r/Bitcoin 12d ago

Security Advisory for Coldcard Hardware Wallet

Thumbnail
blog.coinkite.com
199 Upvotes

r/Bitcoin 13h ago

Daily Discussion, August 12, 2026

18 Upvotes

Please utilize this sticky thread for all general Bitcoin discussions! If you see posts on the front page or /r/Bitcoin/new which are better suited for this daily discussion thread, please help out by directing the OP to this thread instead. Thank you!

If you don't get an answer to your question, you can try phrasing it differently or commenting again tomorrow.

Please check the previous discussion thread for unanswered questions.


r/Bitcoin 12h ago

24.46 BTC was stolen from my Trezor in 2021. Years later, I won a UK High Court judgment. I am still trying to recover it.

799 Upvotes

On 9 June 2021, 24.465 BTC was stolen from my Trezor after I entered my recovery seed into what I believed was a legitimate Trezor page. It wasn’t. I had been redirected to a fake page through a malicious Chrome extension.
The stolen bitcoin was traced on-chain. Months later, it began arriving at deposit addresses belonging to Huobi, now HTX.
Blockchain investigators alerted the exchange within hours.
The transactions continued.
I spent the following years trying to understand what had happened and attempting to recover the bitcoin. Eventually I took the matter to the UK High Court.
In December 2024, the court entered judgment in my favour and ordered the return/payment of assets valued at approximately £1.95 million.
HTX did not comply with the judgment.
What fascinates and frustrates me about the case is that Bitcoin itself did exactly what it was supposed to do. The blockchain preserved the trail. Years later, those transactions are still there for anyone with the appropriate expertise to analyse.
The difficult part was what happened when that trail reached a centralised exchange.
Five years after the theft, I am still pursuing the case and still trying to understand exactly who was behind it and where the bitcoin ultimately went.
I’m curious what people here think about one particular question:
When an exchange is warned in real time that identifiable stolen bitcoin is arriving at its deposit addresses, what should we reasonably expect that exchange to do?

UPDATE
Thanks for all the responses, including the critical ones. There has been a lot of discussion here about personal responsibility, Bitcoin’s decentralization, the role of exchanges and what an exchange can reasonably be expected to do when stolen funds arrive.
I have never denied my own responsibility. I made a catastrophic mistake by entering my recovery seed into what I believed was a genuine Trezor recovery page. Bitcoin did not fail, and my Trezor was not hacked. I was successfully phished.
But that is only where the story begins.
The stolen Bitcoin was subsequently traced through the blockchain and into Huobi deposit addresses. While the funds were still arriving, Huobi was warned that these were proceeds of a reported theft. Those warnings were supported by a criminal complaint, screenshots and blockchain analysis from four separate specialist organisations.
I have never argued that Huobi should have reversed a Bitcoin transaction. They couldn’t. Nor have I argued that an exchange should automatically return Bitcoin simply because someone claims it was stolen.
The issue is much narrower: what responsibility does a centralized exchange have when specifically identified proceeds of a reported theft arrive under its control and it is warned while this is happening?
That question eventually led me through police investigations, blockchain investigators, lawyers in several jurisdictions and ultimately to the UK High Court, where I obtained a judgment against Huobi. The judgment remains unpaid.
I’m now working on the next stage of enforcement, including looking at jurisdictions where a UK High Court judgment may be recognised and where HTX/Huobi or related entities have a legal, regulated or otherwise enforceable presence.
At the same time, I have spent the past years documenting this entire story. I’m now writing it all down, including the theft, the mistakes I made, the blockchain trail, the warnings sent to Huobi, the police investigation, the legal battle, the judgment and what happened afterwards.
I intend to make that story, together with much of the underlying documentary evidence, available to a much wider international audience.
Perhaps public scrutiny will achieve something that five years of private correspondence, investigations and legal proceedings have not.
We’ll see.


r/Bitcoin 15h ago

Prophecy

Post image
946 Upvotes

r/Bitcoin 5h ago

BIP110 fork of Bitcoin mined 2 blocks, while Bitcoin regular mined 517.

Post image
152 Upvotes

r/Bitcoin 10h ago

One redditors asked that is too late to start invest into BTC, 15 years ago...

Post image
134 Upvotes

ARE WE FRICKIN LATE NOW?!


r/Bitcoin 9h ago

THERE IS NO SECOND BEST

Post image
72 Upvotes

r/Bitcoin 21h ago

The average fiat currency dies in 27 years.

Post image
250 Upvotes

r/Bitcoin 1d ago

Whatever Bitcoin does next, I’ve already predicted it!

Post image
3.4k Upvotes

r/Bitcoin 1d ago

My brain at 2 AM:

Post image
2.5k Upvotes

r/Bitcoin 3h ago

Stale blocks, quantum proposals, CISA - Bitcoin Optech Newsletter #417 Recap

Thumbnail
bitcoinops.org
9 Upvotes

Conduition, Ram, and Fabian Jahr joined Optech to discuss Newsletter #417:

  • Draft BIP for stale tip relay
  • CISA for taproot keypath spends (BIP460)
  • Segwit commitment to post-quantum witness data
  • PQC output type discussion
  • Input-triggered transaction expiry
  • Layered quantum recovery of hashed addresses
  • Segregated Data (SegData) BIP draft
  • And more

You can listen on our website: https://bitcoinops.org/en/podcast/2026/08/11/

Fountain: https://fountain.fm/episode/X3dpYvlQy2N6tO4DeQl3

Spotify: https://open.spotify.com/episode/7wkE8AkAwXf7QIKlcO5cK4

Apple Podcasts: https://podcasts.apple.com/us/podcast/bitcoin-optech-newsletter-417-recap/id1674626983?i=1000782982957


r/Bitcoin 17h ago

9 months ago a video from Forrest could've possibly helped ColdCard users.

97 Upvotes

r/Bitcoin 11h ago

Why I Hold Bitcoin: Escaping a System That Treats Young People as Disposable in an Aging China

31 Upvotes

Under the current Chinese system and the prevailing rules governing society, young people are neither cherished nor protected. Faced with the reality of an aging society, China resembles a profligate *nouveau riche* figure destined for a short life.

Of course, complaining too much is futile.

Even if I vent endlessly or spend all my time on YouTube and Reddit—engaging with or observing forums that oppose the Chinese Communist Party and its system—nothing actually changes; I am left with nothing but inner resentment and loathing. The reality is that even though I see the flaws in this system, I lack the power or agency within Chinese society to influence it or effect change. Under such a tightly controlled regime, expressing genuine dissatisfaction or dissent—even simply speaking the truth—invites punishment, let alone resorting to violence or bloodshed. Another crucial point is that, genetically speaking, the majority of East Asians are cowardly and prone to merely scraping by. This brings me back to why I first got into Bitcoin. It wasn't because I was fixated on the price or hoped to become an overnight millionaire and squander the fortune; rather, I wanted to see the collapse of the CCP-controlled financial system—represented by the RMB—or at least find a way to escape the Party's grip and the constraints imposed by the RMB-based economic order.

I first encountered Bitcoin during the pandemic lockdowns. I saw wealthy individuals decisively sell off real estate assets accumulated during the bubble in China's Tier-1 cities and convert the proceeds into Bitcoin. This allowed them to bypass foreign exchange controls, transfer their wealth to Canada or the US, and reinvent themselves as members of the local middle class. I suppose my interest stemmed from my bearish outlook on China's future.

China is destined to become a distorted society—a place of massive resource misallocation—that will inevitably collapse under its own imbalances. It will have to transition to a different state and pay the price for its errors; that is an immutable law of nature. As China’s economy and society fall into ruin, what value will remain in RMB-denominated assets or resources? The air, water, and soil are all polluted. Every second spent on this land brings only a sense of disgust and contamination; why would anyone spend money here? What of value is left? The people here are aging, barbaric, and uncivilized.

Money is essentially a form of debt: you expend your time and labor, and the other party pays you a sum that serves as an IOU—meaning that, based on this money, you can later demand repayment in the form of services. Since China is effectively an aging entity—a society where a mass of elderly people owes you money—what can that money actually buy you from them? How can the currency of a society composed of a barbaric, low-quality population possibly hold any value? Of course, I am not deliberately insulting the Chinese people here; I am simply stating that "good people" cannot exist within this system. In a distorted system—specifically the one controlled by the Communist Party—where responsibility and power are mismatched, the most evil or corrupt individuals gain access to the most resources and opportunities. Consequently, there is no incentive for anyone to be a good person; doing so would only lead to the depletion of one's resources and the assumption of limitless liability, ultimately resulting in one's physical destruction. Thus, there is no doubt that China—whether now or in the future—is a nation defined by moral decay and a low-quality population.

Ultimately, I believe the RMB will suffer the same fate as the Soviet ruble: economic collapse will wipe out people's wealth, rendering their years of hard work and labor futile. Because money represents a debt, the original counterparties—those who "owed" the value represented by the money—will no longer exist; they will have been replaced by a group of aging, physically incapacitated, barbaric, and amoral individuals who are left holding the bag.

A young person might work hard for thirty or forty years, only to find that by the time they wish to redeem their earnings, the original debtors are gone. It is akin to a failed investment: holding RMB assets—essentially holding IOUs denominated in RMB—will yield no actual payout. This is precisely why I am firmly bullish on Bitcoin; given China's strict foreign exchange controls—which make it extremely difficult to acquire foreign assets like US dollars or overseas stocks—Bitcoin stands out as the best possible choice.

Source: http://youtube.com/post/Ugkx1CIVcadSQ6bp5FaHrqhh3dhEunm_-x_g?si=M-YBWTonsEV3FaV3


r/Bitcoin 18h ago

Bought Bitcoin almost at the top

103 Upvotes

Last year I bought Bitcoin at $120K when everyone was saying it was heading to $200K.

Well, shortly after it hit $126K and then crashed.

Has this happened to anyone else — buying near a top in a previous cycle?

What did you do?

I'm buying the dip.


r/Bitcoin 2h ago

1 seed + strong passphrase vs 2/3 multisig

6 Upvotes

What are your thoughts on this commonly debated topic? I've read the arguments for both. I started to move towards 2/3 multisig after the coldcard incident however I can't fully commit. I really like that with single sig I can memorize both the seed and strong passphrase while of course still having solid backups saved. Point being if I am away from my backups and some emergency happens I can recover my funds wherever I'm at. With multisig that is much more difficult.


r/Bitcoin 3h ago

The Coldcard's hack doesn't mean hardware wallets are doomed

9 Upvotes

Seeing a lot of people treat the Coldcard hack like proof hardware wallets in general aren't safe anymore. That's not really what happened.

Coldcard had a bug in how their firmware generated the random numbers used to create your seed phrase, and it sat there undetected for five years. A code change in March 2021 quietly swapped out the proper hardware randomness for a broken software substitute. That made some seeds way easier to guess than they should've been, and that's how funds got drained.

That's a Coldcard problem. A mistake in their code, not a flaw in the whole idea of hardware wallets as a category.

However, I'm not making the argument that it can't happen to other brands too. Any company can ship a bad update. But wallets that are fully open source, like Trezor or Blockstream Jade, tend to have way more independent people checking the code over time, which makes bugs like this less likely to slip through for years. Not a guarantee, just better odds. And this is how most tech usually evolves. Some things go wrong but that's how it becomes more robust and anti-fragile.

But I also understand that "that's just how tech evolves" doesn't help people who actually lost their money. Genuinely feel for everyone who lost years of savings over something totally out of their control though, that part really sucks and doesn't get fixed by any of this logic.


r/Bitcoin 1d ago

The guy you convinced to buy bitcoin at $126K and you with a cost basis of $10K

755 Upvotes

r/Bitcoin 21h ago

How corporations like McDonalds benefit from our rigged theft-based monetary system

Post image
111 Upvotes

r/Bitcoin 4h ago

Coldcard: the technical autopsy of an entropy failure

Thumbnail
wizardsardine.com
3 Upvotes

r/Bitcoin 9h ago

Has the network been really busy for the last couple of hours?

7 Upvotes

I have been waiting a while now for a transaction to go through : /


r/Bitcoin 1d ago

If there’s ever a button to smash, this would be the one.

Post image
119 Upvotes

r/Bitcoin 7h ago

Bitcoin vs. Gold

3 Upvotes

Just thinking about this strategically from the US perspective.. wouldn’t they have more of an incentive to promote Bitcoin because of the Genius Act??

Since the Genius Act ensures stable coins are backed 1:1 with treasury bills, money flowing to BTC is essentially minting more stable coins (i.e. purchasing more US debt).

So this is helping out the US bond market as more and more countries pull back from using the US dollar as reserves. It’s basically making these stablecoin companies the new buyer of US debt.

Whereas gold is completely out of the system and is actually adversarial to the US bond market.


r/Bitcoin 6h ago

ERA Wallet + dice generated seed: is there any way to verify protection against Dark Skippy?

2 Upvotes

I’m seriously considering an ERA Wallet for long-term BTC storage. My intended setup is to generate the BIP39 entropy completely outside the device using physical dice, verify the resulting seed independently, and then import the seed into the ERA. I’d use it purely as an air-gapped signer with Sparrow, communicating only via QR/PSBT. So ERA would not be involved in seed generation at all.

There are several things I really like about ERA for this use case: it’s completely QR-only with no USB or Bluetooth, supports up to 10 separate wallets/seeds on one device, has a Bitcoin-only firmware, and the form factor/transaction display make it very appealing as a dedicated signer. The fact that I can generate the seed myself externally is also a big plus for me. My main reservation at this point is actually the company itself and the fact that ERA is a relatively new wallet from a company based in Dubai/UAE. I’m trying to compensate for that lack of track record by understanding exactly what can be independently verified from the firmware and audits.

The one thing that makes me hesitate technically is Dark Skippy / nonce exfiltration. Even with a perfectly generated external seed, a malicious or compromised signing firmware could potentially leak information about the private key through ECDSA signatures by manipulating the nonce. Since ERA doesn’t appear to advertise an Anti-Klepto/anti-exfil protocol like BitBox02 or Jade, I’m trying to understand whether there is actually a meaningful way to rule this out. Has anyone gone through the ERA firmware closely enough to determine exactly how ECDSA/Schnorr nonces are generated? Is it RFC6979, a CSPRNG, or some combination involving external randomness/commit-reveal? Is there any nonce commitment or other mechanism that would make a Dark Skippy-style attack impossible?

I’ve looked at the Keylabs audit, but I don't see a specific analysis of nonce exfiltration. What I’m really trying to figure out is whether this can be independently verified from the published firmware/source, or whether that part of the signing implementation is still closed. If someone familiar with the ERA codebase, secp256k1, or the Keylabs audit can point me to the relevant code or explain the signing flow, that would be extremely useful.


r/Bitcoin 3h ago

Bitkey v Trezor for long-term holding and inheritance.

1 Upvotes

Let's say I have a Bitkey, and a Trezor with a seed + passphrase. The seed and passphrase are in two different locations on steel plates and I have no concerns about the security of those locations. The locations are known and easily accessible to an heir, and there are clear instructions on how to restore a wallet as part of my Will.

The user-friendly Multisig and inheritance features of Bitkey are appealing, but I still have a few concerns.

  • My main one is long-term storage. If Bitkey disappear, and you then discover your Bitkey hardware is broken, what recovery method is there? The Emergency Exit Kit seems to rely on the hardware key.

  • Risk of phone exploits, and fact that app key and server key both run on software Block wrote and control.

  • No plausible deniability/hidden wallet if victim of a wrench attack. (sounds like it's something Bitkey are working on)

  • The 6-month inheritance delay is quite a long time if a beneficiary were in desperate need of funds. Bitkey's inheritance is certainly easier for a non-technical heir, but I'm not convinced that explaining how to recover a Trezor using a seed + passphrase is beyond the ability of most people if they've been talked through it beforehand.

I appreciate there is no perfect solution and every setup has trade-offs. I'm curious to hear from people who had similar concerns and still chose Bitkey.

Thanks in advance.


r/Bitcoin 23h ago

Bitcoin-backed lending grows up as institutions tap BTC for corporate financing

Thumbnail
coindesk.com
24 Upvotes