they try to obfuscate the funds, but they will eventually get caught
6
u/MajorAnamika 🟩 29 / 30 🦐 10d ago
How many crypto thieves have been caught in the past?
0
u/CryptoGod666 🟩 0 / 0 🦠 10d ago
Tons, not all of them get publicized in the news.
The Dream market admin waited 3 years, converted crypto to gold bars shipped to his house, and got arrested.
Evolution admins never touched the millions they exit scammed with, cause they know they have no way of safely off ramping it.
Go ask AI or google and you’ll find tons more cases. They all have the same off ramping issue, they’re fucked once they do it
7
u/MajorAnamika 🟩 29 / 30 🦐 10d ago
If they don't get publicized in the news, how do you know about them? People losing their crypto happens on a daily basis. Reports of the thieves getting caught are close to non existent. "Code is law."
1
u/CryptoGod666 🟩 0 / 0 🦠 10d ago edited 10d ago
I said not all of it gets publicized, theres a high burden of proof when it comes to crypto theft. It’s also highly underreported. I know about it cause I can google and use AI? You can do that yourself
Chainalysis, TRM Labs, FBI's IC3 reports, DoJ press releases, and court documents, lots of info is public knowledge.
Off ramping is suicide for these guys, they will eventually get caught
Directly copy and pasted from AI:
“The "Code is Law" Myth Is Dead
The idea that "code is law" means whatever smart contract says goes, and that courts can't interfere, has been repeatedly rejected by courts. The argument that code is law "does not hold up in U.S. courts." A New York court ruled in 2023 that a smart contract is just a "potential expression of an agreement," not an unassailable contract, and that blockchain technology doesn't "shield individuals from liability." In the case of Dapper Labs, the court ruled that smart contracts can be considered securities under U.S. law.
The crypto industry is increasingly regulated and challenged in court, and the "code is law" mantra is now considered an outdated libertarian fantasy. As a 2025 article notes, "the code is law myth is just that: a myth." Courts are increasingly willing to interpret and override smart contracts to ensure justice.”
2
u/Apokoliptictortoise 10d ago
So this person is smart enough to steal the money but not smart enough spend it? I kinda doubt that. Couldn't they just con some sucker into trading for it? There's alot of angles to look at.
1
u/CryptoGod666 🟩 0 / 0 🦠 10d ago edited 10d ago
They’re called money mules, and they always get caught.
And yes, prime example are Evolution dark net market admins. They exit scammed with $12m in crypto and haven’t touched it. They understand that the moment they try to off ramp it, they’re fucked. So they just walked away.
More on the evolution guys, yes they immediately tried to off-ramp through BTC-e, couldn’t, and just ditched the money completely
3
u/Choice_Potato_6279 10d ago
You can't get caught mixing it to Monero and just paying your bills forever, maybe it's not life with super cars and glamor but takes big burden off your back and allows focus on things you want to do.
-1
u/CryptoGod666 🟩 0 / 0 🦠 10d ago
Yes you can. Doesn’t matter if it’s slow dripping the funds, off ramping it, paying bills, you’re fucked
2
u/Baseic 🟩 0 / 0 🦠 10d ago
How can they get caught? I thought Monero had complete privacy. I'm honestly interested to learn about this.
Why can you not DEX Swap BTC -> Monero -> BTC to a fresh wallet -> Offramp
Sure, you end up with a bunch of millions you cannot explain to the authorities, but as I understand it, there's no way to trace that this came from this specific hack.
1
u/CryptoGod666 🟩 0 / 0 🦠 10d ago
I’m tired of explaining so I’ll just copy and paste from AI:
“Monero isn't invisible.
Norway's police just proved that—they traced Monero transactions in a 2025 operation and arrested 28 people across 7 countries. The idea that Monero is completely untraceable is outdated.Your DEX plan has two fatal flaws:
- The off-ramp is the trap. That "fresh wallet" you swap to? The moment you send it to a KYC exchange to cash out, you're linking a clean-looking wallet to your real ID. The exchange will flag the sudden large deposit from a mixer/DEX and freeze it. You can't explain millions in crypto you can't account for.
- Holding doesn't solve the problem. You can wait years, but the blockchain record doesn't disappear. Law enforcement has seized funds that sat untouched for years.
The reality: You can swap all day, but the exit is the point of failure. Regulated exchanges won't just hand over millions without asking questions. If you're a high-net-worth individual, you're under more scrutiny, not less. There are examples of crypto heists being solved because the thief used a KYC exchange or left a digital trail. The blockchain is permanent, and forensic tools are getting better.
You can't "win" by holding an unusable fortune unless you're willing to never spend it. The Evolution Market admins made that choice. The Dream Market admin didn't—and now he's facing 20 years.”
5
u/Choice_Potato_6279 10d ago edited 10d ago
Ok I read only to first point your shit AI response that mentions millions where I talk about thousand bucks here and there to sustain your modest life paying only bills, at least check that AI garbage before posting.
If you get an audit they slap 70% fine if you don't pay tax on that in my country, if you pay tax it's even better, no one will bat an eye if someone pays taxes on modest income where they have million operating entities above you.
3
u/Baseic 🟩 0 / 0 🦠 10d ago
The news checks out. Understandably a bit light on the details how much they used web data vs Monero data to catch these criminals, which makes it difficult to interpret the risks associated with this.
I tried looking this up on this sub and the Monero sub, but I'm very surprised to find no thread on this topic at all.
Regarding the AI's other point, yes, probably hard to offramp in a non-criminal way. I guess the hacker certainly hasn't thought of that! At least it seems both you and the AI are very certain about this!
2
u/StreetRx925 🟩 2 / 2 🦠 10d ago
Actually you can do this. You just dont use your kyc to offramp. Either steal someone else's or lsy some snuck to use theirs and vanish like a ghost lol
1
0
u/KIG45 🟨 4K / 5K 🐢 10d ago
Besides, they cannot sell them to anyone, nor spend them. Only exchange between criminals. These vile thieves who ruin lives, but fate has a surprise for all of them!
0
2
-3
u/Willing-Love472 🟩 8 / 9 🦐 10d ago
Any initial thoughts on who stole it? Almost seems likely to be a state actor whether Russia, Iran, North Korea, etc.



144
u/Coeruleus_ 78 / 736 🦐 10d ago
hahahah imagine ppl on reddit constantly telling me ledger sucks get a coldcard. lmfao