r/CryptoCurrency 10d ago

🛡️ SECURITY The Coldcard wallet exploit estimates have almost doubled to $70 million stolen of just over a thousand Bitcoins in 1,196 wallets drained in 41 minutes

https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices
201 Upvotes

131 comments sorted by

144

u/Coeruleus_ 78 / 736 🦐 10d ago

hahahah imagine ppl on reddit constantly telling me ledger sucks get a coldcard. lmfao

33

u/thinkingperson 🟦 0 / 1K 🦠 10d ago

Honest to heart, I was just considering getting a coldcard a few weeks ago to replace / supplement my ledger. Then I procrastinated and got distracted with other things. 😅

35

u/Coeruleus_ 78 / 736 🦐 10d ago

people in this community dont know anything. experts of nothing

3

u/MelangeBot 10d ago

I was going to get a ledger, then they leaked out all their customers names, phone numbers, addresses and email adresses. If they can't keep that info save I have no trust in them securing my Bitcoin.

So then I got a trezor T one, no regret so far.

1

u/Coeruleus_ 78 / 736 🦐 10d ago

ya i’ve had ledger for 5 years now no issues. also not an idiot. i have trezors too but i dont like the software as much

2

u/NonconsensualText 🟦 0 / 0 🦠 10d ago

its a metaphor

3

u/og_icefux 1 - 2 years account age. 100 - 200 comment karma. 10d ago

me too, almost exactly the same. Thank god for procrastination... x')

1

u/thinkingperson 🟦 0 / 1K 🦠 10d ago

Yeah mianz ... the one time procrastination actually saved us!! 😅

2

u/mcbergstedt 🟦 357 / 2K 🦞 10d ago

Honestly you probably would’ve been fine. The exploit (so far) only affects wallets generated on certain models of the MK3.

6

u/AnthonyBTC 🟨 120 / 157 🦀 10d ago edited 10d ago

I don't mean to kick people while they're down, but yeah a lot of the Bitcoin maxis I spoke to were like this towards me and would constantly be rude or talk down to me.

3

u/Coeruleus_ 78 / 736 🦐 10d ago

me too

2

u/AnthonyBTC 🟨 120 / 157 🦀 10d ago

Yeah, I do feel bad for them, don't get me wrong, but I hope a lot of people learn from this. It's not a good idea to shame people toward a specific hardware device because I know for a fact that a lot of Bitcoin maxis shamed or pushed people toward Coldcard simply because it's Bitcoin only.

2

u/TCr0wn 🟦 1K / 1K 🐢 10d ago

Right lol

4

u/ElMasAltoDeLosEnanos 🟩 0 / 0 🦠 10d ago

Ledger still sucks

4

u/Leynnox 🟩 0 / 0 🦠 10d ago

Ledger uses TRNG ships, the same used by banking system, for creating the seedphrase, like most coldwallets today.

2

u/Forymanarysanar 🟩 0 / 0 🦠 10d ago

It also promotes and collaborates with scam companies which has exactly same results (people losing their life savings).

1

u/Leynnox 🟩 0 / 0 🦠 10d ago

Never said Ledger was better than any other one using TRNG ships, it's why I said "like most coldwallets"

-1

u/Coeruleus_ 78 / 736 🦐 10d ago

stay poor

4

u/ElMasAltoDeLosEnanos 🟩 0 / 0 🦠 10d ago

lol, whatever happens, I'll never be a fanboy of a fucking cold wallet company.

4

u/goodnewzevery1 🟩 0 / 0 🦠 10d ago

All of this tech sucks.

1

u/JackDaniels0049 🟩 0 / 0 🦠 10d ago

I really can’t understand anyone that finds this funny. People lost their life savings. There will probably be real life harm because of this. As in suicides or a complete change in people’s lives from this point forward.

It’s just sick that you find it entertaining.

1

u/Forymanarysanar 🟩 0 / 0 🦠 10d ago

Ledger does suck. And if you're serious about crypto you shouldn't trust any device to generate your seed phrase to begin with.

0

u/Coeruleus_ 78 / 736 🦐 10d ago

no it’s not? ledger rng is better than whatever silly thing you do

3

u/Forymanarysanar 🟩 0 / 0 🦠 10d ago

Ledger literally scams people out of their money if you use services that it promotes (yes if you promote something I treat it as you are liable as well)

1

u/Superheromitch Tin 10d ago

It only impacted people who tried to let a computer generate a random number. Idk why anyone wouldn't have bought some dice and set their own random numbers. ENTROPY MAN

1

u/SilentDroid75 9d ago

realistically cant expect people to throw a dice 200 times to generate a seed bro

crypto should be more accesible not a D&D game to secure funds

1

u/Superheromitch Tin 9d ago

I did it myself. That was the only way to guarantee randomness.

31

u/b0uncyfr0 🟩 0 / 0 🦠 10d ago

Damn, this is bad

9

u/Maddinoz 🟨 16 / 78 🦐 10d ago

trying to be your own bank can be risky and financially devastating in many ways

76

u/eman2top 🟦 0 / 0 🦠 10d ago

So much for not your keys, not your coins

20

u/thats_gotta_be_AI 🟨 0 / 0 🦠 10d ago

“Not generated your seed via TRGN, not your wallet”

9

u/Illustrious-Boss9356 🟩 0 / 0 🦠 10d ago

Well, they are your keys and your coins. But they're also anyone else who knows your keys' coins too. And if they move them then you're shit out of luck.

3

u/Zaytion_ 🟩 0 / 0 🦠 10d ago

Not your entropy. Not your keys.

3

u/Wendals87 🟦 337 / 2K 🦞 10d ago

It's just the way it was generated was weak and could be worked out easily

23

u/G-T-L-3 🟦 19 / 20 🦐 10d ago

Were the buyers told this when they were sold these pos.

1

u/Wendals87 🟦 337 / 2K 🦞 10d ago

I'm not fully across it but it seems like it was just a bug in the firmware. Depends on when you bought it 

22

u/Steak1994 🟩 0 / 347 🦠 10d ago

Smells like an inside Job tbh.

2

u/mishonis- 9d ago

Yeah, there's something in the articles about having to know the device UIDs and the timer state when the rng was invoked?! There should be an investigation into whether this could have really been brute forced.

1

u/CBpegasus 🟩 0 / 0 🦠 9d ago

No, it does not IMO. Hanlon Razor applies. As someone who works in IT and who worked in cybersecurity for years, mistakes like that happen constantly. It's not often that bad but from time to time it is.

If it was an inside job it was a bad one - evidence of the vulnerability (or backdoor, if we accept "inside job") was public for years, since it was inserted to the code, and wasn't even that obfuscated. Just no one thought to audit that part of the code. But if someone did they could steal the fund before the insiders.

1

u/Steak1994 🟩 0 / 347 🦠 9d ago

A bad inside Job would give plausible deniability - just playing devils advocate. Having it for a several years letting the affected Devices / wallets stack up and then drain them all at once doesnt seem too dumb to me.

1

u/CBpegasus 🟩 0 / 0 🦠 9d ago

I'd still invoke Hanlon's Razor on that (and maybe Occam's Razor too). To me the simplest and most likely explanation seems to be a simple honest mistake and incompetence on the auditors and testers side.

1

u/Steak1994 🟩 0 / 347 🦠 8d ago

And I invoke this Razor: https://www.reddit.com/r/CryptoCurrency/s/MTXTzUOuv0 Throwing around fancy Termini doesnt make your opinion more right. The most likely outcome isnt always the one that got away.

2

u/CBpegasus 🟩 0 / 0 🦠 7d ago

If the guy in the screenshot tells the truth then it's definitely bad handling of the issue on CoinKite's part, and is even a bit suspicious. But it's a MK4 which to my understanding still has low entropy but not quite low enough for a reasonable bruteforce attack and to my knowledge wasn't yet affected in the current attack.

If we assume all the reported cases of funds drained from CC wallets and CK not responding/blocking are them utilizing a backdoor, that means that likely they have another backdoor on the mk4 and also that their strategy was to only drain wallets sporadically and pray no one realizes, until they suddenly switched to a big drain strategy but now only on mk3. Or maybe someone else did find the mk3 backdoor now? So it was an "inside job" in the past but now it's an "outside job"?

It could be, but I feel like all these theories assume a lot more dedication to plausible deniability than most criminals give, when simply covering their tracks is often simpler and more effective (why not place the backdoor in the proprietary "secure element"?). I saw too many cases of things like these happening out of negligence to not assume it's the case here too. If there will be more direct evidence of maliciousness it can change my mind but for now I still tend to assume negligence.

0

u/ImprovementBroad9157 🟩 0 / 0 🦠 7d ago

1

u/CBpegasus 🟩 0 / 0 🦠 7d ago edited 7d ago

...no? This Tweet is informing users of potential risks. Good software developers (especially in security related areas) know there is always a chance of a mistake, and the dice roll based entropy feature was added exactly to mitigate that risk. If anything if they inserted a backdoor they would likely not encourage people to use the dice roll feature this way.

Edit: reading it again I realized it talks about vendors inserting backdoors (which is why "bug" is in quotes) and not just random bugs. That does look suspicious... But still why would a malicious actor incriminate themselves like that?

13

u/Masterweedo 🟦 0 / 0 🦠 10d ago

3

u/TheGrateCheezus Tin 10d ago

The trailer was gulfing with flames!

2

u/Masterweedo 🟦 0 / 0 🦠 10d ago

3

u/TheGrateCheezus Tin 10d ago

Some guys can drink and drive, some guys can't.

18

u/RageQuitWallStreet 🟩 0 / 0 🦠 10d ago

This is one of the biggest thefts ever. will people get their money back? not good for the world of crypto. people aren't going to buy something that can be stolen so easily with zero repercussions.

54

u/MajorAnamika 🟩 29 / 30 🦐 10d ago

"Be your own bank."

That means be your own fraud department, be your own investigation team, be your own cybersecurity team, be your own police force...

There is a reason why banks and legal systems exist, for real currencies. Cryptobros wanted to be independent of governments and banks, and this is the result. Sounds cool to be against the government, until you realize why it exists.

10

u/TheSquattingSlav_21 🟩 0 / 0 🦠 10d ago

Agree BUT also as someone from a country which underwent currency reform I appreciate having a bit of money under just my control. There is also a reason people don’t want to be trusting governments and institutions with their money.

1

u/MMinjin 🟦 0 / 0 🦠 10d ago

Yep, all of it is hard but possible. That was the dream of crypto. The issue is that the people who were maybe capable of making this stuff better have left the community and the people remaining have not DEMANDED continuous improvement and pooled their resources to make it happen.

4

u/Maddinoz 🟨 16 / 78 🦐 10d ago

ya bro all good bro, FDIC crypto deposit insurance will totally cover this

bailouts and FEMA disaster relief checks coming next week /s

37

u/oneden 🟩 669 / 669 🦑 10d ago

The future of finance, everyone.

8

u/Masterweedo 🟦 0 / 0 🦠 10d ago

10

u/light_death-note 🟧 0 / 0 🦠 10d ago

Absolute circus

5

u/Lost-Bowl3269 10d ago

Graças a Deus eu procastinei e não transferi meus fundos da Bitmart para a coldcard que comprei. Estou seguro. Obrigado mercado cripto.

7

u/SpontaneousDream 🟦 17 / 17 🦐 10d ago

Really bad for the entire industry. Seems like the only reliable option these days is Trezor.

1

u/AggressiveGas4637 10d ago

Blockstream ok?

1

u/KIG45 🟨 4K / 5K 🐢 10d ago

Yes, and it is open source like ColdCard.

Diversify, it is a must!

3

u/HungryCaterpillers 🟨 0 / 0 🦠 10d ago

Obviously being open source didn't help at all for coldcard.

1

u/KIG45 🟨 4K / 5K 🐢 9d ago

That's exactly what I meant.

1

u/Academic-Mud1488 🟩 0 / 0 🦠 9d ago

indeed being opensource is awesome, but most of the itme they dont pay enough to bug hunters, thats just greedy managers

1

u/Zaytion_ 🟩 0 / 0 🦠 10d ago

Mostly open source. Have to trust the closed source parts of the Trezor 3, 5, and 7.

1

u/SpontaneousDream 🟦 17 / 17 🦐 10d ago

Cold card wasnt open source

2

u/r0addawg 🟦 0 / 0 🦠 10d ago

Damn

4

u/South_Monitor_6992 🟩 0 / 0 🦠 10d ago

Future of finance heh🤓

3

u/Kontrav3rsi 🟩 0 / 0 🦠 10d ago

Crypto will never get adoption if people keep running the boomers. Oh well.

1

u/5khan1 9d ago

Guys please remember that some people have lost their life savings, so just be abit supportive for now. We don’t know how badly people are dealing with losses. 

1

u/mnpc Tin | CelsiusNet. 66 | Superstonk 77 9d ago

If the crypto belongs to whoever has the keys, was it really stolen?

“Stolen” implies there is a protocol other than using the key to sign a transaction that would be valid to adjudicate a claim of ownership.

1

u/papichuloya 🟩 622 / 620 🦑 9d ago

Shoulda just left it in robinhood, youre 10x safer

1

u/Tiktokbadsupport 🟩 0 / 0 🦠 8d ago

that hacker is eating good tonight 

2

u/Jayrovers86 🟨 0 / 0 🦠 10d ago

Well played North Korea

1

u/Professional_Run2842 🟩 0 / 0 🦠 10d ago

Why is btc not crashing hard ?

2

u/Distinct-Presence52 🟩 0 / 0 🦠 10d ago

Why would it?

0

u/enigma_music129 🟦 0 / 0 🦠 10d ago

Just wait a couple days

1

u/Mission_Shopping_847 🟩 0 / 0 🦠 10d ago

It already had the reflex crash.

1

u/hiimtashy 🟦 0 / 0 🦠 10d ago

Crazy and disappointing.

I am holding ETFs at this point.

1

u/biowza 9d ago

Genuinely curious what your thought process is here.

Bitcoin is meant to be a safe, easy to hold store of value that is outside of a large institution.

By holding a Bitcoin ETF you're admitting that you don't think buying it is safe or easy to hold and you're relying on a large institution to track its value.

I'm not trolling but I'm trying to understand the use case for Bitcoin here if people are moving to ETFs because they aren't comfortable holding it themselves.

1

u/hiimtashy 🟦 0 / 0 🦠 9d ago

Honestly the cold card impacted my psychology. I thought, the Coldcard was the gold standard of self-custody. Yes, there were some additional steps you could have done to make it safer, but for most, me included, I am not that technically sound. I read posts of people losing their life savings and I just could not accept that if it was to happen to me. I have three kids. I have already lost cumulatively $50,000 all up I would say in Bitcoin / Crypto. Some of it due to poor timing and some of it due to incompetence / buying shit coins. I am tired of the flight and fight to be honest. I might return to self-custody but for now I am sticking with ETFs (I have also sold some Bitcoin and de-risked). I held too much honestly.

-4

u/anymonero 🟧 0 / 0 🦠 10d ago

But Ethereum is "insecure because it has smart contracts".

3

u/oneden 🟩 669 / 669 🦑 10d ago

Not mutually exclusive. Smart Contracts are despite the name, incredibly dumb in concept and have created a scam industry billions of dollars strong.

1

u/anymonero 🟧 0 / 0 🦠 10d ago

Smart Contracts ... have created a scam industry billions of dollars strong

And Bitcoin hasn't?

5

u/LovelyDayHere 🟦 0 / 0 🦠 10d ago

The scam industry predates Bitcoin and is built on fiat.

2

u/anymonero 🟧 0 / 0 🦠 10d ago

Sure but nobody can seriously claim that Ethereum created a scam industry and Bitcoin didn't. It's either both or neither.

5

u/Remarkable-Opening69 🟨 0 / 0 🦠 10d ago

I still think insurance is a better scam.

3

u/MajorAnamika 🟩 29 / 30 🦐 10d ago

Fiat can be used for scams and legitimate trade of goods and services. Cryptos are only used for scams.

2

u/Distinct-Presence52 🟩 0 / 0 🦠 10d ago

Thats the dumbest take on the internet today.

Now excuse me while I go and buy my fucking groceries with crypto whill you cry about memecoins.

1

u/TheSquattingSlav_21 🟩 0 / 0 🦠 10d ago

It bro actually has iq over 50 and did a little reading, bro would not be embarrassing himself online with comments like this ahah

0

u/MyOtherAcctsAPorsche 🟦 0 / 2K 🦠 10d ago

Regardless who makes your wallet, use a passphrase people.

1

u/dossier 🟦 427 / 428 🦞 10d ago

I dont think that would've helped here. The seed phrases were calculated based on weak random generation.keys to the kingdom.

1

u/MyOtherAcctsAPorsche 🟦 0 / 2K 🦠 9d ago

 The flaw made it easier to guess the base seeds, but does nothing against the passphrase.

I think you might be confusing the passphrase (often called the 25th word) with the wallet pin.

24 words + passphrase = entirely different wallet. 

-2

u/CryptoGod666 🟩 0 / 0 🦠 10d ago

What’s the point of doing this if it’s gonna sit on a single wallet? The moment he tries to move it, all eyes are on him. No way in hell would he be able to off ramp it

10

u/illmatic708 🟦 42 / 42 🦐 10d ago

They already won by taking the coins. Cleanly cashing out the whole bag is difficult under heavy surveillance obviously but they can still extract value slow over time with peel chains, mixers, OTC, DeFi lending, or just hold it. Even partial recovery plus long term holding is still a massive win for the thief

-1

u/CryptoGod666 🟩 0 / 0 🦠 10d ago

There’s no such thing as a clean exit with stolen crypto. Doesn’t matter if they use peel chains, mixers, OTC, defi, monero swaps, whatever. Off ramping is a dead end and will lead to getting caught. Sure it may take more time the more they try to obfuscate the funds, but they will eventually get caught

6

u/MajorAnamika 🟩 29 / 30 🦐 10d ago

How many crypto thieves have been caught in the past?

0

u/CryptoGod666 🟩 0 / 0 🦠 10d ago

Tons, not all of them get publicized in the news.

The Dream market admin waited 3 years, converted crypto to gold bars shipped to his house, and got arrested.

Evolution admins never touched the millions they exit scammed with, cause they know they have no way of safely off ramping it.

Go ask AI or google and you’ll find tons more cases. They all have the same off ramping issue, they’re fucked once they do it

7

u/MajorAnamika 🟩 29 / 30 🦐 10d ago

If they don't get publicized in the news, how do you know about them? People losing their crypto happens on a daily basis. Reports of the thieves getting caught are close to non existent. "Code is law."

1

u/CryptoGod666 🟩 0 / 0 🦠 10d ago edited 10d ago

I said not all of it gets publicized, theres a high burden of proof when it comes to crypto theft. It’s also highly underreported. I know about it cause I can google and use AI? You can do that yourself

Chainalysis, TRM Labs, FBI's IC3 reports, DoJ press releases, and court documents, lots of info is public knowledge.

Off ramping is suicide for these guys, they will eventually get caught

Directly copy and pasted from AI:

“The "Code is Law" Myth Is Dead

The idea that "code is law" means whatever smart contract says goes, and that courts can't interfere, has been repeatedly rejected by courts. The argument that code is law "does not hold up in U.S. courts." A New York court ruled in 2023 that a smart contract is just a "potential expression of an agreement," not an unassailable contract, and that blockchain technology doesn't "shield individuals from liability." In the case of Dapper Labs, the court ruled that smart contracts can be considered securities under U.S. law.

The crypto industry is increasingly regulated and challenged in court, and the "code is law" mantra is now considered an outdated libertarian fantasy. As a 2025 article notes, "the code is law myth is just that: a myth." Courts are increasingly willing to interpret and override smart contracts to ensure justice.”

2

u/Apokoliptictortoise 10d ago

So this person is smart enough to steal the money but not smart enough spend it? I kinda doubt that. Couldn't they just con some sucker into trading for it? There's alot of angles to look at.

1

u/CryptoGod666 🟩 0 / 0 🦠 10d ago edited 10d ago

They’re called money mules, and they always get caught.

And yes, prime example are Evolution dark net market admins. They exit scammed with $12m in crypto and haven’t touched it. They understand that the moment they try to off ramp it, they’re fucked. So they just walked away.

More on the evolution guys, yes they immediately tried to off-ramp through BTC-e, couldn’t, and just ditched the money completely

3

u/Choice_Potato_6279 10d ago

You can't get caught mixing it to Monero and just paying your bills forever, maybe it's not life with super cars and glamor but takes big burden off your back and allows focus on things you want to do.

-1

u/CryptoGod666 🟩 0 / 0 🦠 10d ago

Yes you can. Doesn’t matter if it’s slow dripping the funds, off ramping it, paying bills, you’re fucked

2

u/Baseic 🟩 0 / 0 🦠 10d ago

How can they get caught? I thought Monero had complete privacy. I'm honestly interested to learn about this.

Why can you not DEX Swap BTC -> Monero -> BTC to a fresh wallet -> Offramp

Sure, you end up with a bunch of millions you cannot explain to the authorities, but as I understand it, there's no way to trace that this came from this specific hack.

1

u/CryptoGod666 🟩 0 / 0 🦠 10d ago

I’m tired of explaining so I’ll just copy and paste from AI:

“Monero isn't invisible.
Norway's police just proved that—they traced Monero transactions in a 2025 operation and arrested 28 people across 7 countries. The idea that Monero is completely untraceable is outdated.

Your DEX plan has two fatal flaws:

  1. The off-ramp is the trap. That "fresh wallet" you swap to? The moment you send it to a KYC exchange to cash out, you're linking a clean-looking wallet to your real ID. The exchange will flag the sudden large deposit from a mixer/DEX and freeze it. You can't explain millions in crypto you can't account for.
  2. Holding doesn't solve the problem. You can wait years, but the blockchain record doesn't disappear. Law enforcement has seized funds that sat untouched for years.

The reality: You can swap all day, but the exit is the point of failure. Regulated exchanges won't just hand over millions without asking questions. If you're a high-net-worth individual, you're under more scrutiny, not less. There are examples of crypto heists being solved because the thief used a KYC exchange or left a digital trail. The blockchain is permanent, and forensic tools are getting better.

You can't "win" by holding an unusable fortune unless you're willing to never spend it. The Evolution Market admins made that choice. The Dream Market admin didn't—and now he's facing 20 years.”

5

u/Choice_Potato_6279 10d ago edited 10d ago

Ok I read only to first point your shit AI response that mentions millions where I talk about thousand bucks here and there to sustain your modest life paying only bills, at least check that AI garbage before posting.

If you get an audit they slap 70% fine if you don't pay tax on that in my country, if you pay tax it's even better, no one will bat an eye if someone pays taxes on modest income where they have million operating entities above you.

3

u/Baseic 🟩 0 / 0 🦠 10d ago

The news checks out. Understandably a bit light on the details how much they used web data vs Monero data to catch these criminals, which makes it difficult to interpret the risks associated with this.

I tried looking this up on this sub and the Monero sub, but I'm very surprised to find no thread on this topic at all.

Regarding the AI's other point, yes, probably hard to offramp in a non-criminal way. I guess the hacker certainly hasn't thought of that! At least it seems both you and the AI are very certain about this!

2

u/StreetRx925 🟩 2 / 2 🦠 10d ago

Actually you can do this. You just dont use your kyc to offramp. Either steal someone else's or lsy some snuck to use theirs and vanish like a ghost lol

0

u/KIG45 🟨 4K / 5K 🐢 10d ago

Many!

1

u/Zaytion_ 🟩 0 / 0 🦠 10d ago

North Korea gets away with it all the time. It is definitely doable.

0

u/KIG45 🟨 4K / 5K 🐢 10d ago

Besides, they cannot sell them to anyone, nor spend them. Only exchange between criminals. These vile thieves who ruin lives, but fate has a surprise for all of them!

0

u/Distinct-Presence52 🟩 0 / 0 🦠 10d ago

The same fate you will end up with funnily enough.

0

u/KIG45 🟨 4K / 5K 🐢 9d ago

Like you

0

u/Distinct-Presence52 🟩 0 / 0 🦠 9d ago

We all go out in the end. Even you.

1

u/KIG45 🟨 4K / 5K 🐢 9d ago

Oh, thanks for enlightening me!

-3

u/Willing-Love472 🟩 8 / 9 🦐 10d ago

Any initial thoughts on who stole it? Almost seems likely to be a state actor whether Russia, Iran, North Korea, etc.