COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Large-scale Coldcard compromise (1360.23 BTC stolen so far)

bitcointalk-large-scale-compromise-thread

https://bitcointalk.org/index.php?topic=5589927.0

Latest reviewed change

source content difference between and

The thread gained several new replies on 9 August discussing why the stolen funds have not moved, decoy and passphrase strategy, the Mk3 entropy estimate, and a moderator merge note; reply titles also updated to the 1,596 BTC figure.

seen +167 -6 full history below
 1. How the attacker detects whether it's a decoy address and decides to invest all their resources in a single wallet that they believe "It's a decoy, got a correct passphrase and you'll get the whale." which there's no script / tools exist for detecting such things.
 2. (MOST IMPORTANTLY) how the user leverages the passphrase instead of entering their Instagram password to secure their real funds.
 I still believe in SHA256, and accessing my funds from anywhere I want without letting a company give me the keys to my funds or storing my own keys in SDB is far worse.
-Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
-Post by: flatt on August 08, 2026, 02:22:40 PM
 Quote from: philipma1957 on August 08, 2026, 01:30:05 PM
 Quote from: vapourminer on August 08, 2026, 12:43:16 PM
 Quote from: LoyceV on August 08, 2026, 12:22:57 PM

First lines only. The complete diff is in the timeline below.

Organisation
BitcoinTalk
Evidence role
Community discussion
Published
2026-08-04
Source changes
35
Detected differences
36
Unreviewed
0
Copies held
37

flatfly opening the forum's main incident thread on the Bitcoin Discussion board, tallying the drains at 1360.23 BTC and still rising; other registered threads on the forum point here as the megathread. At 292 comments it is the longest-running BitcoinTalk record of community response, reported cases and sentiment as the incident developed. The figures and claims in the thread are the posters' own, not verified here.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +167 -6

    The thread gained several new replies on 9 August discussing why the stolen funds have not moved, decoy and passphrase strategy, the Mk3 entropy estimate, and a moderator merge note; reply titles also updated to the 1,596 BTC figure.

    seen · Captured here 603,688 chars
    What changed from the previous capture 173 lines
     1. How the attacker detects whether it's a decoy address and decides to invest all their resources in a single wallet that they believe "It's a decoy, got a correct passphrase and you'll get the whale." which there's no script / tools exist for detecting such things.
     2. (MOST IMPORTANTLY) how the user leverages the passphrase instead of entering their Instagram password to secure their real funds.
     I still believe in SHA256, and accessing my funds from anywhere I want without letting a company give me the keys to my funds or storing my own keys in SDB is far worse.
    -Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    -Post by: flatt on August 08, 2026, 02:22:40 PM
     Quote from: philipma1957 on August 08, 2026, 01:30:05 PM
     Quote from: vapourminer on August 08, 2026, 12:43:16 PM
     Quote from: LoyceV on August 08, 2026, 12:22:57 PM
     1099511627776 x 1099511627776 x 109951162776
     that's 121 bits and the 1099511627776 is all the cold card had as that is 40 bits.
     as for convinent well the trezor has a standard wallet with say 0.04 BTC and the each of the 3
    -passphrases have say 0.32BTC total 1 of  btc
    +passphrases have say 0.32BTC total 1 of  btc
     what's nice is keeping the passphrase in my banks safety deposit box slows .96 btc from my own spending
     issues.
     do I like it no
     It's perfectly safe to let a hardware calculate the checksum word. Out of the entire list of 2048 words, only 7 or 8 will form a checksum for a 24 word seed. So, you're not sacrificing any randomness by letting a hardware wallet calculate the checksum word.
     You've now got a totally random 24 word seed phrase. And you know it's random because you did the work.
     Pick another 10 words from the bowl of paper strips. That's your passphrase.
    -I'm sure somebody is thinking "But the paper strips don't weigh exactly the same!" That's right. Any imperfections  just add to the randomness since those imperfections can't be predicted or calculated.
    +I'm sure somebody is thinking "But the paper strips don't weigh exactly the same!" That's right. Any imperfections  just add to the randomness since those imperfections can't be predicted or calculated.
     I started doing this after Ledger added key extraction to their firmware. I was a Ledger user back then, and their actions made me question how much I could trust the firmware for any device. So, I figured, if I don't let a device generate my seed phrase, I don't have to trust the device.
     I also swear by ShieldSigner, which is a fork of SeedSigner that adds encrypted Seed QR, passphrase QR, and smartcard support (SeedKeeper and Satochip).
     This gives me the ability to use my seed on a device which is airgapped and stateless.
     6. Get a small safe to keep in your home, where you'll store any documentation that needs to be written down. Document everything for your setup, even if only to help yourself remember "How'd I generate this seed? Why'd I set it up this way?"
     7. Get home automation and put a sensor on the safe, to send you instant notifications if it is opened or moved. Aqara makes this easy and cheap. On sale, you can get an Aqara hub & sensors for under $50.
     I know this list sounds like a lot, but really it's not.
    -Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    -Post by: Meuserna on August 08, 2026, 05:43:45 PM
     Quote from: flatt on August 08, 2026, 09:55:35 AM
     Quote from: LoyceV on August 08, 2026, 08:07:50 AM
     Quote from: vapourminer on August 04, 2026, 10:34:44 AM
     I'm very sure Coldcard lawyers are going to be busy with the rest of the year with different lawsuits.
     Aren't we underestimating the hacker here? He has been so clever to find this bug in Coldcard that wasn't detected before, and now we are assuming that the hacker will have a hard time cashing out those stolen BTC, and he will either end up in the wrong hands or get traced???
     I am sure he must have already figured out how to get out of all this without getting noticed. He has a criminal mind, and we are just thinking that he will find trouble spending those bitcoins  ???  I think we are too innocent to think like this, and if he is reading this, he must be laughing at us.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: Webetcoins on August 09, 2026, 05:21:59 PM
    +Quote from: joker_josue on Today at 08:05:56 AM
    +it seems that the coins, after being stolen, were not touched again.
    +Is the hacker still thinking about what to do, or is he feeling guilty?
    +The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
    +I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.
    +He is probably thinking of the best way for him to cash out all or at least some of those assets so that he can use them in real life. Just because he isn't touching the coins doesn't mean he is feeling remorse for what he did, because such people barely care about these things or have such feelings, if they did, they wouldn't do it in the first place. One could argue that those who get into doing such things are the ones who have suffered a lot themselves in life, but doesn't that make it even more logical for them to understand what it means to have nothing or to lose everything you have or have workeed for your entire life?
    +So, I think the reason why there is a delay in moving those funds is because the attacker knows that he has so many eyes on him, and he probably wouldn't want to make a silly mistake and get caught somehow, so he is surely exploring and researching all his options that he can use to convert his bitcoins either to another untraceable asset, or simply convert it to fiat and use it, because it obviously isn't his goal to just steal the funds and let it lying around in a wallet, but the most difficult thing in such attacks is not the attack itself but it is to use the funds after it.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: pbies on August 09, 2026, 05:33:02 PM
    +XMR (Monero) is no longer usable on exchanges, so he could use ZCash or just swap chunks in Exodus wallet to other crypto, mix it and pay out.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: sergiorus on August 09, 2026, 05:44:57 PM
    +Quote from: pbies on Today at 05:33:02 PM
    +XMR (Monero) is no longer usable on exchanges, so he could use ZCash or just swap chunks in Exodus wallet to other crypto, mix it and pay out.
    +What do you mean by "not usable"?
    +It's still listed on a plenty of centralised exchanges with decent liquidity as well as on DEXs but with questionable liquidity if that's what you meant.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: joker_josue on August 09, 2026, 06:03:25 PM
    +Quote from: Lucius on Today at 01:19:29 PM
    +Do you think someone who clearly doesn't know what passphrase or multi-sig is knows how to insert a message into their transaction? My opinion is that most of these messages come from scammers who play the victim card in the hope that some rich donor will see it and send a big donation.
    +I think one thing has nothing to do with the other.
    +Aside from the most paranoid (and rightfully so), the vast majority of people didn't add a 25th word to their seed created in a hardware wallet, considered reliable by the overwhelming majority of the community.
    +Otherwise, we'll be jeopardizing the entire seed system, which also doesn't make sense.
    +Therefore, a person not having the passphrase does not mean that they had little knowledge about Bitcoin.
    +Quote from: Lucius on Today at 01:19:29 PM
    +Most people assume that it is a person, but isn't it possible that it is not a person but an advanced AI that was tasked with trying to hack a hardware wallet? Most people think that AI capabilities are what we see in popular models mainly from US companies - but the same companies and the US government itself have admitted that China, for example, has far more advanced AI models that are capable of much more than we can even imagine.
    +That's a plausible scenario. I'd never thought of that. Could some AI be running loose, stealing money, and even the AI ​​creators themselves don't know about it?
    +We're already entering the realm of conspiracy theory.   ::)
    +Quote from: UmerIdrees on Today at 04:52:20 PM
    +Aren't we underestimating the hacker here? He has been so clever to find this bug in Coldcard that wasn't detected before, and now we are assuming that the hacker will have a hard time cashing out those stolen BTC, and he will either end up in the wrong hands or get traced???
    +I am sure he must have already figured out how to get out of all this without getting noticed. He has a criminal mind, and we are just thinking that he will find trouble spending those bitcoins  ???  I think we are too innocent to think like this, and if he is reading this, he must be laughing at us.
    +Quote from: Webetcoins on Today at 05:21:59 PM
    +So, I think the reason why there is a delay in moving those funds is because the attacker knows that he has so many eyes on him, and he probably wouldn't want to make a silly mistake and get caught somehow, so he is surely exploring and researching all his options that he can use to convert his bitcoins either to another untraceable asset, or simply convert it to fiat and use it, because it obviously isn't his goal to just steal the funds and let it lying around in a wallet, but the most difficult thing in such attacks is not the attack itself but it is to use the funds after it.
    +Time is everything with this type of hack. The more time passes, the harder it is to get rid of the coins, not the other way around.
    +The longer he waits, the less things get "forgotten," and the better prepared blockchain analysts are to track these coins. The entire community, including exchanges, swaps, and the like, has become better prepared to catch any movement of these coins.
    +He's already missed the window of opportunity to move without being caught. Now, every step he takes is under surveillance.
    +Of course, this doesn't mean they won't try to withdraw the money at any time, but the longer it goes on, the more difficult it will be.
    +That's why I'm saying this: even the hacker himself wasn't expecting to be so successful. Otherwise, as soon as he had acquired the first coins, he would have immediately sent them to mixes and swaps to break their trail.
    +Perhaps he had already planned this, but the news broke too quickly, leaving him with no room for maneuver.
    +I'm not saying that he is naive or ingenuous. I'm simply presenting the scenario where the hacker who carried out the attack wasn't expecting the success they had, and was left unsure of what to do. Because stealing 10 BTC is one thing, stealing 1000 BTC is quite another; the whole plan changes.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: Stalker22 on August 09, 2026, 06:40:47 PM
    +Quote from: fillippone on Today at 11:15:33 AM
    +Quote from: LoyceV on Today at 10:48:34 AM
    +Quote from: philipma1957 on Today at 10:38:43 AM
    +He could keep them still for a month or two and then send them back
    +To return the stolen funds, he'll need to identify each owner first, and you can bet many scammers will claim to be the owners. No single person can do that on his own.
    +The addresses are now compromised.
    +Everyone could claim the ownership of the sending addresses (the private keys).
    +Identifiying the original and authentic owner is almost impossible (it would require checking upon the possession of the physical hw, something that looks very impractical to me).
    +Even verifying possession of the physical HW will not be definitive proof.  It is theoretically possible for someone in possession of the ColdCard HW to recreate the wallet by importing a compromised seed.  How would that differ from the original wallet of the real victim?
    +I think on-chain history is the only real proof.  To verify a claim, someone would have to trace where the funds originally came from - like an CEX withdrawal, or from some other KYC-ed account.  Doing that manual forensics for thousands of separate victim addresses is an insane amount of work though.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: JayJuanGee on August 09, 2026, 06:51:48 PM
    +Quote from: kTimesG on August 08, 2026, 10:04:42 AM
    +Quote from: JayJuanGee on August 08, 2026, 02:25:57 AM
    +You are saying also that no entropy was added by any dice rolls, so I would need to be explained the mechanics of how that would be based on if you are saying that there might have been an override of the Cold Card software that pushed it back to the 40 bits of entropy?
    +It's not 40 bits of entropy, more like 23 (or even less, CC would know better of their die cutting parameters). Watching the official YouTube easy guide "5 minutes setup" of a fresh CC adds some 6 additional bits. Each dice adds around 2 bits on top of this. So that's only around 2 to 3 billion guesses for all seeds out of all entropies + one dice rolls. A laptop can break that in an hour.
    +You are probably not wrong in your presumption, that even the guys who did dice rolls did not do a sufficient quantity of dice rolls, and I already mentioned my understanding that 100 plus dice rolls adds 256 bits of entropy, 50 plus dice rolls adds 128 bits of entropy, 25 plus dice rolls adds 64 bits of entropy and lower quantity of rolls would add lower amounts of entropy... ~2.5 bits per dice roll.
    +And, yeah, Cold Card software probably should not have allowed the setting up a wallet without a minimum quantity of extra entropy, perhaps even 25 plus might have had been enough, but maybe they should have had set the bare minimum quantity of dice rolls to a higher number like 30 plus, which would be around 72 bits of entropy, and even that might not have had been enough as a bare minimum amount, since allowing people to do it would mean that people would do the bare minimum, which is what happened, since there are examples of people not doing any dice rolls or just doing a few dice rolls or just making up their dice roll numbers.
    +Quote from: Cricktor on August 08, 2026, 12:09:10 PM
    +Quote from: joker_josue on August 08, 2026, 07:23:16 AM
    +The only way to be prepared anywhere in the world is to always have your seed with you.
    +How many of us have all the seeds with us 365 days a year, always?
    +If that were actually necessary, we should consider the whole setup to be terribly wrong and faulty. I find this very very wrong to have to carry my mnemonic seeds with me all the time. Sorry, no, this should NOT be necessary! And it is not necessary if we knew that entropy generation wasn't screwed up completely.
    +Apparently there's more due diligence needed to verify that entropy generation isn't flawed. Easier said, than done, though...
    +I must say, I'm genuinely surprised how badly a hardware wallet vendor screwed this up like Coinkite did. I thought light-hearted that this shouldn't be possible because it's such a basic and important functionality to NOT screw up the random stuff when you have TRNGs available. I'm still puzzled...
    +Another reason that a person might need to carry their seed words would be if there might end up being som difficulties crossing a border or maybe some other way that a person's hardware wallet might become compromised, in the event that they are traveling with their hardware wallet.  There may be instances that some guys might want to wipe their device when crossing certain borders.  There also could be instances in which their device might get stolen, lost or confiscated, so then they might want to be able to race to get  to their seed words to be able to sweep the funds in any main wallet or in any hidden wallet(s).
    +Quote from: Meuserna on August 08, 2026, 05:33:19 PM
    +Pick another 10 words from the bowl of paper strips. That's your passphrase.
    +Have you ever tried to transact with a hardware wallet?  It will frequently require the passphrase to be re-entered, especially if a certain amount of time passes between transactions.
    +Accordingly, I am not sure what advantage comes from having to type 10 words each time as compared with maybe having a passphrase that might have some quasi-random string of around 15-ish characters that include numbers, letters, cap letters and symbols.
    +Quote from: Meuserna on August 08, 2026, 05:33:19 PM
    +3. Back up your seed and passphrase on metal.
    +4. Store your seed and passphrase somewhere secure. Somewhere only you have access to. Preferably 2 places, separate.
    +I am perfectly fine with the two places idea, even though practically, there are likely some guys who are quite challenged to have two places that are sufficiently within their control.
    +Quote from: Meuserna on August 08, 2026, 05:33:19 PM
    +6. Get a small safe to keep in your home, where you'll store any documentation that needs to be written down. Document everything for your setup, even if only to help yourself remember "How'd I generate this seed? Why'd I set it up this way?"
    +7. Get home automation and put a sensor on the safe, to send you instant notifications if it is opened or moved. Aqara makes this easy and cheap. On sale, you can get an Aqara hub & sensors for under $50.
    +What if your house burns down?  I understand the document is separate from the seed, yet if you have the seed without the documents, is the seed still going to be useful?
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: asUHWEceyc on August 09, 2026, 07:06:15 PM
    +Quote from: LoyceV on Today at 08:27:01 AM
    +Quote from: joker_josue on Today at 08:05:56 AM
    +The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
    +I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.
    +That's why I came up with this theory:
    +Quote from: LoyceV on August 01, 2026, 06:24:45 AM
    +Or could it just be an amateur who's in way over his head? Someone who accidentally stumbled upon this weakness, and suddenly ended up with $70 million in stolen funds?
    +Quote from: joker_josue on Today at 08:05:56 AM
    +Perhaps we need to look again at the master Satoshi and see how he created his wallets.
    +They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.
    +Satoshi used Send to Pubkey transactions, whilch may become quantum vulnerable in the future. That's not the best example for the long term. But his random generation must have been pretty good :)
    +Surprisingly good for a Windows XP VM https://bitcointalk.org/Smileys/default/grin.gif
    +But, a big bag of private keys also has certain advantages
    +Also-
    +How many NVK proximal influencer-podcaster-types (bent, odell, etc) and their investment projects (1031) that funded coinkite lost money in this thing? What about secondary corporate operators that used coldcards for key handholding services?
    +Did they "know better" or get a heads up?
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Meuserna on August 09, 2026, 07:33:22 PM
    +Quote from: JayJuanGee on Today at 06:51:48 PM
    +Quote from: Meuserna on August 08, 2026, 05:33:19 PM
    +Pick another 10 words from the bowl of paper strips. That's your passphrase.
    +Have you ever tried to transact with a hardware wallet?  It will frequently require the passphrase to be re-entered, especially if a certain amount of time passes between transactions.
    +Accordingly, I am not sure what advantage comes from having to type 10 words each time as compared with maybe having a passphrase that might have some quasi-random string of around 15-ish characters that include numbers, letters, cap letters and symbols.
    +That's a huge flaw in most hardware wallets.
    +Most hardware wallets make entering a passphrase so cumbersome that people use a short and weak passphrase instead.
    +These days, my hardware wallets are Krux and ShieldSigner. Both include the option for Passphrase QR, which makes using very strong passphrases really easy. Save your passphrase as a QR code. To load the wallet, scan the QR with the passphrase.
    +Before I switched to Krux, I was a Ledger user. I hate Ledger, but one thing they did right was make it easy to use a strong passphrase. Ledger devices allowed setting up 2 PIN codes to unlock the device.
    +PIN 1 unlocked the device to the seed-only wallet.
    +PIN 2 unlocked the device to the seed+passphrase wallet.
    +That made using a very strong passphrase really easy. Unlock the device using PIN 2. Done.
    +For years, I've been using passphrases that are over 50 characters long.
    +My hope is that the ColdCard flaw teaches more people (especially devs) the importance of making it easier for users to quickly enter strong passphrases.
    +Quote from: JayJuanGee on Today at 06:51:48 PM
    +Quote from: Meuserna on August 08, 2026, 05:33:19 PM
    +3. Back up your seed and passphrase on metal.
    +4. Store your seed and passphrase somewhere secure. Somewhere only you have access to. Preferably 2 places, separate.
    +I am perfectly fine with the two places idea, even though practically, there are likely some guys who are quite challenged to have two places that are sufficiently within their control.
    +2 places: A safe in your home and a safe deposit box at the bank.
    +Quote from: JayJuanGee on Today at 06:51:48 PM
    +Quote from: Meuserna on August 08, 2026, 05:33:19 PM
    +6. Get a small safe to keep in your home, where you'll store any documentation that needs to be written down. Document everything for your setup, even if only to help yourself remember "How'd I generate this seed? Why'd I set it up this way?"
    +7. Get home automation and put a sensor on the safe, to send you instant notifications if it is opened or moved. Aqara makes this easy and cheap. On sale, you can get an Aqara hub & sensors for under $50.
    +What if your house burns down?  I understand the document is separate from the seed, yet if you have the seed without the documents, is the seed still going to be useful?
    +Your seed and passphrase should be backed up on metal in 2 places: A safe in your home and a safe deposit box at the bank. Your documentation for your wallet should be in 2 places too. This is especially true for anybody doing multisig.
    +Bitcoin self custody comes with self responsibility. Those who aren't prepared to do it right or don't have the means to do it right should buy ETFs instead. It makes me sad to say that, but self custody needs to be done right.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: Meuserna on August 09, 2026, 09:23:14 PM
    +Sometimes, this forum is bizarre.
    +Mods deleted a comment where I explained how ColdCard wallet attackers are now targeting seed-only wallets they suspect are only decoys. Mods said the comment was off topic.
    +Using a seed-only wallet as a decoy is how ColdCard attackers know which seeds might be hiding coins behind a passphrase. There are often clues that a wallet is actually just a decoy.
    +How is that not relevant to this conversation?
    +I believe the safe way to set up a decoy is to leave the seed-only wallet unused, and set up a decoy using a weak passphrase.
    +An empty seed-only wallet gives anyone who finds it no clue that the wallet has ever been used. Adding a few sats there as a decoy gave the ColdCard attackers reason to see if they could find more hidden behind a passphrase. Now, if the passphrase for the real wallet is strong enough, those coins are safe (but should still be moved to a new seed+passphrase or multisig wallet for long term safety).
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: Stalker22 on August 09, 2026, 09:33:12 PM
    +Quote from: Meuserna on Today at 09:23:14 PM
    +Sometimes, this forum is bizarre.
    +Mods deleted a comment where I explained how ColdCard wallet attackers are now targeting seed-only wallets they suspect are only decoys. Mods said the comment was off topic.
    +~
    +The mods did not delete your post, they just merged your comment with your previous post.
    +You can see it here: https://bitcointalk.org/index.php?topic=5589927.msg67024234#msg67024234
    +Just try not to make multiple posts in a row!  It is against the forum rules (https://bitcointalk.org/index.php?topic=703657.0).  You can always use the edit button if you need to add something later.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: PrivacyG on August 09, 2026, 09:39:25 PM
    +Quote from: Meuserna on Today at 09:23:14 PM
    +I believe the safe way to set up a decoy is to leave the seed-only wallet unused, and set up a decoy using a weak passphrase.
    +This is actually a fantastic idea.  Although it is an unnecessary effort in this Coldcard case.  If you have a strong Pass phrase, they would not find it any way no matter how long they search.  The weak decoy would only be useful in a 5 Dollar wrench attack.  And even then.  It is only useful if the attacker does not believe you may be hiding more.
    +Which is what I believe would come after a short search for weak Pass phrases in the Coldcard case too.  Look for weak ones and then move on and try to find treasures.  They have all the time to do it.  And money to purchase better equipment now too.  Unless they are caught.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: Meuserna on August 09, 2026, 10:36:16 PM
    +Quote from: PrivacyG on Today at 09:39:25 PM
    +Quote from: Meuserna on Today at 09:23:14 PM
    +I believe the safe way to set up a decoy is to leave the seed-only wallet unused, and set up a decoy using a weak passphrase.
    +This is actually a fantastic idea.  Although it is an unnecessary effort in this Coldcard case.  If you have a strong Pass phrase, they would not find it any way no matter how long they search.  The weak decoy would only be useful in a 5 Dollar wrench attack.  And even then.  It is only useful if the attacker does not believe you may be hiding more.
    +Which is what I believe would come after a short search for weak Pass phrases in the Coldcard case too.  Look for weak ones and then move on and try to find treasures.  They have all the time to do it.  And money to purchase better equipment now too.  Unless they are caught.
    +Yeah.
    +Decoy wallets aren't effective for a $5 wrench attack unless you have enough Bitcoin in the decoy wallet to convince the attacker they got everything. And, really, at the point when you've become a target for a violent in-person attack, your life is what you need to worry about.
    +But for a ColdCard-style seed-hunting attack, I think a decoy wallet set up using a weak passphrase is a good idea because it becomes like an alarm that tells you someone is trying to crack your passphrase. Even if your passphrase is strong enough to prevent the attack (mine is well over 50 characters) it's still good to know someone is trying. Of course, the attacker has to take the decoy coins in order for you to know they found 'em and are trying to crack your passphrase.
    +Using a weak passphrase as a decoy can also be a great form of security if your main wallet is set up some other way, such as multisig. A weak singlesig passphrase might convince an attacker to keep churning through passphrases to see if they can find your real wallet... which is especially useful if that's not how your real wallet is set up.
    +This whole ColdCard attack is terrible, and my heart breaks for everyone who lost coins. But one sliver of good news is that the attack made everyone start looking for vulnerabilities to patch or improve on.
    +I didn't lose any coins in this attack, but it did make me rethink every aspect of my own setup. We should all be doing that, because there's always room to improve even if it doesn't lead to changing your setup. I've been focusing on how I document mine for future reference, and how I teach the basics.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1596 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +142 -0

    The megathread title updated its tally to 1596 BTC stolen, with a later figure of 1485.77 BTC also appearing, and many new posts were added debating whether the attacker might return funds, how laundering would work, and the emotional impact on victims.

    seen · Captured here 580,185 chars
    What changed from the previous capture 142 lines
     They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.
     Satoshi used Send to Pubkey transactions, whilch may become quantum vulnerable in the future. That's not the best example for the long term. But his random generation must have been pretty good :)
     I'm talking about the seed (so to speak), because to date that's what's guaranteeing the security of these coins.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: philipma1957 on August 09, 2026, 10:38:43 AM
    +Quote from: joker_josue on Today at 08:05:56 AM
    +Quote from: CucakRowo on Today at 02:44:40 AM
    +How long can that hacker carry the burden of all these broken lives on his conscience! Will he really close his eyes and sleep peacefully!
    +Well, it seems that the coins, after being stolen, were not touched again.
    +Is the hacker still thinking about what to do, or is he feeling guilty?
    +The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
    +I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.
    +Quote from: Italian Panic on Today at 06:48:38 AM
    +I�m sure that generating secure seeds and passphrases will be quite a challenge in light of what happened with ColdCard, but this solution also requires relying on third parties and provides a phone number, so it could compromise the privacy of those who don�t have a front man. I think we�ll need to look a little further ahead; we�ll need to find a real solution for self-custody as we understand it today and for our long- and very long-term goals.
    +Perhaps we need to look again at the master Satoshi and see how he created his wallets.
    +They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.
    +He could keep them still for a month or two and then send them back on the grounds that cold card company is crushed for the idiocy that caused the issue in the first place.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: LoyceV on August 09, 2026, 10:48:34 AM
    +Quote from: joker_josue on Today at 08:38:14 AM
    +I can imagine the situation: he discovers the flaw and goes to test it to see if it's really true.
    +Start running the script, perhaps with the goal of verifying if your own wallets are affected. Within minutes, they begin targeting third-party wallets with hundreds of BTC being transferred to your account.
    +I believe the first reaction will be one of shock, but at the same time, incredibly exciting.
    +Suddenly 1000 BTC appears in your account. You must be ecstatic in your basement.
    +You're probably already thinking of a thousand and one things you'll want to do with that money.
    +And then he realizes he can't spend the money. To use it, he'll need to launder it. To launder it, he'll need criminal connections. Having $100 million in your name and looking for criminal connections makes you a massive target, not to mention the thousands of robbed people worldwide who can drink your blood. Meeting the wrong person: death. Getting caught: life in prison. Returning the money: practically impossible now because someone else will take it instantly.
    +Quote
    +I'm talking about the seed (so to speak), because to date that's what's guaranteeing the security of these coins.
    +I wasn't around back then, but I assume Bitcoin-qt back then used the computer's random number generator. Satoshi didn't reuse addresses, so he simply created (give or take) 20,000 different random private keys. There was no "seed" yet.
    +Quote from: philipma1957 on Today at 10:38:43 AM
    +He could keep them still for a month or two and then send them back
    +To return the stolen funds, he'll need to identify each owner first, and you can bet many scammers will claim to be the owners. No single person can do that on his own.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: Pumpsta on August 09, 2026, 10:54:08 AM
    +Man, so many holders are devastated by this now :-\ Is all the compromised btc gone now or the hacker's still running through seeds? If the hack is so easy then why isn't there any collective race to act first so the btc ends in wallets of people who intend to return them to the affected owners?
    +Quote from: kTimesG on August 07, 2026, 10:36:15 AM
    +Do not think dice rolls helped, those wallets do exist, and are also gone.
    +what do you mean even dice rolls don't help?? I kept reading about dice rolls being the best way to make a seed, they're not anymore?
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: fillippone on August 09, 2026, 11:15:33 AM
    +Quote from: LoyceV on Today at 10:48:34 AM
    +Quote from: philipma1957 on Today at 10:38:43 AM
    +He could keep them still for a month or two and then send them back
    +To return the stolen funds, he'll need to identify each owner first, and you can bet many scammers will claim to be the owners. No single person can do that on his own.
    +The addresses are now compromised.
    +Everyone could claim the ownership of the sending addresses (the private keys).
    +Identifiying the original and authentic owner is almost impossible (it would require checking upon the possession of the physical hw, something that looks very impractical to me).
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: Livingleged on August 09, 2026, 11:24:05 AM
    +Quote from: joker_josue on Today at 08:38:14 AM
    +As the hours tick by and the news breaks, the dilemma begins: how are you going to move the money without getting caught? I stole hundreds of BTC from people who saved their whole lives. What have I done!?
    +Now you may be debating whether to return everything, return part of it, or ignore the matter altogether.
    +Same thoughts actually, but I�m more particular about whether it�s  possible to even ignore the matter all together when the community�s eyes are on you ?. Now the attacker will be  more pressured except it was actually planned by a team to carry out the attack. Then they will wait for years probably when most people have forgotten about the wallet before they start moving the coins. Thats shitty to me because the internet doesn�t forgets.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: Cricktor on August 09, 2026, 11:35:02 AM
    +Quote from: philipma1957 on Today at 10:38:43 AM
    +He could keep them still for a month or two and then send them back on the grounds that cold card company is crushed for the idiocy that caused the issue in the first place.
    +As much as I wished that Coinkite gets crushed and vanishes for their anti-open-source stance, arrogance, ignorance and failure to produce safe firmware, it will take a while and they likely need to get sued to step off the hardware wallet market.
    +I'm not so confident that customers will speak up with their wallets and refuse to ever buy a ColdCard again. Ledger crap is still sold by who-knows-what volume and buyers accept (or simply don't know) that Ledger firmware has code to exfiltrate your Ledger wallet's seed. Maybe potential customers will turn their eyes away from ColdCard, it's not guaranteed.
    +Stolen coins can't safely be returned to the compromised originating wallet because you have to assume the originating wallet is basically public, the entropy and encoding mnemonic recovery words aren't secret anymore. Someone else besides the original wallet owner and the thief might also know the mnemonic recovery words and hence would be able to move coins sent to the compromised wallet. (fillippone was faster)
    +It's going to be interesting how the thief or thieves will try to launder the stolen coins. I don't believe the criminals have any emotional strings to those they robbed. It's internet crime, you don't have to see or deal with your victims. All eyes are on the accumulating addresses of stolen coins.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: knowngunman on August 09, 2026, 11:36:25 AM
    +Quote from: joker_josue on Today at 08:38:14 AM
    +I can imagine the situation: he discovers the flaw and goes to test it to see if it's really true.
    +Start running the script, perhaps with the goal of verifying if your own wallets are affected. Within minutes, they begin targeting third-party wallets with hundreds of BTC being transferred to your account.
    +I believe the first reaction will be one of shock, but at the same time, incredibly exciting.
    +Suddenly 1000 BTC appears in your account. You must be ecstatic in your basement.
    +You're probably already thinking of a thousand and one things you'll want to do with that money.
    +As the hours tick by and the news breaks, the dilemma begins: how are you going to move the money without getting caught? I stole hundreds of BTC from people who saved their whole lives. What have I done!?
    +Now you may be debating whether to return everything, return part of it, or ignore the matter altogether.
    +Nah, he meant business. Considering the effort put on this, he did it deliberately.
    +Assuming it was a few wallets, I would agree with you on this but meh over thousands addresses? That's not testing. He's probably planning on next strategy. The incident attracts much attention, he might be waiting for as long as possible to let attention shifted before making a move. They know what they are doing, they know about risk management. You can not pull off something like this and rush decisions, you need time to figure out everything in order not to land in trouble.
    +I agree he's reflecting but definitely not thinking of returning it. He's reflecting on the next step. They are human with no conscience.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: joker_josue on August 09, 2026, 12:34:36 PM
    +Quote from: LoyceV on Today at 10:48:34 AM
    +Quote
    +I'm talking about the seed (so to speak), because to date that's what's guaranteeing the security of these coins.
    +I wasn't around back then, but I assume Bitcoin-qt back then used the computer's random number generator. Satoshi didn't reuse addresses, so he simply created (give or take) 20,000 different random private keys. There was no "seed" yet.
    +That's why he said "so to speak".
    +Back then, seeds weren't used. I had a wallet like that. 10 years later, I went back to that wallet and everything was there, all in order. Without seeds and "complex things".
    +Perhaps what's needed is to relearn how to build wallets without adding more and more extras.
    +I once read something very interesting: "The more security a person seeks, the less security they end up having. Confidence increases, and you become careless about simple things."
    +Quote from: knowngunman on Today at 11:36:25 AM
    +Nah, he meant business. Considering the effort put on this, he did it deliberately.
    +I don't know if such a great effort was needed at the beginning.
    +Entropy was quite low. The good fortune of quickly finding a wallet with substantial funds motivated him to go further and allocate more resources.
    +But of course, I don't think he's an amateur. It was certainly well-planned, but you can't have spent too much time planning, for fear of someone else discovering the flaw first.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: Lucius on August 09, 2026, 01:19:29 PM
    +Quote from: CucakRowo on Today at 02:44:40 AM
    +Two OP_Return messages brought tears to my eyes.
    +One said, ''Please return at least some of the stolen money".
    +Another said, "Suicide tonight if you don't give me back what I worked 12 years, my 6.4 BTC".
    +Who knows how many dreams these people were carrying in their heart? Maybe this was someone's dream of giving their children a secure little future. Maybe someone had been saving that money hoping they could pay for their aging parents treatment. Maybe some people spent their entire live working to achieve this 3 or 4 BTC, and then, in a matter of minute it was all gone.
    +There are probably countless stories of heartbreak behind those transaction that we will never hear about.
    +So many tears, so much fear and desperation, all hidden behind blockchain addresses and transaction ID.
    +How long can that hacker carry the burden of all these broken lives on his conscience! Will he really close his eyes and sleep peacefully!
    +Do you think someone who clearly doesn't know what passphrase or multi-sig is knows how to insert a message into their transaction? My opinion is that most of these messages come from scammers who play the victim card in the hope that some rich donor will see it and send a big donation.
    +Quote from: joker_josue on Today at 08:05:56 AM
    +Well, it seems that the coins, after being stolen, were not touched again.
    +Is the hacker still thinking about what to do, or is he feeling guilty?
    +~snip~
    +Most people assume that it is a person, but isn't it possible that it is not a person but an advanced AI that was tasked with trying to hack a hardware wallet? Most people think that AI capabilities are what we see in popular models mainly from US companies - but the same companies and the US government itself have admitted that China, for example, has far more advanced AI models that are capable of much more than we can even imagine.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Wind_FURY on August 09, 2026, 01:25:15 PM
    +Quote from: joker_josue on August 08, 2026, 07:39:17 AM
    +Quote from: BlackHatCoiner on August 08, 2026, 07:32:36 AM
    +I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.
    +If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.
    +And to be frank with all of you, I'm starting to think this is very justifiable to a point.
    +Owning a Bitcoin ETF is not the same as owning Bitcoin!
    +What really needs to be done is for people to read or reread the Bitcoin white paper again, to understand or remember what Bitcoin is.
    +It's not, but if you're an older "boomer investor" who merely wants to invest $1,000,000, a large amount of money, in Bitcoin, then a Bitcoin ETF is probably the better option because,
    +You don't need to go through the preventive measures, especially if that person is not a very technical individual, and treats Bitcoin only as an investment.
    +Your investment secured by the ETF issuer, and by the legal system if the issuer breached its fiduciary duty.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: Pumpsta on August 09, 2026, 03:29:51 PM
    +Quote from: Lucius on January 21, 1970, 04:11:21 PM
    +Do you think someone who clearly doesn't know what passphrase or multi-sig is knows how to insert a message into their transaction? My opinion is that most of these messages come from scammers who play the victim card in the hope that some rich donor will see it and send a big donation.
    +That's not excluded for sure but I know what a passphrase is and my wallet wasn't covered by one until very recently. You'd think this kind of compromise doesn't happen this easy, Coldcard's been around as a trustworthy company for how long now... I guess most people are alright with just a seed, I can't recall being told by my wallet that a passphrase strengthens the security of my seed, I mean who tf even thinks about the possibility of getting a low security seed generation from a hw anyway ???
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: Cookdata on August 09, 2026, 03:42:07 PM
    +Quote from: Livingleged on Today at 11:24:05 AM
    +Quote from: joker_josue on Today at 08:38:14 AM
    +As the hours tick by and the news breaks, the dilemma begins: how are you going to move the money without getting caught? I stole hundreds of BTC from people who saved their whole lives. What have I done!?
    +Now you may be debating whether to return everything, return part of it, or ignore the matter altogether.
    +Now the attacker will be  more pressured except it was actually planned by a team to carry out the attack. Then they will wait for years probably when most people have forgotten about the wallet before they start moving the coins. Thats shitty to me because the internet doesn�t forgets.
    +Forget? Who forgets their years of investment only to be stolen by some random thieves on the internet in less than a week? This is no longer an individual case, it's now a global case that will remain active until there is a lead somewhere.
    +Many victims would have made a report to law enforcement in different parts of the world. $1m alone is too big to ignore, not to talk of $1m in 100 places.
    +I'm very sure Coldcard lawyers are going to be busy with the rest of the year with different lawsuits.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: UmerIdrees on August 09, 2026, 04:52:20 PM
    +Quote from: Cookdata on Today at 03:42:07 PM
    +Quote from: Livingleged on Today at 11:24:05 AM
    +Quote from: joker_josue on Today at 08:38:14 AM
    +As the hours tick by and the news breaks, the dilemma begins: how are you going to move the money without getting caught? I stole hundreds of BTC from people who saved their whole lives. What have I done!?
    +Now you may be debating whether to return everything, return part of it, or ignore the matter altogether.
    +Now the attacker will be  more pressured except it was actually planned by a team to carry out the attack. Then they will wait for years probably when most people have forgotten about the wallet before they start moving the coins. Thats shitty to me because the internet doesn�t forgets.
    +Forget? Who forgets their years of investment only to be stolen by some random thieves on the internet in less than a week? This is no longer an individual case, it's now a global case that will remain active until there is a lead somewhere.
    +Many victims would have made a report to law enforcement in different parts of the world. $1m alone is too big to ignore, not to talk of $1m in 100 places.
    +I'm very sure Coldcard lawyers are going to be busy with the rest of the year with different lawsuits.
    +Aren't we underestimating the hacker here? He has been so clever to find this bug in Coldcard that wasn't detected before, and now we are assuming that the hacker will have a hard time cashing out those stolen BTC, and he will either end up in the wrong hands or get traced???
    +I am sure he must have already figured out how to get out of all this without getting noticed. He has a criminal mind, and we are just thinking that he will find trouble spending those bitcoins  ???  I think we are too innocent to think like this, and if he is reading this, he must be laughing at us.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1596 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +65 -0

    The megathread gained several posts discussing OP_Return suicide messages, the hacker's possible reflection, and passphrase search economics, and its title was updated to 1596 BTC stolen.

    seen · Captured here 561,784 chars
    What changed from the previous capture 65 lines
     There are probably countless stories of heartbreak behind those transaction that we will never hear about.
     So many tears, so much fear and desperation, all hidden behind blockchain addresses and transaction ID.
     How long can that hacker carry the burden of all these broken lives on his conscience! Will he really close his eyes and sleep peacefully!
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: collardelay on August 09, 2026, 04:58:55 AM
    +Quote from: CucakRowo on Today at 02:44:40 AM
    +Two OP_Return messages brought tears to my eyes.
    +One said, ''Please return at least some of the stolen money".
    +Another said, "Suicide tonight if you don't give me back what I worked 12 years, my 6.4 BTC".
    +Who knows how many dreams these people were carrying in their heart? Maybe this was someone's dream of giving their children a secure little future. Maybe someone had been saving that money hoping they could pay for their aging parents treatment. Maybe some people spent their entire live working to achieve this 3 or 4 BTC, and then, in a matter of minute it was all gone.
    +There are probably countless stories of heartbreak behind those transaction that we will never hear about.
    +So many tears, so much fear and desperation, all hidden behind blockchain addresses and transaction ID.
    +How long can that hacker carry the burden of all these broken lives on his conscience! Will he really close his eyes and sleep peacefully!
    +You would be surprised how evil people can be.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Italian Panic on August 09, 2026, 06:48:38 AM
    +Quote from: fillippone on August 08, 2026, 03:39:10 PM
    +A very interesting read on an improvement idea that could solve the self custody trilemma:
    +https://talkimg.com/images/2026/08/08/UoqAPH.jpeg (https://x.com/lukechilds/status/2085802947670356209?s=46&t=ybCp3ydjDJA_wR_uVxrEgA)
    +Waiting for some commercial solution to implement it.
    +I�m sure that generating secure seeds and passphrases will be quite a challenge in light of what happened with ColdCard, but this solution also requires relying on third parties and provides a phone number, so it could compromise the privacy of those who don�t have a front man. I think we�ll need to look a little further ahead; we�ll need to find a real solution for self-custody as we understand it today and for our long- and very long-term goals.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: joker_josue on August 09, 2026, 08:05:56 AM
    +Quote from: CucakRowo on Today at 02:44:40 AM
    +How long can that hacker carry the burden of all these broken lives on his conscience! Will he really close his eyes and sleep peacefully!
    +Well, it seems that the coins, after being stolen, were not touched again.
    +Is the hacker still thinking about what to do, or is he feeling guilty?
    +The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
    +I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.
    +Quote from: Italian Panic on Today at 06:48:38 AM
    +I�m sure that generating secure seeds and passphrases will be quite a challenge in light of what happened with ColdCard, but this solution also requires relying on third parties and provides a phone number, so it could compromise the privacy of those who don�t have a front man. I think we�ll need to look a little further ahead; we�ll need to find a real solution for self-custody as we understand it today and for our long- and very long-term goals.
    +Perhaps we need to look again at the master Satoshi and see how he created his wallets.
    +They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: LoyceV on August 09, 2026, 08:27:01 AM
    +Quote from: joker_josue on Today at 08:05:56 AM
    +The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
    +I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.
    +That's why I came up with this theory:
    +Quote from: LoyceV on August 01, 2026, 06:24:45 AM
    +Or could it just be an amateur who's in way over his head? Someone who accidentally stumbled upon this weakness, and suddenly ended up with $70 million in stolen funds?
    +Quote from: joker_josue on Today at 08:05:56 AM
    +Perhaps we need to look again at the master Satoshi and see how he created his wallets.
    +They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.
    +Satoshi used Send to Pubkey transactions, whilch may become quantum vulnerable in the future. That's not the best example for the long term. But his random generation must have been pretty good :)
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: joker_josue on August 09, 2026, 08:38:14 AM
    +Quote from: LoyceV on Today at 08:27:01 AM
    +Quote from: joker_josue on Today at 08:05:56 AM
    +The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
    +I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.
    +That's why I came up with this theory:
    +Quote from: LoyceV on August 01, 2026, 06:24:45 AM
    +Or could it just be an amateur who's in way over his head? Someone who accidentally stumbled upon this weakness, and suddenly ended up with $70 million in stolen funds?
    +I don't think he's exactly an amateur, but I understand the point.
    +I can imagine the situation: he discovers the flaw and goes to test it to see if it's really true.
    +Start running the script, perhaps with the goal of verifying if your own wallets are affected. Within minutes, they begin targeting third-party wallets with hundreds of BTC being transferred to your account.
    +I believe the first reaction will be one of shock, but at the same time, incredibly exciting.
    +Suddenly 1000 BTC appears in your account. You must be ecstatic in your basement.
    +You're probably already thinking of a thousand and one things you'll want to do with that money.
    +As the hours tick by and the news breaks, the dilemma begins: how are you going to move the money without getting caught? I stole hundreds of BTC from people who saved their whole lives. What have I done!?
    +Now you may be debating whether to return everything, return part of it, or ignore the matter altogether.
    +Quote from: LoyceV on Today at 08:27:01 AM
    +Quote from: joker_josue on Today at 08:05:56 AM
    +Perhaps we need to look again at the master Satoshi and see how he created his wallets.
    +They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.
    +Satoshi used Send to Pubkey transactions, whilch may become quantum vulnerable in the future. That's not the best example for the long term. But his random generation must have been pretty good :)
    +I'm talking about the seed (so to speak), because to date that's what's guaranteeing the security of these coins.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1596 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +63 -45

    The thread gained a new post about passphrase search economics and another about OP_Return suicide messages, while many relative quote timestamps were rendered as absolute dates.

    seen · Captured here 554,804 chars
    What changed from the previous capture 108 lines
     And to be frank with all of you, I'm starting to think this is very justifiable to a point.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: joker_josue on August 08, 2026, 07:39:17 AM
    -Quote from: BlackHatCoiner on Today at 07:32:36 AM
    +Quote from: BlackHatCoiner on August 08, 2026, 07:32:36 AM
     I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.
     If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.
     And to be frank with all of you, I'm starting to think this is very justifiable to a point.
     What really needs to be done is for people to read or reread the Bitcoin white paper again, to understand or remember what Bitcoin is.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: BlackHatCoiner on August 08, 2026, 07:57:42 AM
    -Quote from: joker_josue on Today at 07:39:17 AM
    +Quote from: joker_josue on August 08, 2026, 07:39:17 AM
     Owning a Bitcoin ETF is not the same as owning Bitcoin!
     Obviously, but what most people want to get from Bitcoin is appreciating value overtime. This is what I think is what most people want.
     I really hope people aren't into Bitcoin just for the appreciating value aspect, and they also appreciate the fact that nobody can take it away from you without your permission, but I'm just afraid that through the current chaos, it is very difficult to support this claim, considering the average person does not know 99% of what most people in here know about self-custody. Most people will just not roll a dice.
     [1] https://x.com/oomahq/status/2085717166884618584
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: flatt on August 08, 2026, 09:55:35 AM
    -Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: LoyceV on August 08, 2026, 08:07:50 AM
     Quote from: vapourminer on August 04, 2026, 10:34:44 AM
     some people have a non passphrase wallet as a decoy with passphrases behind it.
     I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
     FYI, brute-forcing passphrase for a single wallet most likely TOOK MORE TIME than brute-forcing the whole ColdCard default seed.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: kTimesG on August 08, 2026, 10:04:42 AM
    -Quote from: JayJuanGee on Today at 02:25:57 AM
    +Quote from: JayJuanGee on August 08, 2026, 02:25:57 AM
     You are saying also that no entropy was added by any dice rolls, so I would need to be explained the mechanics of how that would be based on if you are saying that there might have been an override of the Cold Card software that pushed it back to the 40 bits of entropy?
     It's not 40 bits of entropy, more like 23 (or even less, CC would know better of their die cutting parameters). Watching the official YouTube easy guide "5 minutes setup" of a fresh CC adds some 6 additional bits. Each dice adds around 2 bits on top of this. So that's only around 2 to 3 billion guesses for all seeds out of all entropies + one dice rolls. A laptop can break that in an hour.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: bitmover on August 08, 2026, 11:09:28 AM
    -Quote from: joker_josue on Today at 07:39:17 AM
    -Quote from: BlackHatCoiner on Today at 07:32:36 AM
    +Quote from: joker_josue on August 08, 2026, 07:39:17 AM
    +Quote from: BlackHatCoiner on August 08, 2026, 07:32:36 AM
     I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.
     If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.
     And to be frank with all of you, I'm starting to think this is very justifiable to a point.
     I am also affraid that when you own a bitcoin ETF you do not own a permitionless money, but you can at least have some protection against inflation.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: joker_josue on August 08, 2026, 11:19:59 AM
    -Quote from: sergiorus on Today at 09:50:09 AM
    +Quote from: sergiorus on August 08, 2026, 09:50:09 AM
     Someone on Twitter [1] did their own investigation and is claiming a possible inside job.
     It's a thread of many tweets, the link is here (https://x.com/oomahq/status/2085717166884618584)
     I had heard him talk about this investigation, but I hadn't found it yet.
     Things are going to get very ugly for the Coldcard team. It remains to be seen when the first lawsuits will start to come.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: vapourminer on August 08, 2026, 11:51:30 AM
    -Quote from: BlackHatCoiner on Today at 07:32:36 AM
    +Quote from: BlackHatCoiner on August 08, 2026, 07:32:36 AM
     I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.
     If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.
     And to be frank with all of you, I'm starting to think this is very justifiable to a point.
     im on team dice but only because i hang on this forum. i easily could of been a victim years ago.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: BlackHatCoiner on August 08, 2026, 11:56:08 AM
    -Quote from: vapourminer on Today at 11:51:30 AM
    +Quote from: vapourminer on August 08, 2026, 11:51:30 AM
     its always been this way really.
     I know, but I used to tell to newcomers that you can "just get a hardware wallet and sleep easy" in case they didn't want to trust an exchange (and many don't trust them). Now I'm not sure what the correct suggestion is. Expecting them to use a signing device and roll dice is not something I can recommend to everyday people.
     Quote
     I never trusted my computer's RNG in the first place, and I remember asking in this forum how most people do trust it. (I know the Coldcard issue was not the hardware's RNG per se, but I still would rather trust something I can verify with my own eyes.)
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: Cricktor on August 08, 2026, 12:09:10 PM
    -Quote from: joker_josue on Today at 07:23:16 AM
    +Quote from: joker_josue on August 08, 2026, 07:23:16 AM
     The only way to be prepared anywhere in the world is to always have your seed with you.
     How many of us have all the seeds with us 365 days a year, always?
     If that were actually necessary, we should consider the whole setup to be terribly wrong and faulty. I find this very very wrong to have to carry my mnemonic seeds with me all the time. Sorry, no, this should NOT be necessary! And it is not necessary if we knew that entropy generation wasn't screwed up completely.
     Apparently there's more due diligence needed to verify that entropy generation isn't flawed. Easier said, than done, though...
     I must say, I'm genuinely surprised how badly a hardware wallet vendor screwed this up like Coinkite did. I thought light-hearted that this shouldn't be possible because it's such a basic and important functionality to NOT screw up the random stuff when you have TRNGs available. I'm still puzzled...
    -Quote from: NotATether on Today at 07:26:21 AM
    +Quote from: NotATether on August 08, 2026, 07:26:21 AM
     The necessary step is, and I'll keep yelling this from rooftops until it reaches mass adoption, to generate your own seed phrase yourself, without any hardware wallet.
     And also make a BIP39 passphrase for your seed.
     This can only work if users learn and understand how to safely and properly generate their own mnemonic seeds. There are many ways to screw this up without being easily able to notice it.
     A mnemonic passphrase (the additional thing) needs to be complex enough to withstand brute-force attacks (it's also computationally somewhat expensive as each guess iteration requires 2048 rounds of PBKDF2 with HMAC-SHA512), but it adds a security layer with no margin for error if you fail to document it properly and highly recommended also redundantly. Commonly you should also separate it from your mnemonic recovery words, so it needs separate secure storage places.
     That's quite a (necessary) burden with many possibilities for people to screw up.
     On the other hand, with the necessary knowledge and understanding, I'm with you. I just have doubts it will work out for the masses.
    -Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: LoyceV on August 08, 2026, 08:07:50 AM
     I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
     If the additional mnemonic passphrase is brute-forceable, the creator has failed already badly. It does not make sense to me, e.g. to use just a few additional words from the BiP39 wordlist. The mnemonic passphrase needs to be complex enough that brute-force attacks are not feasible.
     With a complex enough mnemonic passphrase I consider the "decoy" wallet as a valuable canary indicator of compromise. Users of such a setup should of course pay very much attention to not link their "decoy" UTXOs with their "hidden" main stash(es).
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: LoyceV on August 08, 2026, 12:22:57 PM
    -Quote from: flatt on Today at 09:55:35 AM
    -Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: flatt on August 08, 2026, 09:55:35 AM
    +Quote from: LoyceV on August 08, 2026, 08:07:50 AM
     Quote from: vapourminer on August 04, 2026, 10:34:44 AM
     some people have a non passphrase wallet as a decoy with passphrases behind it.
     I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
     Quote
     FYI, brute-forcing passphrase for a single wallet most likely TOOK MORE TIME than brute-forcing the whole ColdCard default seed.
     That completely depends on the passphrase. If someone uses just 2 BIP39 words, that only gives 4 million possibilities, which is many orders of magnitude easier to brute-force than the weak seed words.
    -Quote from: BlackHatCoiner on Today at 11:56:08 AM
    +Quote from: BlackHatCoiner on August 08, 2026, 11:56:08 AM
     I know, but I used to tell to newcomers that you can "just get a hardware wallet and sleep easy" in case they didn't want to trust an exchange (and many don't trust them). Now I'm not sure what the correct suggestion is.
     I used to recommend Ledger or Trezor, until Ledger went nuts. Now I'd recommend Trezor only, just because they've been around for a long time. But even though I know one fuckup doesn't mean another hardware wallet will do the same, the rate at which hardware wallets are disappearing from being trusted is not comforting. I've also seen hardware wallets that simply lose support after a few years, and users will have to buy a new one again. This is something for the long run, if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.
    -Quote from: Cricktor on Today at 12:09:10 PM
    +Quote from: Cricktor on August 08, 2026, 12:09:10 PM
     With a complex enough mnemonic passphrase I consider the "decoy" wallet as a valuable canary indicator of compromise. Users of such a setup should of course pay very much attention to not link their "decoy" UTXOs with their "hidden" main stash(es).
     The one major reason for me to choose a hardware wallet over offline cold storage, is that it's much more convenient to make a payment. If I have to manually enter 12 randon words on a devide with 2 buttons each time I want to make a payment, I don''t really see the point of using it anymore.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: vapourminer on August 08, 2026, 12:43:16 PM
    -Quote from: LoyceV on Today at 12:22:57 PM
    -Quote from: flatt on Today at 09:55:35 AM
    -Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: LoyceV on August 08, 2026, 12:22:57 PM
    +Quote from: flatt on August 08, 2026, 09:55:35 AM
    +Quote from: LoyceV on August 08, 2026, 08:07:50 AM
     Quote from: vapourminer on August 04, 2026, 10:34:44 AM
     some people have a non passphrase wallet as a decoy with passphrases behind it.
     I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
     Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".
     perhaps there is a script that monitors the decoy addy. the decoy gets swept: tons of warnings in real life start happening. gives a head start to move the passphrased coins out.
     one works from real life attacks, one works from cyber attacks.. half dozen of one is 6 of the other, pick yer poison
    -Quote from: LoyceV on Today at 12:22:57 PM
    +Quote from: LoyceV on August 08, 2026, 12:22:57 PM
     [...] if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.
     pretty much this. and i started with one of the 1st trezors. i still trust trezor but i bring my own entropy now.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: philipma1957 on August 08, 2026, 01:30:05 PM
    -Quote from: vapourminer on Today at 12:43:16 PM
    -Quote from: LoyceV on Today at 12:22:57 PM
    -Quote from: flatt on Today at 09:55:35 AM
    -Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: vapourminer on August 08, 2026, 12:43:16 PM
    +Quote from: LoyceV on August 08, 2026, 12:22:57 PM
    +Quote from: flatt on August 08, 2026, 09:55:35 AM
    +Quote from: LoyceV on August 08, 2026, 08:07:50 AM
     Quote from: vapourminer on August 04, 2026, 10:34:44 AM
     some people have a non passphrase wallet as a decoy with passphrases behind it.
     I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
     Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".
     perhaps there is a script that monitors the decoy addy. the decoy gets swept: tons of warnings in real life start happening. gives a head start to move the passphrased coins out.
     one works from real life attacks, one works from cyber attacks.. half dozen of one is 6 of the other, pick yer poison
    -Quote from: LoyceV on Today at 12:22:57 PM
    +Quote from: LoyceV on August 08, 2026, 12:22:57 PM
     [...] if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.
     pretty much this. and i started with one of the 1st trezors. i still trust trezor but i bring my own entropy now.
     Yeah I ended up adding passphrase to my trezors.
     do I like it no
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: Woodie on August 08, 2026, 01:43:17 PM
    -Quote from: sergiorus on Today at 09:50:09 AM
    +Quote from: sergiorus on August 08, 2026, 09:50:09 AM
     Someone on Twitter [1] did their own investigation and is claiming a possible inside job.
     It's a thread of many tweets, the link is here (https://x.com/oomahq/status/2085717166884618584)
     ~snip~
     https://x.com/COLDCARDwallet/status/1447213375398846473
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: flatt on August 08, 2026, 01:56:14 PM
    -Quote from: LoyceV on Today at 12:22:57 PM
    +Quote from: LoyceV on August 08, 2026, 12:22:57 PM
     Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".
     There have already been reports of 2-word passphrases being compromised.
     That completely depends on the passphrase. If someone uses just 2 BIP39 words, that only gives 4 million possibilities, which is many orders of magnitude easier to brute-force than the weak seed words.
     I still believe in SHA256, and accessing my funds from anywhere I want without letting a company give me the keys to my funds or storing my own keys in SDB is far worse.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: flatt on August 08, 2026, 02:22:40 PM
    -Quote from: philipma1957 on Today at 01:30:05 PM
    -Quote from: vapourminer on Today at 12:43:16 PM
    -Quote from: LoyceV on Today at 12:22:57 PM
    -Quote from: flatt on Today at 09:55:35 AM
    -Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: philipma1957 on August 08, 2026, 01:30:05 PM
    +Quote from: vapourminer on August 08, 2026, 12:43:16 PM
    +Quote from: LoyceV on August 08, 2026, 12:22:57 PM
    +Quote from: flatt on August 08, 2026, 09:55:35 AM
    +Quote from: LoyceV on August 08, 2026, 08:07:50 AM
     Quote from: vapourminer on August 04, 2026, 10:34:44 AM
     some people have a non passphrase wallet as a decoy with passphrases behind it.
     I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
     Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".
     perhaps there is a script that monitors the decoy addy. the decoy gets swept: tons of warnings in real life start happening. gives a head start to move the passphrased coins out.
     one works from real life attacks, one works from cyber attacks.. half dozen of one is 6 of the other, pick yer poison
    -Quote from: LoyceV on Today at 12:22:57 PM
    +Quote from: LoyceV on August 08, 2026, 12:22:57 PM
     [...] if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.
     pretty much this. and i started with one of the 1st trezors. i still trust trezor but i bring my own entropy now.
     Yeah I ended up adding passphrase to my trezors.
     I would never make myself harder than before like that, but currently I choose my favorite signature, hashes it and put it as my extra passphrase, which I can access it from anywhere anytime.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: LoyceV on August 08, 2026, 02:24:10 PM
    -Quote from: flatt on Today at 01:56:14 PM
    +Quote from: flatt on August 08, 2026, 01:56:14 PM
     This still doesn't increase the risk as you claim.
     You're still missing the point: if someone added a passphrase to his weak Coldcard without funding a decoy wallet, his funds wouldn't have been taken. It's the decoy that makes the seed words and thus potential passphrase light up.
     Quote
     At this point it's easier to just type a private key, it's shorter.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: joker_josue on August 08, 2026, 02:34:51 PM
    -Quote from: vapourminer on Today at 11:51:30 AM
    +Quote from: vapourminer on August 08, 2026, 11:51:30 AM
     im on team dice but only because i hang on this forum. i easily could of been a victim years ago.
     You build your seeds with the dice and then "retrieve" them in a hardware wallet?
    -Quote from: Cricktor on Today at 12:09:10 PM
    -Quote from: joker_josue on Today at 07:23:16 AM
    +Quote from: Cricktor on August 08, 2026, 12:09:10 PM
    +Quote from: joker_josue on August 08, 2026, 07:23:16 AM
     The only way to be prepared anywhere in the world is to always have your seed with you.
     How many of us have all the seeds with us 365 days a year, always?
     If that were actually necessary, we should consider the whole setup to be terribly wrong and faulty. I find this very very wrong to have to carry my mnemonic seeds with me all the time. Sorry, no, this should NOT be necessary! And it is not necessary if we knew that entropy generation wasn't screwed up completely.
     The seed is not meant to be passed around; it should be kept safe and sound in a secure place. Of course, it's good for a person to think about how they can access the seed if they can't return to its original location. But that's a different matter altogether.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: flatt on August 08, 2026, 02:40:44 PM
    -Quote from: LoyceV on Today at 02:24:10 PM
    -Quote from: flatt on Today at 01:56:14 PM
    +Quote from: LoyceV on August 08, 2026, 02:24:10 PM
    +Quote from: flatt on August 08, 2026, 01:56:14 PM
     This still doesn't increase the risk as you claim.
     You're still missing the point: if someone added a passphrase to his weak Coldcard without funding a decoy wallet, his funds wouldn't have been taken. It's the decoy that makes the seed words and thus potential passphrase light up.
     Good point, but at that point, there's no such decoy thing if you're not funding on it.
     Waiting for some commercial solution to implement it.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: Meuserna on August 08, 2026, 05:33:19 PM
    -Quote from: NotATether on Today at 07:26:21 AM
    +Quote from: NotATether on August 08, 2026, 07:26:21 AM
     Quote from: Forsyth Jones on August 07, 2026, 03:01:28 AM
     The Coldcard case made it clear, at the very least, that creating a wallet, writing down the seed phrase, depositing some funds, and only opening the wallet 10 years later IS NOT ENOUGH. A strategy for acting during trips is more than necessary.
     The necessary step is, and I'll keep yelling this from rooftops until it reaches mass adoption, to generate your own seed phrase yourself, without any hardware wallet.
     I know this list sounds like a lot, but really it's not.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: Meuserna on August 08, 2026, 05:43:45 PM
    -Quote from: flatt on Today at 09:55:35 AM
    -Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: flatt on August 08, 2026, 09:55:35 AM
    +Quote from: LoyceV on August 08, 2026, 08:07:50 AM
     Quote from: vapourminer on August 04, 2026, 10:34:44 AM
     some people have a non passphrase wallet as a decoy with passphrases behind it.
     I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
     I believe it's wiser to use a simple passphrase as a decoy wallet. One word, easily cracked, for a decoy wallet. And leave the seed-only wallet untouched, never used.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: LoyceV on August 08, 2026, 08:13:37 PM
    -Quote from: Meuserna on Today at 05:43:45 PM
    +Quote from: Meuserna on August 08, 2026, 05:43:45 PM
     I believe it's wiser to use a simple passphrase as a decoy wallet. One word, easily cracked, for a decoy wallet. And leave the seed-only wallet untouched, never used.
     I like this option! In Coldcard's case, it would likely have taking the attacker a very long time to search the entire seed word space for simple passphrase options.
     Question: how do brute-force attacks typically work? Do they check against the first address in a wallet, or the first N addresses?
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: Meuserna on August 08, 2026, 08:53:35 PM
    -Quote from: LoyceV on Today at 08:13:37 PM
    -Quote from: Meuserna on Today at 05:43:45 PM
    +Quote from: LoyceV on August 08, 2026, 08:13:37 PM
    +Quote from: Meuserna on August 08, 2026, 05:43:45 PM
     I believe it's wiser to use a simple passphrase as a decoy wallet. One word, easily cracked, for a decoy wallet. And leave the seed-only wallet untouched, never used.
     I like this option! In Coldcard's case, it would likely have taking the attacker a very long time to search the entire seed word space for simple passphrase options.
     Question: how do brute-force attacks typically work? Do they check against the first address in a wallet, or the first N addresses?
     Brute force attacking passphrases is only feasible if the attacker has a reason to check that specific seed phrase.
     If a seed phrase has never been used by itself as a wallet, an attacker has no way of knowing if it's been used with a passphrase or as part of a multisig... unless the attacker found the paper/metal backup of course. That's an obvious clue the seed was probably used. But in the ColdCard attacks, the thieves are searching seed phrases based on the list of billions of possible seeds the borked ColdCard firmware could generate.
     If your seed phrase was truly random, it cannot be found by seed phrase hunting. Bu ColdCard's seeds weren't truly random, so they can be found by using the same borked method ColdCard used.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: joker_josue on August 08, 2026, 10:09:15 PM
    +Quote from: Meuserna on August 08, 2026, 08:53:35 PM
    +If a seed phrase has never been used by itself as a wallet, an attacker has no way of knowing if it's been used with a passphrase or as part of a multisig... unless the attacker found the paper/metal backup of course. That's an obvious clue the seed was probably used. But in the ColdCard attacks, the thieves are searching seed phrases based on the list of billions of possible seeds the borked ColdCard firmware could generate.
    +If your seed phrase was truly random, it cannot be found by seed phrase hunting. Bu ColdCard's seeds weren't truly random, so they can be found by using the same borked method ColdCard used.
    +In short, a passphrase doesn't necessarily need to be highly complex, because even something simple (I'm not talking about the word "bitcoin"...) will generate a very high number of probabilities, which will take a long time to discover.
    +The attackers must be able to afford to search by passphrase because they already know the seeds. Since they already have a database of seeds with balances, it becomes easier for them to use techniques similar to those used to find passwords.
    +They no longer have to find sequences of 24 words +1, they only have to find that one +1.
    +Furthermore, the profit they've already made allows them to continue their research without significant losses or risks. Everything they find now is a bonus.
    +Title: Re: Large-scale Coldcard compromise (1596 BTC stolen so far)
    +Post by: CucakRowo on August 09, 2026, 02:44:40 AM
    +Two OP_Return messages brought tears to my eyes.
    +One said, ''Please return at least some of the stolen money".
    +Another said, "Suicide tonight if you don't give me back what I worked 12 years, my 6.4 BTC".
    +Who knows how many dreams these people were carrying in their heart? Maybe this was someone's dream of giving their children a secure little future. Maybe someone had been saving that money hoping they could pay for their aging parents treatment. Maybe some people spent their entire live working to achieve this 3 or 4 BTC, and then, in a matter of minute it was all gone.
    +There are probably countless stories of heartbreak behind those transaction that we will never hear about.
    +So many tears, so much fear and desperation, all hidden behind blockchain addresses and transaction ID.
    +How long can that hacker carry the burden of all these broken lives on his conscience! Will he really close his eyes and sleep peacefully!
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1596 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +78 -1

    The thread title updated to 1,596 BTC stolen and gained several new replies discussing seed-generation methods, decoy-wallet risks, and passphrase brute-force mechanics.

    seen · Captured here 551,869 chars
    What changed from the previous capture 79 lines
     Bitcoin Forum
     Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    -Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Title: Large-scale Coldcard compromise (1596 BTC stolen so far)
     Post by: flatfly on July 30, 2026, 08:44:17 PM
     https://x.com/Rob1Ham/status/2082896614218203616
     [EDIT]
     This still doesn't increase the risk as you claim.
     You're still missing the point: if someone added a passphrase to his weak Coldcard without funding a decoy wallet, his funds wouldn't have been taken. It's the decoy that makes the seed words and thus potential passphrase light up.
     Good point, but at that point, there's no such decoy thing if you're not funding on it.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: fillippone on August 08, 2026, 03:39:10 PM
    +A very interesting read on an improvement idea that could solve the self custody trilemma:
    +https://talkimg.com/images/2026/08/08/UoqAPH.jpeg (https://x.com/lukechilds/status/2085802947670356209?s=46&t=ybCp3ydjDJA_wR_uVxrEgA)
    +Waiting for some commercial solution to implement it.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Meuserna on August 08, 2026, 05:33:19 PM
    +Quote from: NotATether on Today at 07:26:21 AM
    +Quote from: Forsyth Jones on August 07, 2026, 03:01:28 AM
    +The Coldcard case made it clear, at the very least, that creating a wallet, writing down the seed phrase, depositing some funds, and only opening the wallet 10 years later IS NOT ENOUGH. A strategy for acting during trips is more than necessary.
    +The necessary step is, and I'll keep yelling this from rooftops until it reaches mass adoption, to generate your own seed phrase yourself, without any hardware wallet.
    +And also make a BIP39 passphrase for your seed.
    +THIS. It's what I've been doing for a few years, and it's not hard.
    +Print the BIPP39 wordlist in columns, on paper. Cut the sheets of paper into strips with one word per strip. Put the strips of paper in a large mixing bowl. Pick a word. Write it down. Put the word back in the bowl. Mix 'em up and pick again. Do this 23 times.
    +It's perfectly safe to let a hardware calculate the checksum word. Out of the entire list of 2048 words, only 7 or 8 will form a checksum for a 24 word seed. So, you're not sacrificing any randomness by letting a hardware wallet calculate the checksum word.
    +You've now got a totally random 24 word seed phrase. And you know it's random because you did the work.
    +Pick another 10 words from the bowl of paper strips. That's your passphrase.
    +I'm sure somebody is thinking "But the paper strips don't weigh exactly the same!" That's right. Any imperfections  just add to the randomness since those imperfections can't be predicted or calculated.
    +I started doing this after Ledger added key extraction to their firmware. I was a Ledger user back then, and their actions made me question how much I could trust the firmware for any device. So, I figured, if I don't let a device generate my seed phrase, I don't have to trust the device.
    +I also swear by ShieldSigner, which is a fork of SeedSigner that adds encrypted Seed QR, passphrase QR, and smartcard support (SeedKeeper and Satochip).
    +This gives me the ability to use my seed on a device which is airgapped and stateless.
    +I generated the seed, so I know I can't be part of a seed-hunter search like ColdCard's, because I know my seed is truly random.
    +I use the seed on a device that is airgapped, so I know it can't be reached by online hackers.
    +I don't save the seed or the wallet on the hardware wallet device. If it gets stolen, there's nothing on it for a thief to find.
    +For travel, I really like the ability to keep seeds on a SeedKeeper smart card. It's just a java card, but it has a secure element chip, and it wipes itself out after 5 incorrect password attempts. You can even set the number of allowed attempts lower.
    +The steps for rock solid security:
    +1. Generate your own seed.
    +2. Use a strong passphrase.
    +3. Back up your seed and passphrase on metal.
    +4. Store your seed and passphrase somewhere secure. Somewhere only you have access to. Preferably 2 places, separate.
    +5. Choose a hardware wallet that is open source, airgapped, stateless, and offers encrypted seed backup for easy loading. ShieldSigner and Krux make all of this easy.
    +6. Get a small safe to keep in your home, where you'll store any documentation that needs to be written down. Document everything for your setup, even if only to help yourself remember "How'd I generate this seed? Why'd I set it up this way?"
    +7. Get home automation and put a sensor on the safe, to send you instant notifications if it is opened or moved. Aqara makes this easy and cheap. On sale, you can get an Aqara hub & sensors for under $50.
    +I know this list sounds like a lot, but really it's not.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Meuserna on August 08, 2026, 05:43:45 PM
    +Quote from: flatt on Today at 09:55:35 AM
    +Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: vapourminer on August 04, 2026, 10:34:44 AM
    +some people have a non passphrase wallet as a decoy with passphrases behind it.
    +I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
    +You missed 2 real things: the perspective of hacker & the function of decoy.
    +it's called decoy for a reason. once the owner see their decoy is gone , the owner can immediately move the funds. it does not increased the risk at all, it literally does increased the security for the funds. and in this case (the worst case ever displayed on this day UNTIL probably 100 next years), the hacker knows well brute-forcing into passphrase is such a waste of time because the owner could be already moved the real funds within no-time.
    +FYI, brute-forcing passphrase for a single wallet most likely TOOK MORE TIME than brute-forcing the whole ColdCard default seed.
    +I've changed my mind about decoy wallets. I now think using the seed-only wallet as a decoy isn't a good idea.
    +Using the seed-only wallet as a decoy lets whoever finds that seed know the seed phrase has been used. That gives them a reason to start searching passphrases.
    +The ColdCard attackers had to search billions of seed phrases to find coins. Searching billions of seed phrases isn't hard since the attacker was surely running automated scripts to generate wallets and check addresses. Almost all of the seeds were empty. Maybe a few thousand out of billions of seeds had wallets.
    +Even in the ColdCard situation, where the total number of possible seeds is limited and known, it's still billions of seeds. It isn't feasible for thieves to try to crack passphrases for billions of wallets, since they don't know which of the billions of seeds might have passphrase wallets except for those which had something at the main seed-only wallet. Those thieves are trying to crack passphrases of seeds they know have been used.
    +I believe it's wiser to use a simple passphrase as a decoy wallet. One word, easily cracked, for a decoy wallet. And leave the seed-only wallet untouched, never used.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: LoyceV on August 08, 2026, 08:13:37 PM
    +Quote from: Meuserna on Today at 05:43:45 PM
    +I believe it's wiser to use a simple passphrase as a decoy wallet. One word, easily cracked, for a decoy wallet. And leave the seed-only wallet untouched, never used.
    +I like this option! In Coldcard's case, it would likely have taking the attacker a very long time to search the entire seed word space for simple passphrase options.
    +Question: how do brute-force attacks typically work? Do they check against the first address in a wallet, or the first N addresses?
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Meuserna on August 08, 2026, 08:53:35 PM
    +Quote from: LoyceV on Today at 08:13:37 PM
    +Quote from: Meuserna on Today at 05:43:45 PM
    +I believe it's wiser to use a simple passphrase as a decoy wallet. One word, easily cracked, for a decoy wallet. And leave the seed-only wallet untouched, never used.
    +I like this option! In Coldcard's case, it would likely have taking the attacker a very long time to search the entire seed word space for simple passphrase options.
    +Question: how do brute-force attacks typically work? Do they check against the first address in a wallet, or the first N addresses?
    +It depends on what's being brute forced and how the attacker tries to do it.
    +Seed Phrases:
    +The ColdCard firmware flaw caused ColdCard to only generate seeds from a small number of possibilities. It's still in the billions though.
    +What the original attacker surely did was run a script to generate the same list of seed phrases. Billions. The script then generated wallets from those seed phrases and searched addresses for a balance. Evidence suggests the attacker's script stopped searching a seed when it found an empty address and moved on to the next seed.
    +Normally, hunting for wallets by searching random seeds is impossible. There are too many possible seed phrase combinations to search. It's in the quadrillions of quadrillions of quadrillions. But the ColdCard firmware bug meant all seeds generated by ColdCard came from a much smaller list unless the user used dice rolls. This made it possible to hunt for ColdCard seed phrases.
    +And by the way... I'm sure attackers are trying to find 2-of-3 multisigs this way. They're generating seed phrases and testing combinations to see if any generate wallets with a balance. That's a much slower process, but for attackers, it just means running a script and letting it churn away as it tests combinations. I do think 2-of-3 multisig wallets created on ColdCards will be found.
    +Passphrases:
    +Trying to crack a passphrase is different.
    +The first thing an attacker will probably do is a dictionary search. They'll run a script to try all words to see if any are being used as a passphrase. Anything more than 4 or 5 words isn't going to be easily found. Anything more than 6 words isn't going to be found at all.
    +Again, to be clear: They'll generate a wallet at the seed+abandon to see if they get an address with a balance. No? They'll generate a wallet for the seed+ability to see if they get an address with a balance. Etc. They have to generate and check every wallet, one at a time.
    +Th next thing an attacker will probably try is a charachter search. This is slower. They have to generate a wallet for the seed+a... then the seed+b... then the seed+c. And they have to test every wallet for every number and symbol too. Then they start over to check wallets for the seed+aa and the seed+ab and the seed+ac... etc. They'll be running a script that churns away until it finds something.
    +Here's the thing:
    +Brute force attacking passphrases is only feasible if the attacker has a reason to check that specific seed phrase.
    +If a seed phrase has never been used by itself as a wallet, an attacker has no way of knowing if it's been used with a passphrase or as part of a multisig... unless the attacker found the paper/metal backup of course. That's an obvious clue the seed was probably used. But in the ColdCard attacks, the thieves are searching seed phrases based on the list of billions of possible seeds the borked ColdCard firmware could generate.
    +If your seed phrase was truly random, it cannot be found by seed phrase hunting. Bu ColdCard's seeds weren't truly random, so they can be found by using the same borked method ColdCard used.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1596 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +232 -42

    The opening post added Telegram and web scam links to its warning list with a second edit, and the thread gained replies debating decoy and passphrase risk, referencing an inside-job tweet, and comparing self-custody to ETFs.

    seen · Captured here 540,788 chars
    What changed from the previous capture 274 lines
     Code:
     https://t.me/coldcardREAL
     https://t.me/coldcardMigration
    +https://t.me/ColdcardwalletTG
    +https://t.me/ColdCardDev
     These groups are swaming with scammers that want victims to use their malicious links:
     Code:
     https://swiftprotocolresolvers.web.app/
     https://dapplogin-connect.com
     https://t.me/AiCustomerSupport247_bot
     https://onchains-hub.vercel.app
    +https://meta-masks.vercel.app
    +http://multichaindecent.web.app/
     Do not enter seed words there! Do not send funds there! Do not download any software from there!
     Edit. Added new scams
    +Edit 2. Added new scams
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: NUCLEAR7.1 on August 04, 2026, 10:13:31 PM
     Quote from: shahzadafzal on August 04, 2026, 09:12:58 PM
     Post by: LoyceV on August 08, 2026, 08:07:50 AM
     Quote from: vapourminer on August 04, 2026, 10:34:44 AM
     some people have a non passphrase wallet as a decoy with passphrases behind it.
    -I wonder how many people realize that in this case, a "decoy" wallet actually increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
    -Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    -Post by: Kalicharan on August 08, 2026, 08:28:41 AM
    -WEEK 1 (02.08 - 08.08)
    -Telegram Profile Link https://t.me/Kalicharan44
    -Twitter profile link https://twitter.com/kalicharan44
    -Twitter campaign
    -Twitter Profile Link https://twitter.com/kalicharan44
    -Followers:
    -Retweet
    -1.  https://x.com/i/status/2084472592816042180
    -2. https://x.com/i/status/2085190036769873937
    -3. https://x.com/i/status/2086002779735405013
    -4. https://x.com/i/status/2086002868147093896
    -5. https://x.com/i/status/2086002936044507487
    -Tweet
    -1. https://x.com/i/status/2084476655976972778
    -Facebook campaign
    -Facebook Profile Link: https://www.facebook.com/Kalicharan44
    -Friends:
    -Spreadsheet #:
    -Shares
    -1. https://www.facebook.com/100083630666228/posts/1019528570844822/?app=fbl
    -2. https://www.facebook.com/100083630666228/posts/1021225910675088/?app=fbl
    -3. https://www.facebook.com/100083630666228/posts/1023146377149708/?app=fbl
    -4. https://www.facebook.com/100083630666228/posts/1023146587149687/?app=fbl
    -5. https://www.facebook.com/100083630666228/posts/1023146653816347/?app=fbl
    -post
    -1. https://www.facebook.com/100083630666228/posts/pfbid037en1TBb1bVp8yNJwpmLBfktSLgF3zf33icNXHcvFuBLe5BCCJzRzUE9gU5zRA7Vjl/
    -Shilling: campaign
    -Telegram shilling:
    -1. https://t.me/ICOCryptoReview/275888
    -2. https://t.me/CryptoInvestorsNews2020/501915
    -3. https://t.me/BestCryptoInvestments2020/307746
    -4. https://x.com/i/status/2086005537494425782
    -5. https://x.com/i/status/2086006097052393533
    -Twitter shilling:
    -1. https://x.com/i/status/2084476655976972778
    -2. https://x.com/i/status/2085191004135862508
    -3. https://x.com/i/status/2086004652911554719
    -4. https://t.me/CryptoAirdropBounties/530979
    -5. https://t.me/ICOCryptoReview/275957
    +I wonder how many people realize that in this case, a "decoy" wallet would have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: sergiorus on August 08, 2026, 09:50:09 AM
    +Someone on Twitter [1] did their own investigation and is claiming a possible inside job.
    +It's a thread of many tweets, the link is here (https://x.com/oomahq/status/2085717166884618584)
    +The OP tweet:
    +Quote
    +I did my own investigation because I obviously don't trust them.
    +What I found is that the external dependency of the firmware with the critical vulnerability hidden in it was written by CoinKite's CTO
    +@DocHex
    +pretending to be someone else.
    +All of the following can be verified:
    +https://pbs.twimg.com/media/HPH0qqaXoAI_7FI?format=jpg&name=medium
    +[1] https://x.com/oomahq/status/2085717166884618584
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: flatt on August 08, 2026, 09:55:35 AM
    +Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: vapourminer on August 04, 2026, 10:34:44 AM
    +some people have a non passphrase wallet as a decoy with passphrases behind it.
    +I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
    +You missed 2 real things: the perspective of hacker & the function of decoy.
    +it's called decoy for a reason. once the owner see their decoy is gone , the owner can immediately move the funds. it does not increased the risk at all, it literally does increased the security for the funds. and in this case (the worst case ever displayed on this day UNTIL probably 100 next years), the hacker knows well brute-forcing into passphrase is such a waste of time because the owner could be already moved the real funds within no-time.
    +FYI, brute-forcing passphrase for a single wallet most likely TOOK MORE TIME than brute-forcing the whole ColdCard default seed.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: kTimesG on August 08, 2026, 10:04:42 AM
    +Quote from: JayJuanGee on Today at 02:25:57 AM
    +You are saying also that no entropy was added by any dice rolls, so I would need to be explained the mechanics of how that would be based on if you are saying that there might have been an override of the Cold Card software that pushed it back to the 40 bits of entropy?
    +It's not 40 bits of entropy, more like 23 (or even less, CC would know better of their die cutting parameters). Watching the official YouTube easy guide "5 minutes setup" of a fresh CC adds some 6 additional bits. Each dice adds around 2 bits on top of this. So that's only around 2 to 3 billion guesses for all seeds out of all entropies + one dice rolls. A laptop can break that in an hour.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: bitmover on August 08, 2026, 11:09:28 AM
    +Quote from: joker_josue on Today at 07:39:17 AM
    +Quote from: BlackHatCoiner on Today at 07:32:36 AM
    +I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.
    +If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.
    +And to be frank with all of you, I'm starting to think this is very justifiable to a point.
    +Owning a Bitcoin ETF is not the same as owning Bitcoin!
    +What really needs to be done is for people to read or reread the Bitcoin white paper again, to understand or remember what Bitcoin is.
    +I think both points are valid.
    +But it is much better to own a bitcoin ETF than to own a hacked wallet.
    +Maybe it will make sense for some people to have both.
    +I am also affraid that when you own a bitcoin ETF you do not own a permitionless money, but you can at least have some protection against inflation.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: joker_josue on August 08, 2026, 11:19:59 AM
    +Quote from: sergiorus on Today at 09:50:09 AM
    +Someone on Twitter [1] did their own investigation and is claiming a possible inside job.
    +It's a thread of many tweets, the link is here (https://x.com/oomahq/status/2085717166884618584)
    +I had heard him talk about this investigation, but I hadn't found it yet.
    +Thank you for sharing.
    +Things are going to get very ugly for the Coldcard team. It remains to be seen when the first lawsuits will start to come.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: vapourminer on August 08, 2026, 11:51:30 AM
    +Quote from: BlackHatCoiner on Today at 07:32:36 AM
    +I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.
    +If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.
    +And to be frank with all of you, I'm starting to think this is very justifiable to a point.
    +its always been this way really. ive always recommended (shudder) a registered exchange for noobs. because they expect to be able to "reset" passwords (pins, passphrases) on demand. the fact that they lose a piece of paper and it gone for good? thats not for most of the people i meet.
    +so only after they fully understand self custody do i recommend hardware airgaped wallets etc.
    +most people in general arent ready for self custody and it seems many here werent ready either.
    +im on team dice but only because i hang on this forum. i easily could of been a victim years ago.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: BlackHatCoiner on August 08, 2026, 11:56:08 AM
    +Quote from: vapourminer on Today at 11:51:30 AM
    +its always been this way really.
    +I know, but I used to tell to newcomers that you can "just get a hardware wallet and sleep easy" in case they didn't want to trust an exchange (and many don't trust them). Now I'm not sure what the correct suggestion is. Expecting them to use a signing device and roll dice is not something I can recommend to everyday people.
    +Quote
    +im on team dice but only because i hang on this forum. i easily could of been a victim years ago.
    +I never trusted my computer's RNG in the first place, and I remember asking in this forum how most people do trust it. (I know the Coldcard issue was not the hardware's RNG per se, but I still would rather trust something I can verify with my own eyes.)
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Cricktor on August 08, 2026, 12:09:10 PM
    +Quote from: joker_josue on Today at 07:23:16 AM
    +The only way to be prepared anywhere in the world is to always have your seed with you.
    +How many of us have all the seeds with us 365 days a year, always?
    +If that were actually necessary, we should consider the whole setup to be terribly wrong and faulty. I find this very very wrong to have to carry my mnemonic seeds with me all the time. Sorry, no, this should NOT be necessary! And it is not necessary if we knew that entropy generation wasn't screwed up completely.
    +Apparently there's more due diligence needed to verify that entropy generation isn't flawed. Easier said, than done, though...
    +I must say, I'm genuinely surprised how badly a hardware wallet vendor screwed this up like Coinkite did. I thought light-hearted that this shouldn't be possible because it's such a basic and important functionality to NOT screw up the random stuff when you have TRNGs available. I'm still puzzled...
    +Quote from: NotATether on Today at 07:26:21 AM
    +The necessary step is, and I'll keep yelling this from rooftops until it reaches mass adoption, to generate your own seed phrase yourself, without any hardware wallet.
    +And also make a BIP39 passphrase for your seed.
    +This can only work if users learn and understand how to safely and properly generate their own mnemonic seeds. There are many ways to screw this up without being easily able to notice it.
    +A mnemonic passphrase (the additional thing) needs to be complex enough to withstand brute-force attacks (it's also computationally somewhat expensive as each guess iteration requires 2048 rounds of PBKDF2 with HMAC-SHA512), but it adds a security layer with no margin for error if you fail to document it properly and highly recommended also redundantly. Commonly you should also separate it from your mnemonic recovery words, so it needs separate secure storage places.
    +That's quite a (necessary) burden with many possibilities for people to screw up.
    +On the other hand, with the necessary knowledge and understanding, I'm with you. I just have doubts it will work out for the masses.
    +Quote from: LoyceV on Today at 08:07:50 AM
    +I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
    +If the additional mnemonic passphrase is brute-forceable, the creator has failed already badly. It does not make sense to me, e.g. to use just a few additional words from the BiP39 wordlist. The mnemonic passphrase needs to be complex enough that brute-force attacks are not feasible.
    +With a complex enough mnemonic passphrase I consider the "decoy" wallet as a valuable canary indicator of compromise. Users of such a setup should of course pay very much attention to not link their "decoy" UTXOs with their "hidden" main stash(es).
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: LoyceV on August 08, 2026, 12:22:57 PM
    +Quote from: flatt on Today at 09:55:35 AM
    +Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: vapourminer on August 04, 2026, 10:34:44 AM
    +some people have a non passphrase wallet as a decoy with passphrases behind it.
    +I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
    +You missed 2 real things: the perspective of hacker & the function of decoy.
    +Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".
    +Quote
    +the hacker knows well brute-forcing into passphrase is such a waste of time because the owner could be already moved the real funds within no-time.
    +There have already been reports of 2-word passphrases being compromised.
    +Quote
    +FYI, brute-forcing passphrase for a single wallet most likely TOOK MORE TIME than brute-forcing the whole ColdCard default seed.
    +That completely depends on the passphrase. If someone uses just 2 BIP39 words, that only gives 4 million possibilities, which is many orders of magnitude easier to brute-force than the weak seed words.
    +Quote from: BlackHatCoiner on Today at 11:56:08 AM
    +I know, but I used to tell to newcomers that you can "just get a hardware wallet and sleep easy" in case they didn't want to trust an exchange (and many don't trust them). Now I'm not sure what the correct suggestion is.
    +I used to recommend Ledger or Trezor, until Ledger went nuts. Now I'd recommend Trezor only, just because they've been around for a long time. But even though I know one fuckup doesn't mean another hardware wallet will do the same, the rate at which hardware wallets are disappearing from being trusted is not comforting. I've also seen hardware wallets that simply lose support after a few years, and users will have to buy a new one again. This is something for the long run, if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.
    +Quote from: Cricktor on Today at 12:09:10 PM
    +With a complex enough mnemonic passphrase I consider the "decoy" wallet as a valuable canary indicator of compromise. Users of such a setup should of course pay very much attention to not link their "decoy" UTXOs with their "hidden" main stash(es).
    +The one major reason for me to choose a hardware wallet over offline cold storage, is that it's much more convenient to make a payment. If I have to manually enter 12 randon words on a devide with 2 buttons each time I want to make a payment, I don''t really see the point of using it anymore.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: vapourminer on August 08, 2026, 12:43:16 PM
    +Quote from: LoyceV on Today at 12:22:57 PM
    +Quote from: flatt on Today at 09:55:35 AM
    +Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: vapourminer on August 04, 2026, 10:34:44 AM
    +some people have a non passphrase wallet as a decoy with passphrases behind it.
    +I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
    +You missed 2 real things: the perspective of hacker & the function of decoy.
    +Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".
    +perhaps there is a script that monitors the decoy addy. the decoy gets swept: tons of warnings in real life start happening. gives a head start to move the passphrased coins out.
    +one works from real life attacks, one works from cyber attacks.. half dozen of one is 6 of the other, pick yer poison
    +Quote from: LoyceV on Today at 12:22:57 PM
    +[...] if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.
    +pretty much this. and i started with one of the 1st trezors. i still trust trezor but i bring my own entropy now.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: philipma1957 on August 08, 2026, 01:30:05 PM
    +Quote from: vapourminer on Today at 12:43:16 PM
    +Quote from: LoyceV on Today at 12:22:57 PM
    +Quote from: flatt on Today at 09:55:35 AM
    +Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: vapourminer on August 04, 2026, 10:34:44 AM
    +some people have a non passphrase wallet as a decoy with passphrases behind it.
    +I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
    +You missed 2 real things: the perspective of hacker & the function of decoy.
    +Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".
    +perhaps there is a script that monitors the decoy addy. the decoy gets swept: tons of warnings in real life start happening. gives a head start to move the passphrased coins out.
    +one works from real life attacks, one works from cyber attacks.. half dozen of one is 6 of the other, pick yer poison
    +Quote from: LoyceV on Today at 12:22:57 PM
    +[...] if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.
    +pretty much this. and i started with one of the 1st trezors. i still trust trezor but i bring my own entropy now.
    +Yeah I ended up adding passphrase to my trezors.
    +3 washers with 8 characters each
    +I decided on 32 of my 36 punches knock out 0OIL
    +so my passphrases are 32 to the 8th cubed or
    +1099511627776 x 1099511627776 x 109951162776
    +that's 121 bits and the 1099511627776 is all the cold card had as that is 40 bits.
    +as for convinent well the trezor has a standard wallet with say 0.04 BTC and the each of the 3
    +passphrases have say 0.32BTC total 1 of  btc
    +what's nice is keeping the passphrase in my banks safety deposit box slows .96 btc from my own spending
    +issues.
    +do I like it no
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Woodie on August 08, 2026, 01:43:17 PM
    +Quote from: sergiorus on Today at 09:50:09 AM
    +Someone on Twitter [1] did their own investigation and is claiming a possible inside job.
    +It's a thread of many tweets, the link is here (https://x.com/oomahq/status/2085717166884618584)
    +~snip~
    +Inside job would be an understatement, see shared tweet.. is this possible that this was left as a backdoor for themselves ?
    +They had a light moment about the entropy bug 🐛 and some years pass they get hit by the very entropy generation bug. Definitely pulled a retirement job on their clients and it was just a matter of time!
    +https://www.talkimg.com/images/2026/08/08/Uoeig3.jpg
    +https://x.com/COLDCARDwallet/status/1447213375398846473
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: flatt on August 08, 2026, 01:56:14 PM
    +Quote from: LoyceV on Today at 12:22:57 PM
    +Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".
    +There have already been reports of 2-word passphrases being compromised.
    +That completely depends on the passphrase. If someone uses just 2 BIP39 words, that only gives 4 million possibilities, which is many orders of magnitude easier to brute-force than the weak seed words.
    +In this case, and many similar cases to come, a passphrase is still a good way to secure your funds, and letting hackers eat the decoy as a warning to move your funds immediately. This still doesn't increase the risk as you claim. The rest depends on how the user uses the "passphrase." The user could even use a one-word passphrase with 64 hexadecimal characters, and the funds would still be there until next Christmas when the user is ready to move the funds.
    +In short, it depends on:
    +1. How the attacker detects whether it's a decoy address and decides to invest all their resources in a single wallet that they believe "It's a decoy, got a correct passphrase and you'll get the whale." which there's no script / tools exist for detecting such things.
    +2. (MOST IMPORTANTLY) how the user leverages the passphrase instead of entering their Instagram password to secure their real funds.
    +I still believe in SHA256, and accessing my funds from anywhere I want without letting a company give me the keys to my funds or storing my own keys in SDB is far worse.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: flatt on August 08, 2026, 02:22:40 PM
    +Quote from: philipma1957 on Today at 01:30:05 PM
    +Quote from: vapourminer on Today at 12:43:16 PM
    +Quote from: LoyceV on Today at 12:22:57 PM
    +Quote from: flatt on Today at 09:55:35 AM
    +Quote from: LoyceV on Today at 08:07:50 AM
    +Quote from: vapourminer on August 04, 2026, 10:34:44 AM
    +some people have a non passphrase wallet as a decoy with passphrases behind it.
    +I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
    +You missed 2 real things: the perspective of hacker & the function of decoy.
    +Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".
    +perhaps there is a script that monitors the decoy addy. the decoy gets swept: tons of warnings in real life start happening. gives a head start to move the passphrased coins out.
    +one works from real life attacks, one works from cyber attacks.. half dozen of one is 6 of the other, pick yer poison
    +Quote from: LoyceV on Today at 12:22:57 PM
    +[...] if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.
    +pretty much this. and i started with one of the 1st trezors. i still trust trezor but i bring my own entropy now.
    +Yeah I ended up adding passphrase to my trezors.
    +3 washers with 8 characters each
    +I decided on 32 of my 36 punches knock out 0OIL
    +so my passphrases are 32 to the 8th cubed or
    +1099511627776 x 1099511627776 x 109951162776
    +that's 121 bits and the 1099511627776 is all the cold card had as that is 40 bits.
    +as for convinent well the trezor has a standard wallet with say 0.04 BTC and the each of the 3
    +passphrases have say 0.32BTC total 1 of  btc
    +what's nice is keeping the passphrase in my banks safety deposit box slows .96 btc from my own spending
    +issues.
    +do I like it no
    +I would never make myself harder than before like that, but currently I choose my favorite signature, hashes it and put it as my extra passphrase, which I can access it from anywhere anytime.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: LoyceV on August 08, 2026, 02:24:10 PM
    +Quote from: flatt on Today at 01:56:14 PM
    +This still doesn't increase the risk as you claim.
    +You're still missing the point: if someone added a passphrase to his weak Coldcard without funding a decoy wallet, his funds wouldn't have been taken. It's the decoy that makes the seed words and thus potential passphrase light up.
    +Quote
    +The user could even use a one-word passphrase with 64 hexadecimal characters
    +At this point it's easier to just type a private key, it's shorter.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: joker_josue on August 08, 2026, 02:34:51 PM
    +Quote from: vapourminer on Today at 11:51:30 AM
    +im on team dice but only because i hang on this forum. i easily could of been a victim years ago.
    +You build your seeds with the dice and then "retrieve" them in a hardware wallet?
    +Quote from: Cricktor on Today at 12:09:10 PM
    +Quote from: joker_josue on Today at 07:23:16 AM
    +The only way to be prepared anywhere in the world is to always have your seed with you.
    +How many of us have all the seeds with us 365 days a year, always?
    +If that were actually necessary, we should consider the whole setup to be terribly wrong and faulty. I find this very very wrong to have to carry my mnemonic seeds with me all the time. Sorry, no, this should NOT be necessary! And it is not necessary if we knew that entropy generation wasn't screwed up completely.
    +Apparently there's more due diligence needed to verify that entropy generation isn't flawed. Easier said, than done, though...
    +Exactly, I agree.
    +The seed is not meant to be passed around; it should be kept safe and sound in a secure place. Of course, it's good for a person to think about how they can access the seed if they can't return to its original location. But that's a different matter altogether.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: flatt on August 08, 2026, 02:40:44 PM
    +Quote from: LoyceV on Today at 02:24:10 PM
    +Quote from: flatt on Today at 01:56:14 PM
    +This still doesn't increase the risk as you claim.
    +You're still missing the point: if someone added a passphrase to his weak Coldcard without funding a decoy wallet, his funds wouldn't have been taken. It's the decoy that makes the seed words and thus potential passphrase light up.
    +Good point, but at that point, there's no such decoy thing if you're not funding on it.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +94 -0

    The thread title was updated to 1,485.77 BTC stolen and many new posts were added discussing dice entropy, passphrase strategy, ETF custody and a spam-like social-media campaign post.

    seen · Captured here 518,413 chars
    What changed from the previous capture 94 lines
     https://talkimg.com/images/2026/08/07/UoDbFv.jpeg
     https://x.com/coletu/status/2085823098742317223
     After 2 days and 2 hours, the insecure seed phrase with random account number (3459) was swept to this wallet address. https://mempool.space/address/bc1q4gj72x6zz3ax7q6fh4gefamcjjuhu6q0jpf03, apparently the attackers searches different accounts derivation path. I'm wondering how many billions or trillions of private keys they will be generating at this speed.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: JayJuanGee on August 08, 2026, 02:25:57 AM
    +Quote from: kTimesG on August 07, 2026, 10:35:44 PM
    +Quote from: JayJuanGee on August 07, 2026, 06:35:00 PM
    +You believe that the dice rolls were not adding any entropy for those who ended up choosing the dice rolls, and that ColdCard's software was not accounting for the dice rolls for those who chose dice rolls - which supposedly 50 rolls would cause 128 bits of entropy and 100 rolls 256 bits of entropy.
    +Oh, they were definitely accounted, but accounted to what's basically a zero-entropy state.
    +Transaction from the last wave 93651006580a975b (https://mempool.space/tx/93651006580a975babfdf68b39a0a27324b981d7fdd543a082d64facd2d14dc9) on Aug. 2 spent from 9 distinct compromised CC, all of them used dice. Unless ofcourse someone owned 9 different CC and acted (but the use of a consolidation instead of separate TXs says something else).
    +I am not smart enough to know how the provided link shows that dice were used in order to create the seed words.
    +Of course, if there were fewer than 50 rolls, so for example, 25 dice rolls, then 64.62 bits of entropy would be provided, which might not be too difficult to crack, but still 64 bits is better than 40 bits.. .which is part of the reason that 50 rolls minimum were to allow for 128 bits of entropy, which is standard for a 12 word seed.
    +Maybe you are saying that there were dice rolls but fewer than 50 rolls?  maybe fewer than 25 rolls?
    +You are saying also that no entropy was added by any dice rolls, so I would need to be explained the mechanics of how that would be based on if you are saying that there might have been an override of the Cold Card software that pushed it back to the 40 bits of entropy? or for some reason the cold card was not accepting the inputted dice roll entropy, even if it might have met the standard of 50 rolls for 12 words or 100 rolls for 24 words.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: joker_josue on August 08, 2026, 07:23:16 AM
    +Quote from: Forsyth Jones on August 07, 2026, 03:01:28 AM
    +The Coldcard case made it clear, at the very least, that creating a wallet, writing down the seed phrase, depositing some funds, and only opening the wallet 10 years later IS NOT ENOUGH. A strategy for acting during trips is more than necessary.
    +Yes, today we can reach that conclusion. But until two weeks ago, that wasn't what was expected to be necessary.
    +In reality, this is still not the case, as we continue to see coins that are over 10 years old, intact and safe. Coins that we know belong to people who have already died or to people who lost their seed, remain quietly in their place.
    +Meuserna said something accurate:
    +Quote from: Meuserna on August 06, 2026, 05:49:25 PM
    +I wish more Bitcoiners understood: the device is not the wallet. The seed is the wallet, because the seed generates the addresses and keys.
    +The only way to be prepared anywhere in the world is to always have your seed with you.
    +How many of us have all the seeds with us 365 days a year, always?
    +Yes, today we might have to start making plans to act at any moment. But, unfortunately, until 2 weeks ago, 99.9% of users not imagined that going on a 2-week vacation would require taking their seed.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: NotATether on August 08, 2026, 07:26:21 AM
    +Quote from: Forsyth Jones on August 07, 2026, 03:01:28 AM
    +The Coldcard case made it clear, at the very least, that creating a wallet, writing down the seed phrase, depositing some funds, and only opening the wallet 10 years later IS NOT ENOUGH. A strategy for acting during trips is more than necessary.
    +The necessary step is, and I'll keep yelling this from rooftops until it reaches mass adoption, to generate your own seed phrase yourself, without any hardware wallet.
    +And also make a BIP39 passphrase for your seed.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: BlackHatCoiner on August 08, 2026, 07:32:36 AM
    +I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.
    +If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.
    +And to be frank with all of you, I'm starting to think this is very justifiable to a point.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: joker_josue on August 08, 2026, 07:39:17 AM
    +Quote from: BlackHatCoiner on Today at 07:32:36 AM
    +I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.
    +If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.
    +And to be frank with all of you, I'm starting to think this is very justifiable to a point.
    +Owning a Bitcoin ETF is not the same as owning Bitcoin!
    +What really needs to be done is for people to read or reread the Bitcoin white paper again, to understand or remember what Bitcoin is.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: BlackHatCoiner on August 08, 2026, 07:57:42 AM
    +Quote from: joker_josue on Today at 07:39:17 AM
    +Owning a Bitcoin ETF is not the same as owning Bitcoin!
    +Obviously, but what most people want to get from Bitcoin is appreciating value overtime. This is what I think is what most people want.
    +I really hope people aren't into Bitcoin just for the appreciating value aspect, and they also appreciate the fact that nobody can take it away from you without your permission, but I'm just afraid that through the current chaos, it is very difficult to support this claim, considering the average person does not know 99% of what most people in here know about self-custody. Most people will just not roll a dice.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: LoyceV on August 08, 2026, 08:07:50 AM
    +Quote from: vapourminer on August 04, 2026, 10:34:44 AM
    +some people have a non passphrase wallet as a decoy with passphrases behind it.
    +I wonder how many people realize that in this case, a "decoy" wallet actually increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Kalicharan on August 08, 2026, 08:28:41 AM
    +WEEK 1 (02.08 - 08.08)
    +Telegram Profile Link https://t.me/Kalicharan44
    +Twitter profile link https://twitter.com/kalicharan44
    +Twitter campaign
    +Twitter Profile Link https://twitter.com/kalicharan44
    +Followers:
    +Retweet
    +1.  https://x.com/i/status/2084472592816042180
    +2. https://x.com/i/status/2085190036769873937
    +3. https://x.com/i/status/2086002779735405013
    +4. https://x.com/i/status/2086002868147093896
    +5. https://x.com/i/status/2086002936044507487
    +Tweet
    +1. https://x.com/i/status/2084476655976972778
    +Facebook campaign
    +Facebook Profile Link: https://www.facebook.com/Kalicharan44
    +Friends:
    +Spreadsheet #:
    +Shares
    +1. https://www.facebook.com/100083630666228/posts/1019528570844822/?app=fbl
    +2. https://www.facebook.com/100083630666228/posts/1021225910675088/?app=fbl
    +3. https://www.facebook.com/100083630666228/posts/1023146377149708/?app=fbl
    +4. https://www.facebook.com/100083630666228/posts/1023146587149687/?app=fbl
    +5. https://www.facebook.com/100083630666228/posts/1023146653816347/?app=fbl
    +post
    +1. https://www.facebook.com/100083630666228/posts/pfbid037en1TBb1bVp8yNJwpmLBfktSLgF3zf33icNXHcvFuBLe5BCCJzRzUE9gU5zRA7Vjl/
    +Shilling: campaign
    +Telegram shilling:
    +1. https://t.me/ICOCryptoReview/275888
    +2. https://t.me/CryptoInvestorsNews2020/501915
    +3. https://t.me/BestCryptoInvestments2020/307746
    +4. https://x.com/i/status/2086005537494425782
    +5. https://x.com/i/status/2086006097052393533
    +Twitter shilling:
    +1. https://x.com/i/status/2084476655976972778
    +2. https://x.com/i/status/2085191004135862508
    +3. https://x.com/i/status/2086004652911554719
    +4. https://t.me/CryptoAirdropBounties/530979
    +5. https://t.me/ICOCryptoReview/275957
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. source content difference between and source content +70 -10

    The thread title was updated to 1,485.77 BTC stolen and several new posts discussed the flaw, attribution, mitigation and on-chain experiments.

    seen · Captured here 509,896 chars
    What changed from the previous capture 80 lines
     I think the major risk here is the user: having a too complicated setup puts the operational risk very high, and I am thinking if this is the real risk, when the entropy used to generate the seed is sufficient.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: Cricktor on August 07, 2026, 07:06:05 AM
    -Quote from: philipma1957 on Today at 01:53:04 AM
    +Quote from: philipma1957 on August 07, 2026, 01:53:04 AM
     ...
     I don't want to diminish the idea of the punches and stamping stuff into metal.
     What bothers me is the execution. Putting the punches in such a "tight" container won't mix them very well even when you rotate the container and pick punches blind-folded or with closed eyes. Do you really think humans pick punches in a completely random way out of such container even when they don't look at what they're doing?
     The only explanation I can come is that they were actively still searching for victims during this time, they did not already have already the keys for all of them!
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: mabji1 on August 07, 2026, 08:39:05 AM
    -Quote from: stompix on Today at 08:19:20 AM
    +Quote from: stompix on August 07, 2026, 08:19:20 AM
     Quote from: Stalker22 on August 06, 2026, 02:02:27 PM
     Quote from: stompix on August 06, 2026, 11:12:59 AM
     I doubt they have planned it this way all along but indeed, it came at one of the worst times possible,
     It is highly improbable that they had all the keys from day one and simply waited for "fun." The most logical conclusion is a combination of staggered data exfiltration and a deliberate rate-limiting strategy to stay under the radar of on-chain monitoring tools for as long as possible.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: Numan467 on August 07, 2026, 09:17:38 AM
    -Quote from: ABCbits on Today at 08:08:23 AM
    +Quote from: ABCbits on August 07, 2026, 08:08:23 AM
     Quote from: Pmalek on August 06, 2026, 03:35:05 PM
     Bitcoin Red Team consists of 16 people who are working around the clock now and running security audits on Bitcoin code bases. According to their report, they have already made close to 5,000 findings and discovered what they believe are 85 critical and 635 high severity issues. They report these issues back to project owners and companies, and I think that's a great thing that has come out of this terrible situation. Whitehats and industry experts joining forces to help secure the wider Bitcoin ecosystem.
     https://xcancel.com/callebtc/status/2085024458012586286
     Note: this didn't take months of preparation or trillions of scans. It's simply just a catastrophic system failure on the firmware coder's part. The first attacker simply probably didn't bother to dig deeper, while the subsequent ones did.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: vapourminer on August 07, 2026, 10:51:07 AM
    -Quote from: Forsyth Jones on Today at 03:01:28 AM
    +Quote from: Forsyth Jones on August 07, 2026, 03:01:28 AM
     The Coldcard case made it clear, at the very least, that creating a wallet, writing down the seed phrase, depositing some funds, and only opening the wallet 10 years later IS NOT ENOUGH. A strategy for acting during trips is more than necessary.
     many many decades ago i used to hide things like a PINs and other codes as phone numbers on a piece of paper. like Vivian xxx-xxx-xxxx would have the PIN for my Visa debit card or things along those lines.. door codes etc.
     back then before smartphones no one looked twice at a phone list. now a printed phone list would probably be sus in itself.
     now? need to hide 128 bits worth somewhere.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: bitmover on August 07, 2026, 11:41:17 AM
    -Quote from: philipma1957 on Today at 01:53:04 AM
    +Quote from: philipma1957 on August 07, 2026, 01:53:04 AM
     I would rather just buy a hardware wallet and add a passphrase.
     Or you can just flip a coin 256 times and add results to iancoleman.io
     Dont need to buy anything too fancy
     Source: https://www.bloomberg.com/news/articles/2026-08-06/hacked-bitcoin-wallet-maker-declines-to-estimate-amount-lost
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: Pmalek on August 07, 2026, 03:20:16 PM
    -Quote from: ABCbits on Today at 08:08:23 AM
    +Quote from: ABCbits on August 07, 2026, 08:08:23 AM
     I have mixed thought about it. I can see OpenSats actually fund this person[1] and AFAIK OpenSats generally fund promising person and project. But i also worry about quality/accuracy of their finding. "27.5 hours in, we've filed 4,962 findings across 390 projects" from 16 people and some AI sounds too high/fast. Either way, we'll know how accurate are their findings, by looking at release note of wallet and other cryptocurrency software/library in next few months.
     A few posts down in the thread whose link I posted in my previous post, calle says that the severity of the findings has already been confirmed by (some) projects. They say that certain teams have upgraded while others have downgraded their software releases. I think it's going to be difficult to find out how much of an impact those findings had. Software is regularly updated and unless the developers publicly acknowledge calle's help, we won't know if it's a regular update, an update based on findings from their own team, or an update performed because of vulnerabilities and issues found by the Bitcoin Red Team.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: JayJuanGee on August 07, 2026, 06:35:00 PM
    -Quote from: fillippone on Today at 06:47:41 AM
    +Quote from: fillippone on August 07, 2026, 06:47:41 AM
     Firstly, a very beautiful visualization of the Coldcard Hack:
     https://talkimg.com/images/2026/08/07/Uo8oK9.png (https://x.com/bitcoinpolicy/status/2084337559346548988?s=46&t=ybCp3ydjDJA_wR_uVxrEgA)
     This particularity resonates with the thread I created a long time ago:
     There were quite a few guys on this forum proclaiming that Bitkey is an inferior product to regular hardware wallets (there is even a thread, I think that has not been active lately) because the Bitkey is not really a hardware wallet in the sense of privacy and self-sovereignty as we know hardware wallets to offer (or supposed to offer) since there seem to be several ways that coins can end up getting recovered through the Bitkey without the user's key even being involved.  At least, recently Bitkey added a screen, but still there seems to be a bit of theater in terms of what a bitcoin wallet should be (referring to privacy, self-sovereignty and security).
     I think that self-custody by single sig and a strong passphrase and even self-custody multi-sig are still quite viable (and probably even preferable) paths - even though sometimes there could be multi-sig that would be shared amongst family members, which could work for some kinds of shared funds, and of course, in some business arrangements multi-sig within a group of key players of the business might also be quite practical for how to treat some of the funds.
     I don't like the seeming recent push to give up self-autonomy or the abilities to act autonomously as the base case of bitcoin, even though there could be some cases in which a third key might be given to a 3rd party, but not as our ideas of what are base case uses of bitcoin.
    -Quote from: Cricktor on Today at 07:06:05 AM
    -Quote from: philipma1957 on Today at 01:53:04 AM
    +Quote from: Cricktor on August 07, 2026, 07:06:05 AM
    +Quote from: philipma1957 on August 07, 2026, 01:53:04 AM
     ...
     I don't want to diminish the idea of the punches and stamping stuff into metal.
     What bothers me is the execution. Putting the punches in such a "tight" container won't mix them very well even when you rotate the container and pick punches blind-folded or with closed eyes. Do you really think humans pick punches in a completely random way out of such container even when they don't look at what they're doing?
     To practice this idea of cards, I did go to the Github Repo of the Ian Coleman BIP39 Tool (https://github.com/iancoleman/bip39/releases) in order to try out the inputing of cards, and I had to ask AI to get assistance to make sure that I was setting it up (and doing) it correctly, so then I did a practice round of inputting my cards online (and the preference for security is to do it off-line), and it took me 61 draws to reach 256 bits of entropy, and also it was amazing that I had 27 duplicate draws (a few of them were cards I drew 3 times, such as the king of hearts 3 times and the king of spades 4 times, and I drew the jack of hearts two times, but those two times were twice in a row.
     It still is a lot of work to help to ensure that the wallet is not screwing up entropy, so of course, using a tool like this still has to take some safeguards that the words are not being viewed by someone else - as compared with if we were to just have the 2048 words and to draw them from a hat.
     By the way, since I had to draw cards 61 times in order to achieve 256 bits of entropy, I suppose that is not much different from rolling dice 100 times, since we could have 10 dice and then just roll 10 at a time 10 times in order to reach 100 rolls... so maybe my going through the exercise of drawing cards 61 times causes me to be less enthusiastic about cards as an entropy solution.
    -Quote from: kTimesG on Today at 10:36:15 AM
    +Quote from: kTimesG on August 07, 2026, 10:36:15 AM
     The only thing left are three dust addresses totalling less than 1000 satoshis. Everything else is gone, so that explains why the attackers moved to weak passphrases; there was nothing else left to do. Do not think dice rolls helped, those wallets do exist, and are also gone.
     You believe that the dice rolls were not adding any entropy for those who ended up choosing the dice rolls, and that ColdCard's software was not accounting for the dice rolls for those who chose dice rolls - which supposedly 50 rolls would cause 128 bits of entropy and 100 rolls 256 bits of entropy.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: pbies on August 07, 2026, 07:50:34 PM
    +The PRNG flaw (#ifndef) bug could be from simple oversight by junior or even mid developer.
    +This happens tons of times in normal, corporational companies.
    +System works but details are seen later, too late.
    +Solution: outsider should check the code, always. This is expensive but the only way to grant good programs.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: WellRozey on August 07, 2026, 08:02:10 PM
    +Correct me if ima wrong but this has never happened with hardware wallet before, this is the first time, not in this manner I believe, and crazy things is I've never heard anyone mentioned this ColdCard before, not even on this forum.
    +It's always Ledger, Trezor and few others, I'm shocked about how many people are using this HW, that numbers are very high, it's such as shame, I think that the born of AI makes things easier in both good and bad ways.
    +Hardware manufacturers should start using AI to their advantages too on every decisions they made with their products, finding vulnerability even when your security is very tight is the way to go now, because you just can never tell.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Stalker22 on August 07, 2026, 08:26:44 PM
    +Quote from: pbies on August 07, 2026, 07:50:34 PM
    +The PRNG flaw (#ifndef) bug could be from simple oversight by junior or even mid developer.
    +This happens tons of times in normal, corporational companies.
    +System works but details are seen later, too late.
    +Solution: outsider should check the code, always. This is expensive but the only way to grant good programs.
    +Peter D. Gray (Doc-Hex) is not some junior, or even mid level developer.  He is the CTO and co-founder of Coinkite, a veteran developer with decades of experience, and the guy who wrote the vast majority of Coldcard firmware himself.  He literally set up a pseudonymous alt account (switck) on GitHub to write and merge libNgU code, and pass off his own commits as "peer-reviewed" using his own GPG signing keys.
    +Outsiders did try to warn them about code issues, and Coinkite brushed them off with pure arrogance.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: philipma1957 on August 07, 2026, 10:09:05 PM
    +Quote from: bitmover on August 07, 2026, 11:41:17 AM
    +Quote from: philipma1957 on August 07, 2026, 01:53:04 AM
    +I would rather just buy a hardware wallet and add a passphrase.
    +Or you can just flip a coin 256 times and add results to iancoleman.io
    +Dont need to buy anything too fancy
    +I have the punches on hand cost = zero
    +and after careful study of the 36 punches I can use 32 of them.
    +32x32x32x32x32x32x32x32=1.0995�10��  or  1,099,511,627,776          1 washer of 8 characters
    +32x32x32x32x32x32x32x32=1.0995�10��  or  1,099,511,627,776         2nd washer 8 characters
    +32x32x32x32x32x32x32x32=1.0995�10��  or  1,099,511,627,776        3rd washer 8 characters
    +and 1,099,511,627,776 cube is exactly 121 bits for just the passphrase
    +and if you own a trezor I one some test your seed I did
    +my seed works for recovery
    +adding that  3 washer 24 chart passphrase cost some time and about 1 dollar for the washers.
    +I have the washers as back for the 20 word seed.
    +if you don't back the trezor up with a washer system (some type of back up) not too good.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: kTimesG on August 07, 2026, 10:35:44 PM
    +Quote from: JayJuanGee on August 07, 2026, 06:35:00 PM
    +You believe that the dice rolls were not adding any entropy for those who ended up choosing the dice rolls, and that ColdCard's software was not accounting for the dice rolls for those who chose dice rolls - which supposedly 50 rolls would cause 128 bits of entropy and 100 rolls 256 bits of entropy.
    +Oh, they were definitely accounted, but accounted to what's basically a zero-entropy state.
    +Transaction from the last wave 93651006580a975b (https://mempool.space/tx/93651006580a975babfdf68b39a0a27324b981d7fdd543a082d64facd2d14dc9) on Aug. 2 spent from 9 distinct compromised CC, all of them used dice. Unless ofcourse someone owned 9 different CC and acted (but the use of a consolidation instead of separate TXs says something else).
    +I'm running some AI pre-post-mortem analysis, since there's way too much data. All I can say is that the losses are at least $ 142 million, if not more. It's also somewhat possible this bug was used before for years already. Actually, there's a real possibility that multiple users simply got the same seed over the years, due to the birthday paradox and the limited bounds.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Cookdata on August 07, 2026, 10:47:08 PM
    +Quote from: Cookdata on August 06, 2026, 10:28:24 AM
    +Quote from: ryzaadit on August 06, 2026, 09:03:03 AM
    +Their device detected the sweeps and both of them are in the race for RBF transaction.
    +The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
    +There is a similar experimental video about Mk3 but with different objectives, the person created 5 different wallets using Mk3 Coldcard, the first wallet was generated using the insecure random number generator, the same seed phrase was used to generate 3 wallets with different passphrases and the last wallet which is the 5th was generated using the same seed phrase from a random account.
    +https://talkimg.com/images/2026/08/06/Uo9QgT.png
    +http://x.com/ColeTU/status/2085090397223637049
    +He funded the 5 generated addresses from each wallet with 10800 sats each https://mempool.space/tx/f6a0e25dfa9b03f4a45c65cddeebafb0ea50c9b2732febbafd9a7f40ecf7b7da to see which of the wallet is getting sweep first and it turns out that the insecured RNG which is the first wallet was swept immediately, he could have overide it with a new transaction and pay more fees too but his objective is to see how the scammers are moving the coins and if passphrase 1 word, 2 words or 3 are secured enough with an insucure RNG seed phrase.
    +So far, the first wallet is swept, and the sats are sitting in this address: https://mempool.space/address/bc1qunqajps4elc78m8fq7s7nglc6x80j49exheq78
    +The rest of the wallets with the same seed phrase and passphrases are intact, the same wallet with the same seed phrase but a random account is also intact. That means the scammers focus is on default accounts created from Mk3, they don't search all account derivations.
    +https://talkimg.com/images/2026/08/07/UoDbFv.jpeg
    +https://x.com/coletu/status/2085823098742317223
    +After 2 days and 2 hours, the insecure seed phrase with random account number (3459) was swept to this wallet address. https://mempool.space/address/bc1q4gj72x6zz3ax7q6fh4gefamcjjuhu6q0jpf03, apparently the attackers searches different accounts derivation path. I'm wondering how many billions or trillions of private keys they will be generating at this speed.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  9. source content difference between and source content +33 -0

    The thread gained new posts by Pmalek and JayJuanGee on the Bitcoin Red Team findings and self-custody debates, and the reply titles now show 1,485.77 BTC stolen.

    seen · Captured here 502,774 chars
    What changed from the previous capture 33 lines
     Coldcard Maker Coinkite Says It Will Publish Post-Mortem, Declines to Estimate Customer Losses
     Bloomberg reported that Coinkite, the maker of the Coldcard Bitcoin hardware wallet, said it is focused on assisting customers affected by the security incident and will publish a post-mortem once its full investigation is complete, rather than speculate on the scale of customer losses. Coinkite said the privacy-focused design of its products prevents it from independently verifying external estimates of the amount stolen. Recent outside research has raised estimated losses from the attack to roughly $130 million.
     Source: https://www.bloomberg.com/news/articles/2026-08-06/hacked-bitcoin-wallet-maker-declines-to-estimate-amount-lost
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Pmalek on August 07, 2026, 03:20:16 PM
    +Quote from: ABCbits on Today at 08:08:23 AM
    +I have mixed thought about it. I can see OpenSats actually fund this person[1] and AFAIK OpenSats generally fund promising person and project. But i also worry about quality/accuracy of their finding. "27.5 hours in, we've filed 4,962 findings across 390 projects" from 16 people and some AI sounds too high/fast. Either way, we'll know how accurate are their findings, by looking at release note of wallet and other cryptocurrency software/library in next few months.
    +A few posts down in the thread whose link I posted in my previous post, calle says that the severity of the findings has already been confirmed by (some) projects. They say that certain teams have upgraded while others have downgraded their software releases. I think it's going to be difficult to find out how much of an impact those findings had. Software is regularly updated and unless the developers publicly acknowledge calle's help, we won't know if it's a regular update, an update based on findings from their own team, or an update performed because of vulnerabilities and issues found by the Bitcoin Red Team.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: JayJuanGee on August 07, 2026, 06:35:00 PM
    +Quote from: fillippone on Today at 06:47:41 AM
    +Firstly, a very beautiful visualization of the Coldcard Hack:
    +https://talkimg.com/images/2026/08/07/Uo8oK9.png (https://x.com/bitcoinpolicy/status/2084337559346548988?s=46&t=ybCp3ydjDJA_wR_uVxrEgA)
    +This particularity resonates with the thread I created a long time ago:
    +There are 2^256 private keys out there: how big is that number? (https://bitcointalk.org/index.php?topic=5147514)
    +Regarding the hack, I was almost rushing to rebuild my setup from scratch. But not being affected, I had a double thoughts about refactoring my cold wallet in a multisig with very convolute password.
    +I think the major risk here is the user: having a too complicated setup puts the operational risk very high, and I am thinking if this is the real risk, when the entropy used to generate the seed is sufficient.
    +I am finding it quite annoying how much the bitcoin podcast space had moved from single sig to multi-sig, and they are not even accepting that multi-sig can be a good practice for an individual (because it is too complicated blah blah blah).  It is a bit ridiculous how fast several of them seemed to have switched to throw self-custody under the bus.
    +So in some sense the podcast scene has been pumping the shit out of products that end up fucking up both the privacy and the self-sovereignty aspects of bitcoin.
    +There were quite a few guys on this forum proclaiming that Bitkey is an inferior product to regular hardware wallets (there is even a thread, I think that has not been active lately) because the Bitkey is not really a hardware wallet in the sense of privacy and self-sovereignty as we know hardware wallets to offer (or supposed to offer) since there seem to be several ways that coins can end up getting recovered through the Bitkey without the user's key even being involved.  At least, recently Bitkey added a screen, but still there seems to be a bit of theater in terms of what a bitcoin wallet should be (referring to privacy, self-sovereignty and security).
    +I think that self-custody by single sig and a strong passphrase and even self-custody multi-sig are still quite viable (and probably even preferable) paths - even though sometimes there could be multi-sig that would be shared amongst family members, which could work for some kinds of shared funds, and of course, in some business arrangements multi-sig within a group of key players of the business might also be quite practical for how to treat some of the funds.
    +I don't like the seeming recent push to give up self-autonomy or the abilities to act autonomously as the base case of bitcoin, even though there could be some cases in which a third key might be given to a 3rd party, but not as our ideas of what are base case uses of bitcoin.
    +Quote from: Cricktor on Today at 07:06:05 AM
    +Quote from: philipma1957 on Today at 01:53:04 AM
    +...
    +I don't want to diminish the idea of the punches and stamping stuff into metal.
    +What bothers me is the execution. Putting the punches in such a "tight" container won't mix them very well even when you rotate the container and pick punches blind-folded or with closed eyes. Do you really think humans pick punches in a completely random way out of such container even when they don't look at what they're doing?
    +There will very likely be some bias based on the initial placement of punches. It may look random and maybe doesn't really matter, but it's not any news that humans are commonly terrible at generating good entropy (by inventing some own procedures).
    +Use dice or a known way to throw coins where the latter could even compensate for biased coins or if you fear that your way of tossing coins introduces a bias by itself.
    +I, personally, like the idea of using a deck of cards.  That is 52 possible outcomes as compared with 6 on the dice and 2 on a coin should allow for fewer draws. In theory, instead of rolling a dice 100 times, you could pick 45 cards for the same amount of entropy (I checked this through AI).  That saves a lot of labor.   Too bad hardware wallets do not have an option to choose playing cards for their entropy creation - even though some of us might be skeptical if the wallets are the ones inputting the supposed entropy.
    +To practice this idea of cards, I did go to the Github Repo of the Ian Coleman BIP39 Tool (https://github.com/iancoleman/bip39/releases) in order to try out the inputing of cards, and I had to ask AI to get assistance to make sure that I was setting it up (and doing) it correctly, so then I did a practice round of inputting my cards online (and the preference for security is to do it off-line), and it took me 61 draws to reach 256 bits of entropy, and also it was amazing that I had 27 duplicate draws (a few of them were cards I drew 3 times, such as the king of hearts 3 times and the king of spades 4 times, and I drew the jack of hearts two times, but those two times were twice in a row.
    +It still is a lot of work to help to ensure that the wallet is not screwing up entropy, so of course, using a tool like this still has to take some safeguards that the words are not being viewed by someone else - as compared with if we were to just have the 2048 words and to draw them from a hat.
    +By the way, since I had to draw cards 61 times in order to achieve 256 bits of entropy, I suppose that is not much different from rolling dice 100 times, since we could have 10 dice and then just roll 10 at a time 10 times in order to reach 100 rolls... so maybe my going through the exercise of drawing cards 61 times causes me to be less enthusiastic about cards as an entropy solution.
    +Quote from: kTimesG on Today at 10:36:15 AM
    +The only thing left are three dust addresses totalling less than 1000 satoshis. Everything else is gone, so that explains why the attackers moved to weak passphrases; there was nothing else left to do. Do not think dice rolls helped, those wallets do exist, and are also gone.
    +You believe that the dice rolls were not adding any entropy for those who ended up choosing the dice rolls, and that ColdCard's software was not accounting for the dice rolls for those who chose dice rolls - which supposedly 50 rolls would cause 128 bits of entropy and 100 rolls 256 bits of entropy.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  10. source content difference between and source content +194 -0

    About a dozen new posts, most notably Wind_FURY pasting Inverse Hanlon's long X essay arguing the incident looks like an inside job, kTimesG claiming the attack was over by Aug 2 with about 2050 compromised accounts detected, and sergiorus relaying Bloomberg's report that Coinkite declined to estimate customer losses.

    seen · Captured here 495,172 chars
    What changed from the previous capture 194 lines
     I have been warming up more towards the ideas of several members who proclaim that there is quite a bit of value in future-proofing my own chosen set up a bit more, yet I am not going to point out which areas, exactly, in which I might be currently vulnerable - since even with my own set ups, I have variations in their level of security, and some of them I am considering whether to upgrade sooner or later, and it can surely take a long time to upgrade, as we mentioned in another post in which there was a description of maybe doing 50-ish different transfers after the set up had been made.
     At the same time, we might have our own ways of keeping back up records in regards to what our set-ups might be, so then we might have to update our various back up records too.  It can be difficult (and problematic) to keep too much information in our heads, even if we might think that some of the information is basic, such as the location of each of the pieces of information that might be needed to reconstruct our seed... and then are those pieces of information complete enough or do they include any changes that  we might have had chosen to make.
     This particular attack had a bit of its own uniqueness in terms of potentially creating a bit of a time-buffer for anyone who had any amount of security beyond the various defaults that were built into Cold Card, and that seemed to be one of the problems with the assumptions around cold card, since they seemed to have so many security features within their device.  Accordingly, there were likely a lot of normies (and even somewhat seemingly sophisticated bitcoiners) presuming that since Cold Card had so many various security options that their default must have had at least had some levels of protection, which that was a "HOLY SHIT!!!!" kind of a revelation to find out that Cold Card's default protections (at such a low level as the random number generator) was so damned vulnerable.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: fillippone on August 07, 2026, 06:47:41 AM
    +Firstly, a very beautiful visualization of the Coldcard Hack:
    +https://talkimg.com/images/2026/08/07/Uo8oK9.png (https://x.com/bitcoinpolicy/status/2084337559346548988?s=46&t=ybCp3ydjDJA_wR_uVxrEgA)
    +This particularity resonates with the thread I created a long time ago:
    +There are 2^256 private keys out there: how big is that number? (https://bitcointalk.org/index.php?topic=5147514)
    +Regarding the hack, I was almost rushing to rebuild my setup from scratch. But not being affected, I had a double thoughts about refactoring my cold wallet in a multisig with very convolute password.
    +I think the major risk here is the user: having a too complicated setup puts the operational risk very high, and I am thinking if this is the real risk, when the entropy used to generate the seed is sufficient.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Cricktor on August 07, 2026, 07:06:05 AM
    +Quote from: philipma1957 on Today at 01:53:04 AM
    +...
    +I don't want to diminish the idea of the punches and stamping stuff into metal.
    +What bothers me is the execution. Putting the punches in such a "tight" container won't mix them very well even when you rotate the container and pick punches blind-folded or with closed eyes. Do you really think humans pick punches in a completely random way out of such container even when they don't look at what they're doing?
    +There will very likely be some bias based on the initial placement of punches. It may look random and maybe doesn't really matter, but it's not any news that humans are commonly terrible at generating good entropy (by inventing some own procedures).
    +Use dice or a known way to throw coins where the latter could even compensate for biased coins or if you fear that your way of tossing coins introduces a bias by itself.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: ABCbits on August 07, 2026, 08:08:23 AM
    +Quote from: Pmalek on August 06, 2026, 03:35:05 PM
    +Bitcoin Red Team consists of 16 people who are working around the clock now and running security audits on Bitcoin code bases. According to their report, they have already made close to 5,000 findings and discovered what they believe are 85 critical and 635 high severity issues. They report these issues back to project owners and companies, and I think that's a great thing that has come out of this terrible situation. Whitehats and industry experts joining forces to help secure the wider Bitcoin ecosystem.
    +https://xcancel.com/callebtc/status/2085024458012586286
    +I have mixed thought about it. I can see OpenSats actually fund this person[1] and AFAIK OpenSats generally fund promising person and project. But i also worry about quality/accuracy of their finding. "27.5 hours in, we've filed 4,962 findings across 390 projects" from 16 people and some AI sounds too high/fast. Either way, we'll know how accurate are their findings, by looking at release note of wallet and other cryptocurrency software/library in next few months.
    +[1] https://opensats.org/blog/cashu-calle-receives-lts-grant (https://opensats.org/blog/cashu-calle-receives-lts-grant)
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: stompix on August 07, 2026, 08:19:20 AM
    +Quote from: Stalker22 on August 06, 2026, 02:02:27 PM
    +Quote from: stompix on August 06, 2026, 11:12:59 AM
    +I doubt they have planned it this way all along but indeed, it came at one of the worst times possible,
    +~
    +I think someone DID plan this carefully.  The first few batched transactions were executed almost simultaneously.  This means someone had to crack all the private keys, find the wallets with the largest balances, prepare and sign all the transactions, and just wait for the right time to execute.
    +But if they did prepare for that for let's say a few months...
    +Why did it take 3 days before the first major drain and the second one?
    +He wasted previous time in which news spread, probably not a lot of people were able to move their funds in the meantime but I'm pretty sure some did, so he lost money on that!
    +The first attack was on the 30th of June, Thursday, midday for some, the next one happened Friday night to Saturday, and the third one on Sunday.
    +Why did he or "they" wait for 3-4 days, depending on the timezone to drain them all?
    +The only explanation I can come is that they were actively still searching for victims during this time, they did not already have already the keys for all of them!
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: mabji1 on August 07, 2026, 08:39:05 AM
    +Quote from: stompix on Today at 08:19:20 AM
    +Quote from: Stalker22 on August 06, 2026, 02:02:27 PM
    +Quote from: stompix on August 06, 2026, 11:12:59 AM
    +I doubt they have planned it this way all along but indeed, it came at one of the worst times possible,
    +~
    +I think someone DID plan this carefully.  The first few batched transactions were executed almost simultaneously.  This means someone had to crack all the private keys, find the wallets with the largest balances, prepare and sign all the transactions, and just wait for the right time to execute.
    +But if they did prepare for that for let's say a few months...
    +Why did it take 3 days before the first major drain and the second one?
    +He wasted previous time in which news spread, probably not a lot of people were able to move their funds in the meantime but I'm pretty sure some did, so he lost money on that!
    +The first attack was on the 30th of June, Thursday, midday for some, the next one happened Friday night to Saturday, and the third one on Sunday.
    +Why did he or "they" wait for 3-4 days, depending on the timezone to drain them all?
    +The only explanation I can come is that they were actively still searching for victims during this time, they did not already have already the keys for all of them!
    +It is highly improbable that they had all the keys from day one and simply waited for "fun." The most logical conclusion is a combination of staggered data exfiltration and a deliberate rate-limiting strategy to stay under the radar of on-chain monitoring tools for as long as possible.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Numan467 on August 07, 2026, 09:17:38 AM
    +Quote from: ABCbits on Today at 08:08:23 AM
    +Quote from: Pmalek on August 06, 2026, 03:35:05 PM
    +Bitcoin Red Team consists of 16 people who are working around the clock now and running security audits on Bitcoin code bases. According to their report, they have already made close to 5,000 findings and discovered what they believe are 85 critical and 635 high severity issues. They report these issues back to project owners and companies, and I think that's a great thing that has come out of this terrible situation. Whitehats and industry experts joining forces to help secure the wider Bitcoin ecosystem.
    +https://xcancel.com/callebtc/status/2085024458012586286
    +I have mixed thought about it. I can see OpenSats actually fund this person[1] and AFAIK OpenSats generally fund promising person and project. But i also worry about quality/accuracy of their finding. "27.5 hours in, we've filed 4,962 findings across 390 projects" from 16 people and some AI sounds too high/fast. Either way, we'll know how accurate are their findings, by at release note of wallet and other cryptocurrency software/library in few next months.
    +[1] https://opensats.org/blog/cashu-calle-receives-lts-grant (https://opensats.org/blog/cashu-calle-receives-lts-grant)
    +It was the numbers that caught my attention. Almost 5,000 results on 390 projects in less than a day is pretty cool, but also makes me wonder how much hand checking was done. While AI can scan code very quickly, proof that it is indeed serious flaw usually takes a lot longer.
    +That is why I agree with @ABCbits about waiting before judging the results. Project added value if wallet developers begin to fix bugs from these reports. However, if most of reports turn out to be wrong alarms, then developers may spend much of time working on reports other than working on real safety flaws. While it is good news that OpenSats is supporting the project, the amount of the results will be more important than the amount.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: montaga on August 07, 2026, 09:22:38 AM
    +Amazing how many people still not understand Bitcoin after all the years, embarrassing.
    +https://i.ibb.co/8n2pgXZ3/Untitled.png (https://ibb.co/FkJM4nTv)
    +https://bitcointalk.org/index.php?topic=5389446.0
    +https://bitcointalk.org/index.php?topic=5323755.0
    +Alternative blank alu plate and engraving pin
    +https://www.amazon.com/Credit-Anodized-Aluminum-Metal-Blanks/dp/B074W385L8?th=1
    +.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Wind_FURY on August 07, 2026, 09:36:18 AM
    +Quote from: Wind_FURY on August 06, 2026, 11:22:11 AM
    +--SNIP--
    +Shower thought. The ColdCard situation might be an inside job.
    +Quote
    +Coinkite CTO having a conversation with himself using a pseudonym.
    +https://gist.github.com/dylanleclair1/67d160af313be59851b88d1a81f0d762
    +https://cdn.imgchest.com/files/657ae8dc2b95.jpeg
    +https://x.com/DylanLeClair/status/2085074383773581570
    +👀
    +Warning, LONG POST copied from X. Does this make a case that it's an inside job?
    +Quote
    +Retirement Attack: Coldcard Sold Us a Warning
    +CEO who dismissed the threat by name, a pseudonym that turned out to be the CTO, two warnings four years apart, and a company whose entire answer was that it would have already known.
    +They Sold the Warning
    +On 21 December 2020 (22 Dec UTC), replying to Bitcoin security researcher Michael Flaxman, who had just posted about hardware wallets eliminating the risk of a retirement attack during seed generation and Rodolfo Novak �NVK� addressed the question head on.
    +- My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    +Alternatively people could just use dice ;)
    +Ten weeks later on 1 March 2021, Coinkite�s CTO shipped a commit titled �First pass w/ libNgU� that routed Coldcard�s seed generation into a software pseudorandom number generator seeded from the device�s serial number and a clock.
    +NVK�s threat model in December 2020 pointed outward. Users were the risk. Vendors were not. Ten weeks after he said so his co-founder shipped the vendor version and it stayed shipped for five years.
    +The dice line is the other half: He offered it with a wink and it turned out to be the only thing standing between his customers and total loss.
    +Oops They sold it again
    +On 10 October 2021: seven months into shipping the defect the official Coldcard account posted that Coldcard makes retirement attacks impossible.
    +Someone in the replies asked what a retirement attack was.
    +Coinkite answered it themselves. It�s when the project makers could have a �bug� in the entropy generation for later retrieval.
    +Their scare quotes not mine. By then somebody had already tried to warn them.
    +The escape hatch was optional on purpose
    +Look at what that 2021 post was actually selling: Dice rolls. The documentation it linked to still opens with a sentence that reads differently today; if you don�t trust the TRNGs in your COLDCARD, you can introduce your own randomness with dice. At least ninety nine rolls for a full 256 bits.
    +But that setting is �opt in� and sits behind the default that looks fine from the outside.It asks the user to press buttons a hundred times to avoid trusting the manufacturer.
    +Every person who still has their bitcoin took that option, or used a (strong) passphrase, or ran multisig. Every person who got swept trusted the default.
    +That is the architecture a retirement attack requires. You can�t make the mitigation mandatory because then there�s nothing left to collect. You can�t omit it because the paranoid customers will ask why. So you offer it, document it, recommend at least ninety nine rolls, and let the default do the work. When it detonates the record shows you warned your users, therefore neatly covering your tracks if this was an inside job.
    +Coinkite built the structure, warned of the attack it enables, and then pushed a firmware with a backdoor for five years.
    +The pseudonym was the CTO
    +Here is the detail that reorganizes everything else.
    +Coldcard�s crypto ran through libngu, a library on GitHub under the account switck. About six stars. Maintained by one person: apparently pseudonymous. When James O�Beirne audited the firmware that�s what he found: a random number generation for a device holding billions of dollars in bitcoin backed up to what he described as a shady library with six stars maintained solely by a pseudoanon.
    +Dylan LeClair ran GPG verification against that repo and published the output. James O�Beirne then published a full census: fifty-eight commits authored as Switck carry a good signature from Peter D. Gray�s personal key: the same key that signs nineteen other commits in the same repo under Gray�s own name. The key is expired and the signatures are still good. The RNG selection commit is among them. Signed 28 January 2021, switck published no GPG key of they/their own.
    +Peter Gray is Coinkite�s CTO and cofounded the company with NVK. Coinkite has never had more than about twenty people and by most accounts Gray wrote the large majority of the firmware.
    +So switck was Coinkite�s own CTO. Cryptographically proven; not inferred. Every outside reviewer who looked at libngu saw an unaudited third party dependency by an anonymous stranger and worried about supply chain risk. Coinkite�s own people knew it was in house and had no reason to review it as external code.
    +The use of a pseudonym here means that no one audited that chunk of code. Outsiders assumed insiders had. Insiders knew there was no outside to check.
    +They were warned in 2021
    +Five weeks after the commit on 7 April 2021 someone in a Telegram group flagged the change. Their post sounds in retrospect like a man watching a car roll toward a cliff. Roughly quoting:
    +�The 4.0.x firmware was a radical deviation from every firmware since 2018, with all crypto and BIP39 related code replaced by libNgU. Is it was wise to replace the many-years-old TrezorCrypto code, which has been heavily scrutinized by white hats like Johoe and penetration tested by wallet.fail, with something new. �switck� might be a talented pseudonymous coder, but the commit history is bad� (and they linked to it)
    +The post sat in a Coldcard Telegram group under an embedded NVK tweet about the 4.0.x upgrade: the same tweet in which he said he doesn�t check Telegram.
    +That warning posted five weeks after the defect shipped was correct in every single way. Five years and four months before the money starting mysteriously leaving peoples cold storage.
    +They were warned again in 2025
    +In May 2025 James O�Beirne audited coldcard/firmware. He wanted to establish conclusively where the RNG was sourced from. He traced it into libngu, found the six-star pseudonymous repo, and was confused about why it was there at all. Because linking libsecp256k1 from Python is easy and that appeared to be the stated purpose.
    +He sent Coinkite a report. In his own words: he had �doubts about whether the true RNG was actually in use�, and he pointed out that the �hardcoded yasmarang constants in libngu were sloppy�. He advised them to rip the whole thing out and link against libsecp256k1 directly.
    +That�s the bug! He identified the exact library, constants, and the question of whether the hardware RNG was being used. And he told them to remove it!
    +Coinkite�s answer, as O�Beirne reports, was that if something was wrong �we�d already know about it by now� and that everything was properly configured for the real boards.
    +That is not a technical response. That is an appeal to their own reputation offered to a developer who had just traced the code and found otherwise. And in a separate post O�Beirne identifies Peter Gray �@DocHex� as �the same guy that shrugged off my report of the possibility of the defect in May 2025.� The same Gray who wrote the library. The same Gray who was switck.
    +There was follow-up of a kind. A Signal group titled �LNGU Clean up� was created on 23 May 2025, with members shown as �n,� �Doc,� �andres,� and one other. Doc-hex is Gray. �n� is NVK. So Coinkite formed a group about cleaning up libNgU and named it after the problem. Then they shipped� nothing! Absolutely no fix fourteen months. The group�s messages were set to disappear after four weeks so whatever was said there is gone, just like the bitcoins that were in hundres of hard working peoples Coldcards.
    +O�Beirne blames himself for not pushing harder. He calls not following up rigorously a horrible mistake on his part.
    +Hold that next to Coinkite�s public explanation which is that an attacker probably used AI to find something nobody could reasonably have caught. The developer who caught it is apologizing. The company that was responsibly informed is blaming the clankers.
    +He didn�t know what was in his own crypto library
    +Coinkite�s technical postmortem is worth reading in full because its author is if nothing else candid.
    +He explains that he set the macro to zero believing it meant neither implementation would be compiled. That is not what it does. And he writes that the bulk of the randomness in the device was coming from a PRNG he did not know was in the codebase at all because it arrived through a submodule. Meanwhile the carefully written hardware TRNG code was still being used, but only by accident and only for things that didn�t matter.
    +He is describing a submodule he wrote.
    +The company selling immunity to entropy tampering did not know which random number generator its product used for five years. The man who says he didn�t know is the man who authored both sides of the mistake. And the answer when it finally surfaced was that libngu XORed one software PRNG against a second software PRNG seeded from constants hardcoded in public source. Two deterministic streams XORed together produce a deterministic stream. The built in health check rejects adjacent repeated values which any nondegenerate PRNG passes without effort.
    +Those are the same hardcoded yasmarang constants O�Beirne told them to rip out.
    +Coldcard seeds generated in that window contained no physical randomness whatsoever.
    +They bought a press release not an audit
    +Peter Todd says Coinkite brought him on in early 2014 as �Chief Naysayer�: an advisory role. Years before the first hardware wallet existed there was a press release. By his account he was given nothing to work on: no tasks, no work to bill for, and then the arrangement quietly dropped. He says it�s still on a LinkedIn profile that he hasn�t logged into in a over decade.
    +His assessment now in his own words: �if they had kept him on and asked him to audit the codebases, there�s a good chance he�d have spotted the practices at issue, and maybe eighty million dollars wouldn�t have been stolen�. He puts that audit at roughly $50k and asks what Coinkite spent on podcast sponsorships instead.
    +The company announced that a famous skeptic was reviewing them and then never asked him to review anything. The press release was the product.
    +All the things they said
    +Coinkite�s public position throughout this crisis has been that it had no idea the flaw existed until the day the money started moving. Two documented warnings and a Signal group named after the problem say otherwise.
    +NVK�s stated position on attribution: they �don�t have full attribution or scope yet�, and they �won�t speculate until the technical evaluation is complete�. Coinkite then suggested publicly that the attacker likely used an automated tool to comb the public source and find the flaw before they did. That�s speculation. This propisition rests on absolutely no evidence. And it happens to be the only theory of the case in which nobody at Coinkite knew and nobody at Coinkite failed.
    +You can decline to speculate or you can float the hypothesis that clears you. Doing both inside the same week tells you which one was the priority.
    +Coinkite told customers it kept purchase data for 90 days. When breach notifications went out they reached buyers going back to 2019. Challenged, the company pointed at a policy page, conceded it has no deletion schedule and said the addresses would be kept �for now.�
    +A verifiable lie caught within a few days of the largest breach of trust in hardware wallet history, and on a question where the answer was easily verifiable. This speaks volumes of NVK�s character.
    +The fix broke too
    +On 31 July Coinkite shipped out an emergency firmware update. Three days later a contributor opened pull request #692 against the Coldcard firmware repo, reporting that the hotfix had introduced a new failure on the hardware RNG path.
    +The entropy fix itself is correct: rng_get() now resolves to the board�s true hardware accessor instead of the software fallback. But rng_get_or_fault() had no recovery path for the STM32�s RNG seed error flags. After a seed error the peripheral stops delivering data and the shipped code never clears the condition; so every later call times out and raises OSError(EFAULT) for the rest of that boot. Because rng_get() now sits on the keypad scan path (an interrupt callback that runs before login) that exception lands before the PIN prompt. Power cycling clears the flags; if the error recurs on the next boo: the user is locked out of the upgrade menu too and the device is essentially bricked.
    +The original report overstated the stickiness. The flags do not survive a power cycle: so this is not a permanent brick from a single glitch. It is still a serious regression: an emergency patch for a five-year review failure shipped fast that can take the device down before the user can enter a PIN.
    +#692 was closed in favor of #693, a cleaner recovery sequence from a Coinkite contributor, with #698 as the Mk3 follow-up. Both were still open when this was written. The point is not that nobody noticed. The point is that the first hotfix for a five-year entropy failure needed a second round of patches within days. Giving the attacker MORE TIME to execute sweeping funds from vulnerable wallets.
    +What they�ll say
    +Three objections are coming, and they�re the ones I�d make if I was NVK for sure
    +Galaxy says the waves may not share an operator. True: and irrelevant to the part that matters. Galaxy�s caution is about waves two, three, and four. Once wave one went loud on 30 July the vulnerability was public property and anyone with tooling could pile in. That�s what waves three and four look like. Wave one is the one that tells you something. 1,082 BTC out of 1,195 addresses in 41 minutes with seeds already computed; executed by someone who had been preparing while nobody else on earth knew there was anything to prepare for.
    +The bug was publicly findable: anyone could have found it. Two people found it in public and said so, in 2021 and in 2025. Both were told it was fine. The set of people who knew this was a live question before 30 July is not the general public. It�s a short list and Coinkite was on it.
    +A mass sweep is too loud for an insider. It�s too loud for the rational insider who bleeds quietly over years and never triggers a referral. The loudness cuts against a careful inside job. It does not erase the warnings, the Signal group, or their response that if something was wrong they�d already know.
    +What I think happened
    +Somebody inside that company knew what was sitting in the codebase and knew what it was worth.
    +Look at the timeline:
    +Ten weeks before the bug shipped the CEO publicly waved off the idea that a vendor would ever run a retirement attack and pointed at dice as the alternative. His co-founder and CTO then wrote a crypto library under a pseudonymous GitHub account with about six stars, and shipped the device�s entire randomness path through it.
    +Five weeks later someone flagged the swap in a Coldcard Telegram group and was ignored.
    +Seven months after that the company marketed immunity to the exact attack class the defect enables and made the only reliable defense an �opt in�.
    +Four years in: a Bitcoin developer audited the firmware found the library, named the hardcoded constants, told them to remove the whole thing, and was told they�d already know if something was wrong. They opened a Signal group called �LNGU Clean up,� set the messages to disappear, and shipped nothing. Coins were leaving through 695 transactions nobody noticed. Then somebody who had been precomputing seeds for a long time took 1,082 BTC in 41 minutes.
    +Each of these has an innocent explanation available. All of them stacked in the same direction inside a company of twenty people. This is not a run of bad luck. Inverse Hanlon�s razor exists for exactly this shape: when incompetence needs that many separate coincidences to line up the same way the incentive is the simpler explanation.
    +I can�t say for 100% it was an inside job of course: every document that would definititevly prove it belongs to them. The �LNGU Clean up� thread, whatever survived a four week expiration. Whatever code review they ran and when. The commit history around anyone who touched rng.c after May 2025. Roughly 600 attacker addresses are already in front of federal investigators and Coinkite says it�s cooperating. Cooperation is cheap. Coinkite has apologized, published a postmortem, shipped a fix that needed a second round of patches within days, and offered its customers not a single sat as compensation.
    +The man who found this in May 2025 is publicly apologizing for not pushing harder. And NVK is blaming AI.
    +The people who still have their bitcoins are the ones who read Coldcard�s own documentation, saw the line offering them a way to distrust the manufacturer�s randomness, and took it. Nobody told them that one sentence in the docs was the difference between keeping their money and losing it.
    +Holla atchya boi,
    +-IH
    +https://x.com/inverse_hanlon/status/2084689208627925384
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: kTimesG on August 07, 2026, 10:36:15 AM
    +So here's the real deal, not theoretical blah-blah (which got it wrong):
    +1. The entire attack was already over by Aug 2nd.
    +2. Most likely each wave belonged to a different entity.
    +3. There's most likely a lot of missed mini-waves or whatever (each block that mined TXs of more than 1 separate compromised account are unlikely to belong to same owner).
    +Why I am all but sure about this? I reversed engineer the actual process. The first compromised seed had its initial income address funded on March 18 2021, 19:11:04 GMT. That is exactly one day after v4.0.0 of the firmware was released. All of the accounts that I was able to detect (~ 2050) that still had a balance on Jul. 30 were already sweeped in the last week. That is more than 1200 accounts (more than half of all the compromised seeds) being moved in just the first 48 hours after first wave.
    +Or more practical: 10654 different addresses moved out funds in the last week. Which is a third of all addresses of all accounts.
    +The only thing left are three dust addresses totalling less than 1000 satoshis. Everything else is gone, so that explains why the attackers moved to weak passphrases; there was nothing else left to do. Do not think dice rolls helped, those wallets do exist, and are also gone.
    +I don't think it will be a long time before the security researchers will revise their numbers for the CC actual security bits (it is not even close to 40).
    +Note: this didn't take months of preparation or trillions of scans. It's simply just a catastrophic system failure on the firmware coder's part. The first attacker simply probably didn't bother to dig deeper, while the subsequent ones did.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: vapourminer on August 07, 2026, 10:51:07 AM
    +Quote from: Forsyth Jones on Today at 03:01:28 AM
    +The Coldcard case made it clear, at the very least, that creating a wallet, writing down the seed phrase, depositing some funds, and only opening the wallet 10 years later IS NOT ENOUGH. A strategy for acting during trips is more than necessary.
    +many many decades ago i used to hide things like a PINs and other codes as phone numbers on a piece of paper. like Vivian xxx-xxx-xxxx would have the PIN for my Visa debit card or things along those lines.. door codes etc.
    +back then before smartphones no one looked twice at a phone list. now a printed phone list would probably be sus in itself.
    +now? need to hide 128 bits worth somewhere.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: bitmover on August 07, 2026, 11:41:17 AM
    +Quote from: philipma1957 on Today at 01:53:04 AM
    +I would rather just buy a hardware wallet and add a passphrase.
    +Or you can just flip a coin 256 times and add results to iancoleman.io
    +Dont need to buy anything too fancy
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: sergiorus on August 07, 2026, 11:45:54 AM
    +Coldcard Maker Coinkite Says It Will Publish Post-Mortem, Declines to Estimate Customer Losses
    +Bloomberg reported that Coinkite, the maker of the Coldcard Bitcoin hardware wallet, said it is focused on assisting customers affected by the security incident and will publish a post-mortem once its full investigation is complete, rather than speculate on the scale of customer losses. Coinkite said the privacy-focused design of its products prevents it from independently verifying external estimates of the amount stolen. Recent outside research has raised estimated losses from the attack to roughly $130 million.
    +Source: https://www.bloomberg.com/news/articles/2026-08-06/hacked-bitcoin-wallet-maker-declines-to-estimate-amount-lost
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  11. source content difference between and source content +129 -33

    Three new posts (philipma1957's metal-punch passphrase recipe, Forsyth Jones on travel-time seed strategies, JayJuanGee on setup security) and a one-word typo fix by tvbcof ("bag-fumbers" to "bag-fumblers"). The diff also contains SMF "Today at" relative-date rollover, which is presentation noise.

    seen · Captured here 465,278 chars
    What changed from the previous capture 162 lines
     [I'm not picking on anyone here, this is in fact a repost of a comment I just wrote on reddit.]
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: tvbcof on August 06, 2026, 02:44:38 AM
    -Quote from: gmaxwell on Today at 01:59:15 AM
    +Quote from: gmaxwell on August 06, 2026, 01:59:15 AM
     It would be prudent to remind people here that there are still a lot of vulnerable funds that could be saved and that it would be anti-social to explain how to reduce the search space of coldcard devices just to brag about how smart you are, or show that some rando was wrong on the internet.
     Plenty of other people could be posting about the exact search space needed to enumerate vulnerable seeds and are kindly refraining from doing so. Just because you could figure out that doesn't mean that every would be coin-thief is going to figure it out before the owners sweep their coins.
     [I'm not picking on anyone here, this is in fact a repost of a comment I just wrote on reddit.]
     Maybe you could argue that FTX is more just because the claims were paid out more promptly, and so I am not going to dispute that the forced HODL situation of MTGOX likely created a lot of injustices for those who did not have something like a 10-ish to 13-ish year timeline, to the extent that they had already been paid (maybe around 75% paid), and I am not sure if the still fucking around to pay more claims will end up getting paid, since there is some strangeness in how long it is taking with potential distributions at the end of this year, perhaps?  so yeah, delays are injust, too.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: joker_josue on August 06, 2026, 06:42:59 AM
    -Quote from: tvbcof on Today at 02:44:38 AM
    +Quote from: tvbcof on August 06, 2026, 02:44:38 AM
     I found out about the 'bug', and the initial details of it, when I had about 3 days left in a foreign land.  I had to decide whether to get an emergency ticket home.  My own musings about such optimizations and growth rates had a lot to do with my catching the next plane home rather than waiting.  I'm very glad I did.
     It's vacation time in most countries in the Northern Hemisphere. I believe there are still many people in a similar situation.
     Some people tend to take a few days to be 100% offline, so they may not even be aware of this whole problem yet. They may have already run out of coins and not even know it.
     Fortunately for you, you were aware of the situation and had the ability to return in time (I hope). Many probably weren't so lucky.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: NotATether on August 06, 2026, 07:06:59 AM
    -Quote from: Dave1 on Today at 06:13:09 AM
    +Quote from: Dave1 on August 06, 2026, 06:13:09 AM
     Or this is just for the clickbait and clout about the current incident. But this could be bad crypto media. And if confirmed, this is really a sad story and tragic. The thing is that the one that is going to suffer the most here is that family that is going to be left behind.
     CLICKBAIT until confirmed true by authorities.
     The account on X posting this is just taking screenshots and fabricating news pieces based on his imagination. Very shameful conduct by a so-called "news" account.
     Already requested Community Note for that post so that it doesn't mislead anyone.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: Danish Ali on August 06, 2026, 08:44:38 AM
    -Quote from: joker_josue on Today at 06:42:59 AM
    +Quote from: joker_josue on August 06, 2026, 06:42:59 AM
     It's vacation time in most countries in the Northern Hemisphere. I believe there are still many people in a similar situation.
     Some people tend to take a few days to be 100% offline, so they may not even be aware of this whole problem yet. They may have already run out of coins and not even know it.
     I think that in a week, when many people return from vacation, they will have a sad surprise. More reports will emerge and the numbers will increase.
     https://pbs.twimg.com/media/HO-QEsgWYAEQbGo?format=png&name=small
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: kTimesG on August 06, 2026, 10:23:55 AM
    -Quote from: gmaxwell on Today at 01:59:15 AM
    +Quote from: gmaxwell on August 06, 2026, 01:59:15 AM
     It would be prudent to remind people here that there are still a lot of vulnerable funds that could be saved and that it would be anti-social to explain how to reduce the search space of coldcard devices just to brag about how smart you are, or show that some rando was wrong on the internet.
     My intention was to simply point out that the specific honeypot doesn't reflect real-life conditions.
     It's not a security breach to use the number "42" which was pretended to be some sort of a honey pot of all wallets between 1 and 100 (out of which none was actually ever created)., when in reality there's a jigsaw puzzle hidden in a maze with a billion doors.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: Cookdata on August 06, 2026, 10:28:24 AM
    -Quote from: ryzaadit on Today at 09:03:03 AM
    +Quote from: ryzaadit on August 06, 2026, 09:03:03 AM
     Their device detected the sweeps and both of them are in the race for RBF transaction.
     The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
     There is a similar experimental video about Mk3 but with different objectives, the person created 5 different wallets using Mk3 Coldcard, the first wallet was generated using the insecure random number generator, the same seed phrase was used to generate 3 wallets with different passphrases and the last wallet which is the 5th was generated using the same seed phrase from a random account.
     I have a TREZOR? I am still save?
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: vapourminer on August 06, 2026, 10:56:46 AM
    -Quote from: Bullethead21 on Today at 10:32:39 AM
    +Quote from: Bullethead21 on August 06, 2026, 10:32:39 AM
     I have a TREZOR? I am still save?
     if you used a seed generated on a coldcard, no you are not safe. you need to move funds out.
     otherwise depends on how you generated the seed, but so far other wallets are not affected by the coldcard bug
     I am reluctant to think that a serious news program is capable of making a mistake of such magnitude, and, most likely, the person who has told me about it misunderstood what they said. But, if so, there are many more people who know less about the subject that my friend and who saw the news that must be thinking that something is wrong with Bitcoin.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: stompix on August 06, 2026, 11:12:59 AM
    -Quote from: Dave1 on Today at 06:13:09 AM
    +Quote from: Dave1 on August 06, 2026, 06:13:09 AM
     Not sure if this is true or not,
     https://x.com/News_crypto/status/2084558130239664431
     Or this is just for the clickbait and clout about the current incident. But this could be bad crypto media. And if confirmed, this is really a sad story and tragic. The thing is that the one that is going to suffer the most here is that family that is going to be left behind.
     One guy sends a message and claims to commit suicide, and we already write him dead?
     Also, who uses a tumbler to split move funds 4 times before sending that message to reimburse him to an address with no activity?
     Seriously, lately the ratio of noise to actual info is going down the drain.
    -Quote from: joker_josue on Today at 06:42:59 AM
    +Quote from: joker_josue on August 06, 2026, 06:42:59 AM
     It's vacation time in most countries in the Northern Hemisphere. I believe there are still many people in a similar situation.
     Some people tend to take a few days to be 100% offline, so they may not even be aware of this whole problem yet. They may have already run out of coins and not even know it.
     I doubt they have planned it this way all along but indeed, it came at one of the worst times possible, at least for Christmas or some other holiday a lot of people are home with family, in summer, things are different. I'm sure there are plenty who don't even know what has happened yet.
     https://x.com/DylanLeClair/status/2085074383773581570
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: ultrloa on August 06, 2026, 11:27:59 AM
    -Quote from: vapourminer on Today at 10:56:46 AM
    -Quote from: Bullethead21 on Today at 10:32:39 AM
    +Quote from: vapourminer on August 06, 2026, 10:56:46 AM
    +Quote from: Bullethead21 on August 06, 2026, 10:32:39 AM
     I have a TREZOR? I am still save?
     if you used a seed generated on a coldcard, no you are not safe. you need to move funds out.
     otherwise depends on how you generated the seed, but so far other wallets are not affected by the coldcard bug
     Seems that it didn't get much coverage in mainstream media, though?
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: Danish Ali on August 06, 2026, 01:37:45 PM
    -Quote from: vapourminer on Today at 10:56:46 AM
    -Quote from: Bullethead21 on Today at 10:32:39 AM
    +Quote from: vapourminer on August 06, 2026, 10:56:46 AM
    +Quote from: Bullethead21 on August 06, 2026, 10:32:39 AM
     I have a TREZOR? I am still save?
     if you used a seed generated on a coldcard, no you are not safe. you need to move funds out.
     otherwise depends on how you generated the seed, but so far other wallets are not affected by the coldcard bug
     Exactly, the device brand does not matter here, the seed origin does. Any wallet holding Coldcard generated seed is equally at risk regardless of what hardware it is running on now.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: Stalker22 on August 06, 2026, 02:02:27 PM
    -Quote from: stompix on Today at 11:12:59 AM
    +Quote from: stompix on August 06, 2026, 11:12:59 AM
     I doubt they have planned it this way all along but indeed, it came at one of the worst times possible,
     ~
     I think someone DID plan this carefully.  The first few batched transactions were executed almost simultaneously.  This means someone had to crack all the private keys, find the wallets with the largest balances, prepare and sign all the transactions, and just wait for the right time to execute.
    -Quote from: stompix on Today at 11:12:59 AM
    +Quote from: stompix on August 06, 2026, 11:12:59 AM
     I'm sure there are plenty who don't even know what has happened yet.
     Unfortunately, yes.  Mainstream coverage of this incident has been practically nonexistent, keeping the story confined strictly to the crypto space.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: vapourminer on August 06, 2026, 02:24:29 PM
    -Quote from: Stalker22 on Today at 02:02:27 PM
    +Quote from: Stalker22 on August 06, 2026, 02:02:27 PM
     Mainstream coverage of this incident has been practically nonexistent, keeping the story confined strictly to the crypto space.
     just as well; the public would think its a bitcoin-the-protocol is hacked and create panic. its just one hardware wallets manufacturers idiot programming. not a big deal in the general bitcoin space as a whole.
     not to minimize the absolute suck this whole thing is for victims and thats what they were, victims. not their fault they trusted this thing it was recommended by many here and elsewhere.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: LoyceV on August 06, 2026, 02:29:00 PM
    -Quote from: ryzaadit on Today at 09:03:03 AM
    +Quote from: ryzaadit on August 06, 2026, 09:03:03 AM
     Crazy to see the sweeps just need 10 seconds after the deposit.
     Was that a new hardware wallet with a newly created seed phrase, or a seed phrase that was compromised before?
     If it's the former, that means someone (or multiple entities) are now racing through all ~trillion possible seed phrases to detect any new incoming funds.
     I was curious about that scenario too. That would mean that (eventually) only miners profit from funds sent to addresses with leaked private keys.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: hd49728 on August 06, 2026, 02:41:05 PM
    -Quote from: ryzaadit on Today at 09:03:03 AM
    +Quote from: ryzaadit on August 06, 2026, 09:03:03 AM
     Crazy to see the sweeps just need 10 seconds after the deposit.
     Some social experiment being made by Wesatoshis, who provides a Bitcoin hardware terminal for moving transaction with @Pathfinder to fill his Coldcard MK3 with 10,000 sat for the atacker to take the baits. And indeed..... just need 10 second after the deposit for the atacker trying to take those fund
     Their device detected the sweeps and both of them are in the race for RBF transaction.
     Who knows, it can even be an insider job. That's always the first thought I get when such hacks happen.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: oll on August 06, 2026, 03:09:11 PM
    -Quote from: vapourminer on Today at 02:24:29 PM
    -Quote from: Stalker22 on Today at 02:02:27 PM
    +Quote from: vapourminer on August 06, 2026, 02:24:29 PM
    +Quote from: Stalker22 on August 06, 2026, 02:02:27 PM
     Mainstream coverage of this incident has been practically nonexistent, keeping the story confined strictly to the crypto space.
     just as well; the public would think its a bitcoin-the-protocol is hacked and create panic. its just one hardware wallets manufacturers idiot programming. not a big deal in the general bitcoin space as a whole.
     not to minimize the absolute suck this whole thing is for victims and thats what they were, victims. not their fault they trusted this thing it was recommended by many here and elsewhere.
     https://xcancel.com/callebtc/status/2085024458012586286
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: ryzaadit on August 06, 2026, 05:38:04 PM
    -Quote from: Bullethead21 on Today at 10:32:39 AM
    +Quote from: Bullethead21 on August 06, 2026, 10:32:39 AM
     I have a TREZOR? I am still save?
     https://pbs.twimg.com/media/HO9SYJlW0AAcuuO?format=jpg&name=large
     Best thing to do, add your own entropy my friend. Learn about entropy.
    -Quote from: LoyceV on Today at 02:29:00 PM
    +Quote from: LoyceV on August 06, 2026, 02:29:00 PM
     Was that a new hardware wallet with a newly created seed phrase, or a seed phrase that was compromised before?
     If it's the former, that means someone (or multiple entities) are now racing through all ~trillion possible seed phrases to detect any new incoming funds.
     Unfortunately, it's new.
    -Quote from: pawanjain on Today at 02:44:08 PM
    +Quote from: pawanjain on August 06, 2026, 02:44:08 PM
     At this point, I have stopped trusting these hardware wallets. Are there even any option left for really good hardware wallets?
     Just because of one stupid manufacturer mistake, don't lose your belief in hardware wallets. There are so many good hardware wallets out there.
     People forget some important things, mostly new people. They think that owning a hardware wallet their fund 100% secure, and this is the reason by using hardware wallet removes the feeling of safety, especially for anyone who has not learned more about safety risk.
     - Store your funds not just in one single bucket
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: Meuserna on August 06, 2026, 05:49:25 PM
    -Quote from: ultrloa on Today at 11:27:59 AM
    +Quote from: ultrloa on August 06, 2026, 11:27:59 AM
     I think there's no way for Trezor user to generate seed on Coldcard. So generally he's safe from this exploit.
     Sure there is.
     Generate a seed on a ColdCard. Enter the seed on a Trezor to restore the wallet. The wallet is still in danger because the seed was generated on a ColdCard.
     ColdCard owners are getting robbed because their devices generated predictable seeds. Moving a predictable seed to a Trezor doesn't change the fact that the seed was predictable, so the seed can be found by going through the list of all possible seeds generated by ColdCard's borked code.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: suzanne5223 on August 06, 2026, 07:35:01 PM
    -Quote from: Cookdata on Today at 10:28:24 AM
    -Quote from: ryzaadit on Today at 09:03:03 AM
    +Quote from: Cookdata on August 06, 2026, 10:28:24 AM
    +Quote from: ryzaadit on August 06, 2026, 09:03:03 AM
     Their device detected the sweeps and both of them are in the race for RBF transaction.
     The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
     There is a similar experimental video about Mk3 but with different objectives, the person created 5 different wallets using Mk3 Coldcard, the first wallet was generated using the insecure random number generator, the same seed phrase was used to generate 3 wallets with different passphrases and the last wallet which is the 5th was generated using the same seed phrase from a random account.
     https://x.com/wowens/status/2084041966212591963?s=20
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: OgNasty on August 06, 2026, 07:38:06 PM
    -Quote from: suzanne5223 on Today at 07:35:01 PM
    -Quote from: Cookdata on Today at 10:28:24 AM
    -Quote from: ryzaadit on Today at 09:03:03 AM
    +Quote from: suzanne5223 on August 06, 2026, 07:35:01 PM
    +Quote from: Cookdata on August 06, 2026, 10:28:24 AM
    +Quote from: ryzaadit on August 06, 2026, 09:03:03 AM
     Their device detected the sweeps and both of them are in the race for RBF transaction.
     The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
     There is a similar experimental video about Mk3 but with different objectives, the person created 5 different wallets using Mk3 Coldcard, the first wallet was generated using the insecure random number generator, the same seed phrase was used to generate 3 wallets with different passphrases and the last wallet which is the 5th was generated using the same seed phrase from a random account.
     It isn't like this costs the attacker anything though.  It's also probably an automated process at this point, so most likely the person is just wasting their own time and money.  In this case they probably got some social media fame, followers, and maybe a boost to their X payout.  However, this isn't the huge win it may appear to be if you don't understand how the process works.  Whatever it takes to cope with the pain though.  In the end, laughter is the best medicine.
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: tvbcof on August 06, 2026, 08:57:32 PM
    -Quote from: suzanne5223 on Today at 07:35:01 PM
    +Quote from: suzanne5223 on August 06, 2026, 07:35:01 PM
     ...
     from image:
     imagine compromising someone's hardware wallet and still fumbling the bag
     ...
    -Imagine controlling everyone who used the device's keys, dice or not, and letting a hoard of bag-fumbers fight over the the dice-less dregs for the next few years.
    +Imagine controlling everyone who used the device's keys, dice or not, and letting a hoard of bag-fumblers fight over the the dice-less dregs for the next few years.
     Imagine further, whale keys sitting safely on the blockchain to be harvested as-needed in the coming decades.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: bitmover on August 06, 2026, 10:44:03 PM
    -Quote from: JayJuanGee on Today at 06:28:48 AM
    +Quote from: JayJuanGee on August 06, 2026, 06:28:48 AM
     Personally, I think that the earlier table that was posted by Forsyth Jones is a good guideline for at least shooting for at least minimal levels of safety, especially if we want to shoot to have our levels to at least be in the orange, and probably better to be in the lighter orange rather than the darker orange, just to be safer, yet even if we land in the darker orange, we should not need to panic, even though we might want to consider if we might want to create a wee bit stronger variation and then move our coins to that stronger variation.
     Quote from: Forsyth Jones on August 03, 2026, 11:54:10 PM
     Below is a table showing the strength of each passphrase extension:
     Just create a passphrase you like and can remember. I believe this is the lesson for everyone about this attack/scam
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: fillippone on August 06, 2026, 10:48:48 PM
    -Quote from: Pmalek on Today at 03:35:05 PM
    +Quote from: Pmalek on August 06, 2026, 03:35:05 PM
     Bitcoin Red Team consists of 16 people who are working around the clock now and running security audits on Bitcoin code bases. According to their report, they have already made close to 5,000 findings and discovered what they believe are 85 critical and 635 high severity issues. They report these issues back to project owners and companies, and I think that's a great thing that has come out of this terrible situation. Whitehats and industry experts joining forces to help secure the wider Bitcoin ecosystem.
     https://xcancel.com/callebtc/status/2085024458012586286
     Bitcoin code is safe.
     The code is arguably kept simple just to avoid any hidden bug or negative feature.
     Interacting with this code requires using many more codes: wallets, signing devices, cryptographic libraries, exchanges....
     Those software are not secure, and prone to AI-driven exploit.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: philipma1957 on August 07, 2026, 01:53:04 AM
    +Quote from: bitmover on August 06, 2026, 10:44:03 PM
    +Quote from: JayJuanGee on August 06, 2026, 06:28:48 AM
    +Personally, I think that the earlier table that was posted by Forsyth Jones is a good guideline for at least shooting for at least minimal levels of safety, especially if we want to shoot to have our levels to at least be in the orange, and probably better to be in the lighter orange rather than the darker orange, just to be safer, yet even if we land in the darker orange, we should not need to panic, even though we might want to consider if we might want to create a wee bit stronger variation and then move our coins to that stronger variation.
    +Quote from: Forsyth Jones on August 03, 2026, 11:54:10 PM
    +Below is a table showing the strength of each passphrase extension:
    +https://i.bitlist.co/0IVL5jMzaudl.jpg
    +I think 32 years is secure enough for me  :D
    +But even the 12 years variation of 8 characters are basically invulnerable for any practical purposes.
    +Just create a passphrase you like and can remember. I believe this is the lesson for everyone about this attack/scam
    +buy this
    +https://www.amazon.com/gp/product/B000I2FW2Q/ref=ox_sc_act_title_1?smid=ATVPDKIKX0DER&th=1
    +a set of 36 punches
    +next buy this
    +https://www.amazon.com/gp/product/B0GMH6LGJT/ref=ox_sc_act_title_1?smid=A1MDC9YLETZE7Z&th=1
    +30 washers
    +https://www.amazon.com/gp/product/B0FG2LRFZ2/ref=ox_sc_act_title_1?smid=A1FA0UJGUNVMLI&th=1
    +1/4 nuts and bolts
    +now here comes the important part.
    +go to the punch set and out of all 36 pick 20 letters and number see the photos
    +https://www.talkimg.com/images/2026/08/07/UoigW2.jpg
    +https://www.talkimg.com/images/2026/08/07/Uoi8Cc.jpg
    +I picked those 20 because they are easy to see that they are different from each other
    +so.
    +A B D E F G H J M P
    +R S T V W Y Z 3 4 8
    +PUT THEM IN THIS
    +https://www.talkimg.com/images/2026/08/07/UoiKYP.jpg
    +https://www.talkimg.com/images/2026/08/07/Uoibiq.jpg
    +Move and rotate it a pull a bar out with closed eyes
    +pretend it was the Z    1 in 20 shot.  put it in the mixer rotate flip spin pull new letter or number say 3
    +so Z3 is 1 in 400 put it back again and again
    +pretend YOU do 12 times get the passphrase below
    +Z3B                    1 IN                        8,000
    +Z3BG                   1 IN                    160,000
    +Z3BGP                 1 IN                  3,200,000
    +Z3BGPT               1 IN                64,000,000
    +Z3BGPT8             1 IN                1,280,000,000
    +Z3BGPT8Y           1 IN                25,600,000,000
    +Z3BGPT8YY           1 IN             512,000,000,000
    +Z3BGPT8YYA         1 IN        10,240,000,000,000
    +Z3BGPT8YYA3       1 IN      204,800,000,000,000
    +Z3BGPT8YYA3S     1 IN        4,096,000,000,000,000                12 PULLS OF THE 20 PUNCHES IS       4,096 X 1 TRILLION
    +Z3BGPT8YYA3S4   1 IN       81,920,000,000,000,000               13 PULLS OF THE 20 PUNCHES IS       81,920 X 1 TRILLION
    +Z3BGPT8YYA3S4H   1 IN  1,638,400,000,000,000,000              14 PULLS OF THE 20 PUNCHES IS   1,638,400 X 1 TRILLION
    +Z3BGPT8YYA3S4H8 1 IN 32,768,000,000,000,000,000             15 PULLS OF THE 20 PUNCHES IS  32,768,000 X 1 TRILLION
    +SO A 15 character passphrase is pretty okay it is 65 bits  which is crack able but it is after the seed of 12 or 20 or 24 words
    +a 20 character passphrase built with 20 punches is 85 bits
    +a 24 character passphrase built wit 20 punches is 102 bits.
    +cold card seed at 40 bits is around 1,099,511,627,776 when compared to the 15 character passphrase above
    +15 characters is 32,768,000 harder
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Forsyth Jones on August 07, 2026, 03:01:28 AM
    +Quote from: joker_josue on August 6, 2026, 03:42:59 AM
    +It's vacation time in most countries in the Northern Hemisphere. I believe there are still many people in a similar situation.
    +Some people tend to take a few days to be 100% offline, so they may not even be aware of this whole problem yet. They may have already run out of coins and not even know it.
    +I think that in a week, when many people return from vacation, they will have a sad surprise. More reports will emerge and the numbers will increase.
    +Quote from: pawanjain on August 6, 2026, 11:44:08 AM
    +At this point, I have stopped trusting these hardware wallets. Are there even any option left for really good hardware wallets?
    +What's the point of having one if they can have such bugs which can sweep out millions of funds in such a short time.
    +I know it's not the users fault here but the company has to take the responsibility here for the mess up and ensure their users get their funds back.
    +Who knows, it can even be an insider job. That's always the first thought I get when such hacks happen.
    +Quote from: bitmover on August 6, 2026, 07:44:03 PM
    +I think 32 years is secure enough for me
    +But even the 12 years variation of 8 characters are basically invulnerable for any practical purposes.
    +Just create a passphrase you like and can remember. I believe this is the lesson for everyone about this attack/scam
    +The question is this: imagine you bought a hardware wallet. You depend on the developer's competence, on 3rd parties who review the code for you (if it has an open source license), meanwhilte, the manufactors pursue certification licenses for their devices (usually for secure elements and microcontrollers). The guy chose Coldcard, at this moment, he's enjoying a vacation on some paradise island (little does he know it might be the last time) and has no idea of the sea of disappointment he is about to dive into.
    +A simple act that could SAVE his savings:
    +- Having thought about ways to prevent himself in case of disasters like this, things like: carrying a seed phrase (encrypted, steganographic or not) with him, he could move the funds to a new wallet if he knew about this targeted hack on Coldcard.
    +- He could have added a strong passphrase, but let's say he knows the passphrase by heart, but he doesn't have the seed phrase with him, he needs the both things (remembering that he is on a family trip, visiting the Eiffel Tower, etc), he failed again.
    +- Memorizing the seed phrase and passphrase? You always have to maintain it (doing spaced repetition, keep reminding yourself from time to time so you don't forget, and have them written down somewhere, separately).
    +How would you solve this problem if you had a coldcard and haven't been affected yet? Imagine yourself in his shoes, what would you do? How to solve this problem?
    +The passphrase, you either need to keep it somewhere (geographically far from the seed phrase) or have it memorized. Another way is to keep it discreetly in your agenda (paper) or in your leather wallet.
    +Many people (myself included) own more than one hardware wallet or some form of airgapped storage (even better, as long as you know what you're doing). This would also prevent a lot of problems, since people practically entrusted their lives to it.
    +The Coldcard case made it clear, at the very least, that creating a wallet, writing down the seed phrase, depositing some funds, and only opening the wallet 10 years later IS NOT ENOUGH. A strategy for acting during trips is more than necessary.
    +Quote from: philipma1957 on August 6, 2026, 10:53:04 PMLast edit: Today at 11:24:46 PM by philipma1957
    +buy this
    +https://www.amazon.com/gp/product/B000I2FW2Q/ref=ox_sc_act_title_1?smid=ATVPDKIKX0DER&th=1
    +a set of 36 punches
    +This is also good, as long as it's kept at home, in a safe, on the property, etc. but what about when traveling? What about the risk of someone who knows what this is about seizing it and asking questions in a not-so-friendly way?  ::)
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: JayJuanGee on August 07, 2026, 03:46:15 AM
    +Quote from: bitmover on August 06, 2026, 10:44:03 PM
    +Quote from: JayJuanGee on August 06, 2026, 06:28:48 AM
    +Personally, I think that the earlier table that was posted by Forsyth Jones is a good guideline for at least shooting for at least minimal levels of safety, especially if we want to shoot to have our levels to at least be in the orange, and probably better to be in the lighter orange rather than the darker orange, just to be safer, yet even if we land in the darker orange, we should not need to panic, even though we might want to consider if we might want to create a wee bit stronger variation and then move our coins to that stronger variation.
    +Quote from: Forsyth Jones on August 03, 2026, 11:54:10 PM
    +Below is a table showing the strength of each passphrase extension:
    +https://i.bitlist.co/0IVL5jMzaudl.jpg
    +I think 32 years is secure enough for me  :D
    +But even the 12 years variation of 8 characters are basically invulnerable for any practical purposes.
    +Just create a passphrase you like and can remember. I believe this is the lesson for everyone about this attack/scam
    +For sure, we probably do not want to give away our exact set up, except maybe amongst friends and sometimes even on the internet we have to be a bit careful in terms of describing our own set-up, security or our inclinations of what we believe might be "good enough."
    +I have been warming up more towards the ideas of several members who proclaim that there is quite a bit of value in future-proofing my own chosen set up a bit more, yet I am not going to point out which areas, exactly, in which I might be currently vulnerable - since even with my own set ups, I have variations in their level of security, and some of them I am considering whether to upgrade sooner or later, and it can surely take a long time to upgrade, as we mentioned in another post in which there was a description of maybe doing 50-ish different transfers after the set up had been made.
    +At the same time, we might have our own ways of keeping back up records in regards to what our set-ups might be, so then we might have to update our various back up records too.  It can be difficult (and problematic) to keep too much information in our heads, even if we might think that some of the information is basic, such as the location of each of the pieces of information that might be needed to reconstruct our seed... and then are those pieces of information complete enough or do they include any changes that  we might have had chosen to make.
    +This particular attack had a bit of its own uniqueness in terms of potentially creating a bit of a time-buffer for anyone who had any amount of security beyond the various defaults that were built into Cold Card, and that seemed to be one of the problems with the assumptions around cold card, since they seemed to have so many security features within their device.  Accordingly, there were likely a lot of normies (and even somewhat seemingly sophisticated bitcoiners) presuming that since Cold Card had so many various security options that their default must have had at least had some levels of protection, which that was a "HOLY SHIT!!!!" kind of a revelation to find out that Cold Card's default protections (at such a low level as the random number generator) was so damned vulnerable.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  12. source content difference between and source content +88 -0

    Six new posts: Meuserna explaining that restoring a Coldcard-generated seed on a Trezor stays vulnerable, suzanne5223 and OgNasty on bait-wallet experiments, tvbcof speculating about whale keys harvested later, bitmover on passphrase strength, and fillippone on wallet software being the weak layer.

    seen · Captured here 453,870 chars
    What changed from the previous capture 88 lines
     Post by: Pmalek on August 06, 2026, 03:35:05 PM
     Bitcoin Red Team consists of 16 people who are working around the clock now and running security audits on Bitcoin code bases. According to their report, they have already made close to 5,000 findings and discovered what they believe are 85 critical and 635 high severity issues. They report these issues back to project owners and companies, and I think that's a great thing that has come out of this terrible situation. Whitehats and industry experts joining forces to help secure the wider Bitcoin ecosystem.
     https://xcancel.com/callebtc/status/2085024458012586286
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: ryzaadit on August 06, 2026, 05:38:04 PM
    +Quote from: Bullethead21 on Today at 10:32:39 AM
    +I have a TREZOR? I am still save?
    +https://pbs.twimg.com/media/HO9SYJlW0AAcuuO?format=jpg&name=large
    +Best thing to do, add your own entropy my friend. Learn about entropy.
    +Quote from: LoyceV on Today at 02:29:00 PM
    +Was that a new hardware wallet with a newly created seed phrase, or a seed phrase that was compromised before?
    +If it's the former, that means someone (or multiple entities) are now racing through all ~trillion possible seed phrases to detect any new incoming funds.
    +Unfortunately, it's new.
    +Quote from: pawanjain on Today at 02:44:08 PM
    +At this point, I have stopped trusting these hardware wallets. Are there even any option left for really good hardware wallets?
    +Just because of one stupid manufacturer mistake, don't lose your belief in hardware wallets. There are so many good hardware wallets out there.
    +People forget some important things, mostly new people. They think that owning a hardware wallet their fund 100% secure, and this is the reason by using hardware wallet removes the feeling of safety, especially for anyone who has not learned more about safety risk.
    +Hardware wallets are just one key element; you can add more security risks to your stored system.
    +- Learn entropy
    +- Make your own key
    +- Create a multi-signature transaction
    +- Store your funds not just in one single bucket
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Meuserna on August 06, 2026, 05:49:25 PM
    +Quote from: ultrloa on Today at 11:27:59 AM
    +I think there's no way for Trezor user to generate seed on Coldcard. So generally he's safe from this exploit.
    +Sure there is.
    +Generate a seed on a ColdCard. Enter the seed on a Trezor to restore the wallet. The wallet is still in danger because the seed was generated on a ColdCard.
    +Edited to add a specific example: Let's say somebody has been using a ColdCard since 2022. They heard about ColdCard users getting robbed, so they ran to Best Buy and bought a Trezor. They restored their seed on their new Trezor. "Whew! No more ColdCard. I'm safe!" Nope. Their wallet is still in danger because the seed was originally generated on a ColdCard with borked code that was generating seeds with only limited randomness.
    +Over the past week, I keep seeing posts where people say they moved their seed to a Trezor, thinking they're safe.
    +I wish more Bitcoiners understood: the device is not the wallet. The seed is the wallet, because the seed generates the addresses and keys.
    +ColdCard owners are getting robbed because their devices generated predictable seeds. Moving a predictable seed to a Trezor doesn't change the fact that the seed was predictable, so the seed can be found by going through the list of all possible seeds generated by ColdCard's borked code.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: suzanne5223 on August 06, 2026, 07:35:01 PM
    +Quote from: Cookdata on Today at 10:28:24 AM
    +Quote from: ryzaadit on Today at 09:03:03 AM
    +Their device detected the sweeps and both of them are in the race for RBF transaction.
    +The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
    +There is a similar experimental video about Mk3 but with different objectives, the person created 5 different wallets using Mk3 Coldcard, the first wallet was generated using the insecure random number generator, the same seed phrase was used to generate 3 wallets with different passphrases and the last wallet which is the 5th was generated using the same seed phrase from a random account.
    +http://x.com/ColeTU/status/2085090397223637049
    +He funded the 5 generated addresses from each wallet with 10800 sats each https://mempool.space/tx/f6a0e25dfa9b03f4a45c65cddeebafb0ea50c9b2732febbafd9a7f40ecf7b7da to see which of the wallet is getting sweep first and it turns out that the insecured RNG which is the first wallet was swept immediately, he could have overide it with a new transaction and pay more fees too but his objective is to see how the scammers are moving the coins and if passphrase 1 word, 2 words or 3 are secured enough with an insucure RNG seed phrase.
    +So far, the first wallet is swept, and the sats are sitting in this address: https://mempool.space/address/bc1qunqajps4elc78m8fq7s7nglc6x80j49exheq78
    +The rest of the wallets with the same seed phrase and passphrases are intact, the same wallet with the same seed phrase but a random account is also intact. That means the scammers focus is on default accounts created from Mk3, they don't search all account derivations.
    +I think the idea of using an exposed Coldcard wallet as an experiment to see the reaction of what the attacker will do was something that was first started by this person based on the time and date he purposely left 0.0025 BTC behind as bait. At the same time, he outshone the Coldcard attacker onchain (https://mempool.space/tx/ec64b16edd8bcc0893a721a84dfac9c072b0fd5d8c4c8bbab966ee074bf2e2a6).
    +https://talkimg.com/images/2026/08/06/UogF9g.png
    +https://x.com/wowens/status/2084041966212591963?s=20
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: OgNasty on August 06, 2026, 07:38:06 PM
    +Quote from: suzanne5223 on Today at 07:35:01 PM
    +Quote from: Cookdata on Today at 10:28:24 AM
    +Quote from: ryzaadit on Today at 09:03:03 AM
    +Their device detected the sweeps and both of them are in the race for RBF transaction.
    +The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
    +There is a similar experimental video about Mk3 but with different objectives, the person created 5 different wallets using Mk3 Coldcard, the first wallet was generated using the insecure random number generator, the same seed phrase was used to generate 3 wallets with different passphrases and the last wallet which is the 5th was generated using the same seed phrase from a random account.
    +http://x.com/ColeTU/status/2085090397223637049
    +He funded the 5 generated addresses from each wallet with 10800 sats each https://mempool.space/tx/f6a0e25dfa9b03f4a45c65cddeebafb0ea50c9b2732febbafd9a7f40ecf7b7da to see which of the wallet is getting sweep first and it turns out that the insecured RNG which is the first wallet was swept immediately, he could have overide it with a new transaction and pay more fees too but his objective is to see how the scammers are moving the coins and if passphrase 1 word, 2 words or 3 are secured enough with an insucure RNG seed phrase.
    +So far, the first wallet is swept, and the sats are sitting in this address: https://mempool.space/address/bc1qunqajps4elc78m8fq7s7nglc6x80j49exheq78
    +The rest of the wallets with the same seed phrase and passphrases are intact, the same wallet with the same seed phrase but a random account is also intact. That means the scammers focus is on default accounts created from Mk3, they don't search all account derivations.
    +I think the idea of using an exposed Coldcard wallet as an experiment to see the reaction of what the attacker will do was something that was first started by this person based on the time and date he purposely left 0.0025 BTC behind as bait. At the same time, he outshone the Coldcard attacker onchain (https://mempool.space/tx/ec64b16edd8bcc0893a721a84dfac9c072b0fd5d8c4c8bbab966ee074bf2e2a6).
    +https://talkimg.com/images/2026/08/06/UogF9g.png
    +https://x.com/wowens/status/2084041966212591963?s=20
    +It isn't like this costs the attacker anything though.  It's also probably an automated process at this point, so most likely the person is just wasting their own time and money.  In this case they probably got some social media fame, followers, and maybe a boost to their X payout.  However, this isn't the huge win it may appear to be if you don't understand how the process works.  Whatever it takes to cope with the pain though.  In the end, laughter is the best medicine.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: tvbcof on August 06, 2026, 08:57:32 PM
    +Quote from: suzanne5223 on Today at 07:35:01 PM
    +...
    +from image:
    +imagine compromising someone's hardware wallet and still fumbling the bag
    +...
    +Imagine controlling everyone who used the device's keys, dice or not, and letting a hoard of bag-fumbers fight over the the dice-less dregs for the next few years.
    +Imagine further, whale keys sitting safely on the blockchain to be harvested as-needed in the coming decades.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: bitmover on August 06, 2026, 10:44:03 PM
    +Quote from: JayJuanGee on Today at 06:28:48 AM
    +Personally, I think that the earlier table that was posted by Forsyth Jones is a good guideline for at least shooting for at least minimal levels of safety, especially if we want to shoot to have our levels to at least be in the orange, and probably better to be in the lighter orange rather than the darker orange, just to be safer, yet even if we land in the darker orange, we should not need to panic, even though we might want to consider if we might want to create a wee bit stronger variation and then move our coins to that stronger variation.
    +Quote from: Forsyth Jones on August 03, 2026, 11:54:10 PM
    +Below is a table showing the strength of each passphrase extension:
    +https://i.bitlist.co/0IVL5jMzaudl.jpg
    +I think 32 years is secure enough for me  :D
    +But even the 12 years variation of 8 characters are basically invulnerable for any practical purposes.
    +Just create a passphrase you like and can remember. I believe this is the lesson for everyone about this attack/scam
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: fillippone on August 06, 2026, 10:48:48 PM
    +Quote from: Pmalek on Today at 03:35:05 PM
    +Bitcoin Red Team consists of 16 people who are working around the clock now and running security audits on Bitcoin code bases. According to their report, they have already made close to 5,000 findings and discovered what they believe are 85 critical and 635 high severity issues. They report these issues back to project owners and companies, and I think that's a great thing that has come out of this terrible situation. Whitehats and industry experts joining forces to help secure the wider Bitcoin ecosystem.
    +https://xcancel.com/callebtc/status/2085024458012586286
    +Bitcoin code is safe.
    +The most audited code in the world has been under constant scrutiny by the best minds since 16 years.
    +The code is arguably kept simple just to avoid any hidden bug or negative feature.
    +Interacting with this code requires using many more codes: wallets, signing devices, cryptographic libraries, exchanges....
    +Those software are not secure, and prone to AI-driven exploit.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  13. source content difference between and source content +145 -0

    Roughly fifteen new posts: kTimesG and Cookdata on honeypot experiments with Mk3 wallets, Trezor safety questions, an "inside job" shower thought citing a gist about the Coinkite CTO, a Counterparty NOTSOCOLD asset, and Pmalek reporting Bitcoin Red Team's 5,000 audit findings.

    seen · Captured here 442,996 chars
    What changed from the previous capture 145 lines
     The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
     Quote from: @Pathfinder
     https://pbs.twimg.com/media/HO-QEsgWYAEQbGo?format=png&name=small
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: kTimesG on August 06, 2026, 10:23:55 AM
    +Quote from: gmaxwell on Today at 01:59:15 AM
    +It would be prudent to remind people here that there are still a lot of vulnerable funds that could be saved and that it would be anti-social to explain how to reduce the search space of coldcard devices just to brag about how smart you are, or show that some rando was wrong on the internet.
    +My intention was to simply point out that the specific honeypot doesn't reflect real-life conditions.
    +It's not a security breach to use the number "42" which was pretended to be some sort of a honey pot of all wallets between 1 and 100 (out of which none was actually ever created)., when in reality there's a jigsaw puzzle hidden in a maze with a billion doors.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Cookdata on August 06, 2026, 10:28:24 AM
    +Quote from: ryzaadit on Today at 09:03:03 AM
    +Their device detected the sweeps and both of them are in the race for RBF transaction.
    +The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
    +There is a similar experimental video about Mk3 but with different objectives, the person created 5 different wallets using Mk3 Coldcard, the first wallet was generated using the insecure random number generator, the same seed phrase was used to generate 3 wallets with different passphrases and the last wallet which is the 5th was generated using the same seed phrase from a random account.
    +https://talkimg.com/images/2026/08/06/Uo9QgT.png
    +http://x.com/ColeTU/status/2085090397223637049
    +He funded the 5 generated addresses from each wallet with 10800 sats each https://mempool.space/tx/f6a0e25dfa9b03f4a45c65cddeebafb0ea50c9b2732febbafd9a7f40ecf7b7da to see which of the wallet is getting sweep first and it turns out that the insecured RNG which is the first wallet was swept immediately, he could have overide it with a new transaction and pay more fees too but his objective is to see how the scammers are moving the coins and if passphrase 1 word, 2 words or 3 are secured enough with an insucure RNG seed phrase.
    +So far, the first wallet is swept, and the sats are sitting in this address: https://mempool.space/address/bc1qunqajps4elc78m8fq7s7nglc6x80j49exheq78
    +The rest of the wallets with the same seed phrase and passphrases are intact, the same wallet with the same seed phrase but a random account is also intact. That means the scammers focus is on default accounts created from Mk3, they don't search all account derivations.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Bullethead21 on August 06, 2026, 10:32:39 AM
    +I have a TREZOR? I am still save?
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: vapourminer on August 06, 2026, 10:56:46 AM
    +Quote from: Bullethead21 on Today at 10:32:39 AM
    +I have a TREZOR? I am still save?
    +if you used a seed generated on a coldcard, no you are not safe. you need to move funds out.
    +otherwise depends on how you generated the seed, but so far other wallets are not affected by the coldcard bug
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Filicius on August 06, 2026, 11:07:53 AM
    +It's incredible: although I didn't see it, apparently yesterday in the local news they commented on this issue, but when a friend of mine who was able to see it told me about this news it seems that they confused it with a Bitcoin base problem and not with something related to a specific device.
    +I am reluctant to think that a serious news program is capable of making a mistake of such magnitude, and, most likely, the person who has told me about it misunderstood what they said. But, if so, there are many more people who know less about the subject that my friend and who saw the news that must be thinking that something is wrong with Bitcoin.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: stompix on August 06, 2026, 11:12:59 AM
    +Quote from: Dave1 on Today at 06:13:09 AM
    +Not sure if this is true or not,
    +https://x.com/News_crypto/status/2084558130239664431
    +Or this is just for the clickbait and clout about the current incident. But this could be bad crypto media. And if confirmed, this is really a sad story and tragic. The thing is that the one that is going to suffer the most here is that family that is going to be left behind.
    +One guy sends a message and claims to commit suicide, and we already write him dead?
    +Also, who uses a tumbler to split move funds 4 times before sending that message to reimburse him to an address with no activity?
    +Seriously, lately the ratio of noise to actual info is going down the drain.
    +Quote from: joker_josue on Today at 06:42:59 AM
    +It's vacation time in most countries in the Northern Hemisphere. I believe there are still many people in a similar situation.
    +Some people tend to take a few days to be 100% offline, so they may not even be aware of this whole problem yet. They may have already run out of coins and not even know it.
    +I doubt they have planned it this way all along but indeed, it came at one of the worst times possible, at least for Christmas or some other holiday a lot of people are home with family, in summer, things are different. I'm sure there are plenty who don't even know what has happened yet.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Wind_FURY on August 06, 2026, 11:22:11 AM
    +Quote from: decodx on August 05, 2026, 06:56:46 AM
    +Quote from: Wind_FURY on August 05, 2026, 06:40:55 AM
    +Quote from: LoyceV on August 04, 2026, 01:03:42 PM
    +Quote from: Wind_FURY on August 04, 2026, 10:58:59 AM
    +The community in general is still "lucky" that the stupidity came from the ColdCard developers.
    +This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
    +The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.
    +But for the truly paranoid, install Bitcoin Core/Electrum in a computer that will NEVER connect to the internet FOREVER, and generate your keys/seed phrase there. Write it down, then keep it in a safe place. The same for the computer, keep it locked in a vault.
    +Keep sending Bitcoin to that address.
    +To be honest, I don't think this is a good solution for the truly paranoid (or even for the mildly paranoid).   You've just switched from using hardware wallets over to Electrum as your preferred solution.
    +What if there was some vulnerability exposed within the Electrum development? It really wouldn't make that much difference to the final outcome.
    +Read my post again. I believe you didn't understand that it's one of the original solutions for cold-storage before hardware wallets were invented. PLUS Electrum is one of the truly tested wallets in the Bitcoin ecosystem.
    +It's not a debate. It's a FACT.
    +8)
    +Shower thought. The ColdCard situation might be an inside job.
    +Quote
    +Coinkite CTO having a conversation with himself using a pseudonym.
    +https://gist.github.com/dylanleclair1/67d160af313be59851b88d1a81f0d762
    +https://cdn.imgchest.com/files/657ae8dc2b95.jpeg
    +https://x.com/DylanLeClair/status/2085074383773581570
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: ultrloa on August 06, 2026, 11:27:59 AM
    +Quote from: vapourminer on Today at 10:56:46 AM
    +Quote from: Bullethead21 on Today at 10:32:39 AM
    +I have a TREZOR? I am still save?
    +if you used a seed generated on a coldcard, no you are not safe. you need to move funds out.
    +otherwise depends on how you generated the seed, but so far other wallets are not affected by the coldcard bug
    +Right, because those vulnerability on happens on created seeds on those compromised old coldcard firmware and this is not affect the seeds of other devices.
    +But I think there's no way for Trezor user to generate seed on Coldcard. So generally he's safe from this exploit.
    +So those seed generated by like Ledger, Seedsigner and other wallets is not affected on the exploit happened on Coldcard.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: RoxxR on August 06, 2026, 11:36:09 AM
    +Lol now there's a Counterparty asset about this story.
    +https://xcp.io/asset/NOTSOCOLD
    +https://cdn.xcp.io/img/full/NOTSOCOLD
    +Seems that it didn't get much coverage in mainstream media, though?
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Danish Ali on August 06, 2026, 01:37:45 PM
    +Quote from: vapourminer on Today at 10:56:46 AM
    +Quote from: Bullethead21 on Today at 10:32:39 AM
    +I have a TREZOR? I am still save?
    +if you used a seed generated on a coldcard, no you are not safe. you need to move funds out.
    +otherwise depends on how you generated the seed, but so far other wallets are not affected by the coldcard bug
    +Exactly, the device brand does not matter here, the seed origin does. Any wallet holding Coldcard generated seed is equally at risk regardless of what hardware it is running on now.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Stalker22 on August 06, 2026, 02:02:27 PM
    +Quote from: stompix on Today at 11:12:59 AM
    +I doubt they have planned it this way all along but indeed, it came at one of the worst times possible,
    +~
    +I think someone DID plan this carefully.  The first few batched transactions were executed almost simultaneously.  This means someone had to crack all the private keys, find the wallets with the largest balances, prepare and sign all the transactions, and just wait for the right time to execute.
    +Quote from: stompix on Today at 11:12:59 AM
    +I'm sure there are plenty who don't even know what has happened yet.
    +Unfortunately, yes.  Mainstream coverage of this incident has been practically nonexistent, keeping the story confined strictly to the crypto space.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: vapourminer on August 06, 2026, 02:24:29 PM
    +Quote from: Stalker22 on Today at 02:02:27 PM
    +Mainstream coverage of this incident has been practically nonexistent, keeping the story confined strictly to the crypto space.
    +just as well; the public would think its a bitcoin-the-protocol is hacked and create panic. its just one hardware wallets manufacturers idiot programming. not a big deal in the general bitcoin space as a whole.
    +not to minimize the absolute suck this whole thing is for victims and thats what they were, victims. not their fault they trusted this thing it was recommended by many here and elsewhere.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: LoyceV on August 06, 2026, 02:29:00 PM
    +Quote from: ryzaadit on Today at 09:03:03 AM
    +Crazy to see the sweeps just need 10 seconds after the deposit.
    +Was that a new hardware wallet with a newly created seed phrase, or a seed phrase that was compromised before?
    +If it's the former, that means someone (or multiple entities) are now racing through all ~trillion possible seed phrases to detect any new incoming funds.
    +Quote
    +losing 90% of the fund on miners fees.
    +RBF is a bitch for thiefs:
    +Quote from: LoyceV on February 20, 2023, 10:51:12 AM
    +Quote from: o_e_l_e_o on February 20, 2023, 10:40:02 AM
    +Things will get quite interesting once full RBF becomes commonplace. Any such transaction stealing coins from a brain wallet or leaked private key could be replaced by another transaction, regardless of whether or not is opted in to RBF or not. We could end up seeing different bots broadcasting more and more replacements, each paying a higher and higher fee, trying to steal the coins for themselves. Since there is no incentive for any one such bot to surrender and let another bot win, then such transactions could just escalate until the entire value (or close to it) is paid in fees.
    +I was curious about that scenario too. That would mean that (eventually) only miners profit from funds sent to addresses with leaked private keys.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: hd49728 on August 06, 2026, 02:41:05 PM
    +Quote from: ryzaadit on Today at 09:03:03 AM
    +Crazy to see the sweeps just need 10 seconds after the deposit.
    +Some social experiment being made by Wesatoshis, who provides a Bitcoin hardware terminal for moving transaction with @Pathfinder to fill his Coldcard MK3 with 10,000 sat for the atacker to take the baits. And indeed..... just need 10 second after the deposit for the atacker trying to take those fund
    +Their device detected the sweeps and both of them are in the race for RBF transaction.
    +The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
    +It's interesting information to see how attackers do their jobs but I don't see attackers losing anything here. They already stole a lot of money with about 1,500 bitcoins so far, and even in this sweep transaction, they did not lose 9,000 satoshi but actually got 1,000 satoshi. Because every satoshi is worth something now and will be worth more in the future.
    +https://charts.bitbo.io/satoshi-per-dollar/
    +With this test, it shows the attackers use bots to do their jobs but it's not strange because attackers will not move funds manually. They need to sweep fund immediately and as fastest as possible while manual processing it is not helpful.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: pawanjain on August 06, 2026, 02:44:08 PM
    +At this point, I have stopped trusting these hardware wallets. Are there even any option left for really good hardware wallets?
    +What's the point of having one if they can have such bugs which can sweep out millions of funds in such a short time.
    +I know it's not the users fault here but the company has to take the responsibility here for the mess up and ensure their users get their funds back.
    +Who knows, it can even be an insider job. That's always the first thought I get when such hacks happen.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: oll on August 06, 2026, 03:09:11 PM
    +Quote from: vapourminer on Today at 02:24:29 PM
    +Quote from: Stalker22 on Today at 02:02:27 PM
    +Mainstream coverage of this incident has been practically nonexistent, keeping the story confined strictly to the crypto space.
    +just as well; the public would think its a bitcoin-the-protocol is hacked and create panic. its just one hardware wallets manufacturers idiot programming. not a big deal in the general bitcoin space as a whole.
    +not to minimize the absolute suck this whole thing is for victims and thats what they were, victims. not their fault they trusted this thing it was recommended by many here and elsewhere.
    +That's right, because for the general public, bitcoin and blockchain are not amazing technologies, but a "speculative asset" that some of them bought for 120k in euphoria, someone got burned earlier, and someone regrets that he did not buy 100 bucks and carries this fomo through the years. And all this mass of people will happily leave toxic comments without even delving into the topic of the ColdCard issue. This is how the mass psychology of people works: they need to justify their greed and laziness by preserving their own picture of the world. Which is distorted, and so does not want to change. And over the years, this static only increases. And it would seem that a crypto enthusiast can easily help this person, but in the end it will be he who will be the first to be blamed for the investment troubles of such people.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Pmalek on August 06, 2026, 03:35:05 PM
    +Bitcoin Red Team consists of 16 people who are working around the clock now and running security audits on Bitcoin code bases. According to their report, they have already made close to 5,000 findings and discovered what they believe are 85 critical and 635 high severity issues. They report these issues back to project owners and companies, and I think that's a great thing that has come out of this terrible situation. Whitehats and industry experts joining forces to help secure the wider Bitcoin ecosystem.
    +https://xcancel.com/callebtc/status/2085024458012586286
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  14. source content difference between and source content +83 -4

    Six new posts (Dave1 flagging an unconfirmed suicide claim, passphrase-strength discussion, joker_josue and Danish Ali on vacationing users unaware of losses, ryzaadit on a bait-wallet sweep losing the RBF race) plus an edit to a tvbcof post rewording a sentence about sources overstating search-space metrics.

    seen · Captured here 426,543 chars
    What changed from the previous capture 87 lines
     Plenty of other people could be posting about the exact search space needed to enumerate vulnerable seeds and are kindly refraining from doing so. Just because you could figure out that doesn't mean that every would be coin-thief is going to figure it out before the owners sweep their coins.
     [I'm not picking on anyone here, this is in fact a repost of a comment I just wrote on reddit.]
     Not so sure, Greg.
    -I found out about the 'bug', and the initial details of it, when I had about 3 days left in a foreign land.  I had to decide whether to get an emergency ticket home.  My own musings about such optimizations and growth rates had a lot to do with my catching the next plane home rather than waiting.  I'm very glad I did.
    -I would question the potential for someone who didn't think of some of the optimizations to implement them triggered by general chatter.  Even if they did, they would likely be highly out-competed by sharper minds or groups of minds.  No pun on 'mines' intended.
    -At the end of the day, I almost always tend to lean toward full, accurate, and truthful information availability as a general principle.  Not always, but usually all else being marginally close to equal.
    -Actually one could be mildly suspicious about information which circulate information which drastically overstates some of the metrics such as search space.
    +I found out about the 'bug', and the initial details of it, when I had about 3 days left in a foreign land.  I had to decide whether to get an emergency ticket home.  My own musings about such optimizations and growth rates had a lot to do with my catching the next plane home rather than waiting.  I'm very glad I did.
    +I would question the potential for someone who didn't think of some of the optimizations to implement them triggered by general chatter.  Even if they did, they would likely be highly out-competed by sharper minds or groups of minds.  No pun on 'mines' intended.
    +At the end of the day, I almost always tend to lean toward full, accurate, and truthful information availability as a general principle.  Not always, but usually all else being marginally close to equal.
    +Actually one could be mildly suspicious about sources which circulate information that drastically overstates some of the metrics such as search space.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Dave1 on August 06, 2026, 06:13:09 AM
    +Not sure if this is true or not,
    +https://www.talkimg.com/images/2026/08/06/Uo7YJN.png
    +https://x.com/News_crypto/status/2084558130239664431
    +Or this is just for the clickbait and clout about the current incident. But this could be bad crypto media. And if confirmed, this is really a sad story and tragic. The thing is that the one that is going to suffer the most here is that family that is going to be left behind.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Somegory on August 06, 2026, 06:24:17 AM
    +Quote from: Cookdata on August 05, 2026, 04:10:09 PM
    +Quote from: Catenaccio on August 05, 2026, 02:32:43 PM
    +Quote from: philipma1957 on August 03, 2026, 04:45:13 PM
    +My advice is have a few setups and add strong passphrases
    +I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?
    +If a scammer get access to your seed phrase and scan the wallet and see nothing on the wallet, they are not going to walk away immediately, they will try to guess right some common possible words which they know you might use as extension of your seed phrase. They are going to test words like your name, your child name or common strings you use for password, all of these are weak passphrase that scammer can guess right especially if the person knows much about you in detail. You should learn to use words that are uncommon that you can remember any time.
    +Quote
    +It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.
    +I think that's because seed phrase that is generated with a secured entropy is safe for your Bitcoin that's why emphasis are not given to passphrase and some recommendations but it's something you can do. If not for Coldcard negligence, most people don't use passphrase unless they want to use it. Look at numbers of wallet that were swept, it shows most didn't use passphrase else the attacker wouldn't be able to access them.
    +Are you saying that someone can stumble on my seed phrase online, maybe through leaking or maybe I use my hands to insert it online and the next is they will know my child's name or my mother's name?
    +Good luck with that on their end, also who would be stupid enough to use just name? Why not osamabinladen#�+()!//@;*�;@;'snhagunna? Good luck on their end, there is no way they will have access to a passphrase unless they found it through the keeper.
    +Maybe the owner store them carelessness, in the same way that caused the seed phrases to get exposed in the first place, even a single - can make a huge difference.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: JayJuanGee on August 06, 2026, 06:28:48 AM
    +Quote from: Catenaccio on August 05, 2026, 02:32:43 PM
    +Quote from: philipma1957 on August 03, 2026, 04:45:13 PM
    +My advice is have a few setups and add strong passphrases
    +I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?
    +It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.
    +Like how many words are considered as strong enough for a wallet passphrase?
    +No recommendation about that in Mastering Bitcoin book.
    +https://github.com/bitcoinbook/bitcoinbook/blob/develop/ch05_wallets.adoc#optional-passphrase-in-bip39
    +Personally, I think that the earlier table that was posted by Forsyth Jones is a good guideline for at least shooting for at least minimal levels of safety, especially if we want to shoot to have our levels to at least be in the orange, and probably better to be in the lighter orange rather than the darker orange, just to be safer, yet even if we land in the darker orange, we should not need to panic, even though we might want to consider if we might want to create a wee bit stronger variation and then move our coins to that stronger variation.
    +Quote from: Forsyth Jones on August 03, 2026, 11:54:10 PM
    +Below is a table showing the strength of each passphrase extension:
    +https://i.bitlist.co/0IVL5jMzaudl.jpg
    +Quote from: jayhex on August 05, 2026, 03:36:14 PM
    +Quote
    +you jest but at least mtgox people got ~20% of their btc/bcash back
    +Quote
    +Yep and a long solid hodl so good they made nice money in fiat terms.
    +incorrect
    +i think just like FTX they got 20% of the price at the time of theft. so no hodl, just 20% of what u lost at that time 5-6 or more years ago
    +You are guessing, and you are providing skewedly wrong information because you guess wrong and you act like you know what you are talking about, when you don't.
    +MTGOX got around 20% of the number of coins that they had at the time of the shutdown (which is "in-kind" redemption), and I think around 75% of the claims (or the total value had been paid so far) - yeah 10 years later, which is a bit of an injustice in itself.
    +FTX got something around 20% of the cash value at the time of the filing, when the BTC price was then around $19.5k... So they were not the same, and the FTX folks got reimbursed even worse since their bitcoin claims were liquidated into dollars and they got 20% of the dollar value and the BTC price was up around 3x (close to $60k) when they got paid those dollars.
    +Maybe you could argue that FTX is more just because the claims were paid out more promptly, and so I am not going to dispute that the forced HODL situation of MTGOX likely created a lot of injustices for those who did not have something like a 10-ish to 13-ish year timeline, to the extent that they had already been paid (maybe around 75% paid), and I am not sure if the still fucking around to pay more claims will end up getting paid, since there is some strangeness in how long it is taking with potential distributions at the end of this year, perhaps?  so yeah, delays are injust, too.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: joker_josue on August 06, 2026, 06:42:59 AM
    +Quote from: tvbcof on Today at 02:44:38 AM
    +I found out about the 'bug', and the initial details of it, when I had about 3 days left in a foreign land.  I had to decide whether to get an emergency ticket home.  My own musings about such optimizations and growth rates had a lot to do with my catching the next plane home rather than waiting.  I'm very glad I did.
    +It's vacation time in most countries in the Northern Hemisphere. I believe there are still many people in a similar situation.
    +Some people tend to take a few days to be 100% offline, so they may not even be aware of this whole problem yet. They may have already run out of coins and not even know it.
    +I think that in a week, when many people return from vacation, they will have a sad surprise. More reports will emerge and the numbers will increase.
    +Fortunately for you, you were aware of the situation and had the ability to return in time (I hope). Many probably weren't so lucky.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: NotATether on August 06, 2026, 07:06:59 AM
    +Quote from: Dave1 on Today at 06:13:09 AM
    +Or this is just for the clickbait and clout about the current incident. But this could be bad crypto media. And if confirmed, this is really a sad story and tragic. The thing is that the one that is going to suffer the most here is that family that is going to be left behind.
    +CLICKBAIT until confirmed true by authorities.
    +The account on X posting this is just taking screenshots and fabricating news pieces based on his imagination. Very shameful conduct by a so-called "news" account.
    +Already requested Community Note for that post so that it doesn't mislead anyone.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Danish Ali on August 06, 2026, 08:44:38 AM
    +Quote from: joker_josue on Today at 06:42:59 AM
    +It's vacation time in most countries in the Northern Hemisphere. I believe there are still many people in a similar situation.
    +Some people tend to take a few days to be 100% offline, so they may not even be aware of this whole problem yet. They may have already run out of coins and not even know it.
    +I think that in a week, when many people return from vacation, they will have a sad surprise. More reports will emerge and the numbers will increase.
    +Fortunately for you, you were aware of the situation and had the ability to return in time (I hope). Many probably weren't so lucky.
    +It is very serious statement. Losses are well over $130 million and the attack continues, people coming back from vacation are not just walking into bad news, they could be walking into active losses.
    +Probably the most important thing offline users need to know first is that wallets created using the dice-roll option are safe. All else can wait.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: ryzaadit on August 06, 2026, 09:03:03 AM
    +Crazy to see the sweeps just need 10 seconds after the deposit.
    +https://www.talkimg.com/images/2026/08/06/Uo7lZj.png
    +https://x.com/we_satoshis/status/2085034468935450918
    +Some social experiment being made by Wesatoshis, who provides a Bitcoin hardware terminal for moving transaction with @Pathfinder to fill his Coldcard MK3 with 10,000 sat for the atacker to take the baits. And indeed..... just need 10 second after the deposit for the atacker trying to take those fund
    +Their device detected the sweeps and both of them are in the race for RBF transaction.
    +The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
    +Quote from: @Pathfinder
    +https://pbs.twimg.com/media/HO-QEsgWYAEQbGo?format=png&name=small
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  15. source content difference between and source content +45 -12

    The thread gained several replies about alternate wallet designs, a honeypot-monitor estimate, and whether publishing search-space details could endanger vulnerable funds. Relative quote dates also resolved to August 5 dates.

    seen · Captured here 416,556 chars
    What changed from the previous capture 57 lines
     I'd get in trouble if I drilled through the patio concrete for this purpose.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: decodx on August 05, 2026, 06:56:46 AM
    -Quote from: Wind_FURY on Today at 06:40:55 AM
    +Quote from: Wind_FURY on August 05, 2026, 06:40:55 AM
     Quote from: LoyceV on August 04, 2026, 01:03:42 PM
     Quote from: Wind_FURY on August 04, 2026, 10:58:59 AM
     The community in general is still "lucky" that the stupidity came from the ColdCard developers.
     Unfortunately, there is a misconception in our psychology that if something has worked for a long time before us, then we consider it proven, although it may not be so. Every new incoming user thinks, "if everyone is using it so calmly, then someone has checked everything for sure." But it turns out that the system has not been properly tested in five years. And in the age of AI, we will hear more than once about the secrets of systems that were in plain sight, but only the latest AI model will be able to find it.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: LoyceV on August 05, 2026, 09:05:29 AM
    -Quote from: Wind_FURY on Today at 06:40:55 AM
    +Quote from: Wind_FURY on August 05, 2026, 06:40:55 AM
     But for the truly paranoid, install Bitcoin Core/Electrum in a computer that will NEVER connect to the internet FOREVER, and generate your keys/seed phrase there. Write it down, then keep it in a safe place. The same for the computer, keep it locked in a vault.
     Keep sending Bitcoin to that address.
     First, using only one address is terrible for privacy, but also requires exposing all funds if you want to send a transaciton in the future.
     As one of the biggest blockchain security firm has seen some movement already. So it's going to be a cat and mouse game moving forward and trail where it will go.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: examplens on August 05, 2026, 10:49:36 AM
    -Quote from: Dave1 on Today at 09:31:41 AM
    +Quote from: Dave1 on August 05, 2026, 09:31:41 AM
     Let the games begin,
     Here are the first Bitcoin transfers from the address bc1q0rvn88w08j75k4h48lf9fvhan7unjp7vjf5q6m, 64 BTC was sent. According to the further flow of transactions, it seems that it is a matter of mixing through the coinjoin method
     https://mempool.space/tx/e3274a1b87096938d014e1edaa01b06c3dd16e72a48f66ead95c79f83f2b3ddf
     https://mempool.space/tx/80f11c778a2f486ffc55b4e8665a94971ae9c350ac53969e9efcbf90478cbf90
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: tvbcof on August 05, 2026, 12:32:46 PM
    -Quote from: DanWalker on Today at 12:34:00 AM
    +Quote from: DanWalker on August 05, 2026, 12:34:00 AM
     Quote from: Cookdata on August 04, 2026, 01:49:35 PM
     I have seen some creepy tweets of old posts from Coldcard but I don't think this company is worth defending.
     https://talkimg.com/images/2026/08/04/UoJbgc.jpeg
     Yeah let's say Quadriga instead...for pants pooping consistency's sake
     Title: Re: Large-scale Coldcard compromise (1128.47 BTC stolen so far)
     Post by: bitmover on August 05, 2026, 02:08:22 PM
    -Quote from: JayJuanGee on Today at 04:59:37 AM
    +Quote from: JayJuanGee on August 05, 2026, 04:59:37 AM
     Quote from: bitmover on August 03, 2026, 05:02:19 PM
     Quote from: philipma1957 on August 03, 2026, 04:45:13 PM
     My advice is have a few setups and add strong passphrases
     MARA's Slipstream feature eliminates this window of vulnerability. Because the transaction never reaches the public mempool, the attacker sees neither the keys nor the spending details until MARA mines the coins in a confirmed block.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: hosemary on August 05, 2026, 03:55:15 PM
    -Quote from: Catenaccio on Today at 02:32:43 PM
    +Quote from: Catenaccio on August 05, 2026, 02:32:43 PM
     It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.
     When it comes to the amount of entropy and the probability of being cracked, I don't see any difference between a passphrase and a password.
     It's simple. The more random characters you add to your passphrase, the higher entropy it provides.
     For example, if your passphrase contains 10 random printable ASCII characters, there are 9510 possible combinations, which provide around 65.7 bits of entropy.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: Cookdata on August 05, 2026, 04:10:09 PM
    -Quote from: Catenaccio on Today at 02:32:43 PM
    +Quote from: Catenaccio on August 05, 2026, 02:32:43 PM
     Quote from: philipma1957 on August 03, 2026, 04:45:13 PM
     My advice is have a few setups and add strong passphrases
     I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?
     I think that's because seed phrase that is generated with a secured entropy is safe for your Bitcoin that's why emphasis are not given to passphrase and some recommendations but it's something you can do. If not for Coldcard negligence, most people don't use passphrase unless they want to use it. Look at numbers of wallet that were swept, it shows most didn't use passphrase else the attacker wouldn't be able to access them.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: Princess Leah on August 05, 2026, 04:53:08 PM
    -Quote from: Cookdata on Today at 04:10:09 PM
    -Quote from: Catenaccio on Today at 02:32:43 PM
    +Quote from: Cookdata on August 05, 2026, 04:10:09 PM
    +Quote from: Catenaccio on August 05, 2026, 02:32:43 PM
     I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?
     If a scammer get access to your seed phrase and scan the wallet and see nothing on the wallet, they are not going to walk away immediately, they will try to guess right some common possible words which they know you might use as extension of your seed phrase. They are going to test words like your name, your child name or common strings you use for password, all of these are weak passphrase that scammer can guess right especially if the person knows much about you in detail. You should learn to use words that are uncommon that you can remember any time.
     Quote
     Noticed how the characters contains upper and lowercase alphabets, that's to add extra strength to it and make it tough to decoded. People would begin to see the importance of adding extra security to their wallets by including a passphrase, those who did that to their wallets and also used multi sig wallets would be secured from hack.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: philipma1957 on August 05, 2026, 06:05:01 PM
    -Quote from: Catenaccio on Today at 02:32:43 PM
    +Quote from: Catenaccio on August 05, 2026, 02:32:43 PM
     Quote from: philipma1957 on August 03, 2026, 04:45:13 PM
     My advice is have a few setups and add strong passphrases
     I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?
     so this would be 30 million times harder to hit than the hack and you also have a seed in front of of it.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: Meuserna on August 05, 2026, 06:17:30 PM
    -Quote from: Catenaccio on Today at 02:32:43 PM
    +Quote from: Catenaccio on August 05, 2026, 02:32:43 PM
     Quote from: philipma1957 on August 03, 2026, 04:45:13 PM
     My advice is have a few setups and add strong passphrases
     I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?
     https://x.com/i/status/2084949932289765633
     Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: Ambatman on August 05, 2026, 08:32:57 PM
    -Quote from: pawel7777 on Today at 07:54:42 PM
    +Quote from: pawel7777 on August 05, 2026, 07:54:42 PM
     I guess there's a sad lesson to be learned here. Even an open source software that has been around for years cannot be trusted blindly.
     It wasn't necessarily an open source but a verifiable source code.
     And yeah open source doesn't mean it's bug free
     Even bugs were noticed in bitcoin years ago.
     And this would set a precedence for more to come.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: cAPSLOCK on August 05, 2026, 11:28:36 PM
    +Quote from: The Sceptical Chymist on August 03, 2026, 05:06:40 AM
    +Quote from: m2017 on August 03, 2026, 02:53:26 AM
    +This situation also demonstrates the need to have a second hadeware wallet, a different model (or, better yet, from a different manufacturer).
    +I'm wondering if this situation demonstrates the need for more than what you've suggested--what that is I don't know, but I've been seeing a lot of vulnerabilities exploited/pointed out by hackers using AI, which includes HW wallets, altcoin blockchains (if I'm not mistaken), and other miscellaneous things that were once thought to be safe but turned out weren't.
    +I've always liked the concept of DIY HW wallets but haven't ever given one a shot.  Has there been any code written to make any for BTC?  Would one of those not potentially be safer overall?
    +Shit's scary out there right now.
    +Look into the Seedsigner.  I am a fan.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: kTimesG on August 06, 2026, 01:49:26 AM
    +Quote from: cygan on August 05, 2026, 05:55:06 AM
    +the following new website lists 'honeypot' wallets on the mainnet that are vulnerable to this specific ColdCard exploit � some wallets are protected by additional dice rolls or a passphrase.
    +this site tracks which of these an attacker is draining and how quickly. this makes it possible to determine which coins are currently being seized...
    +https://cktripwire.com/
    +The attack estimated time is around 352 times less than what is stipulated on that website. It's just that the "trivial" address is generated very naively as it's using impossible conditions for actually ever be created on a compromised device (unless one uses telepathy to force some hardware to start executing code, instead of using physics). I would only expect the rest of the honeypots to have the same problem (besides basically missing from the 5 years worth of historical blockchain indexed data - so probably skipped during lookup), which means that the entire process says nothing about how actual real hacked seeds were computed.
    +215c78739714754ba7a21269416165b194f5b5136bcd4766d58a7bb2ce8500d8 (a very naive seed, one of 16777216, found in 4.2 seconds using.a RTX 4090, not 88 minutes)
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: gmaxwell on August 06, 2026, 01:59:15 AM
    +It would be prudent to remind people here that there are still a lot of vulnerable funds that could be saved and that it would be anti-social to explain how to reduce the search space of coldcard devices just to brag about how smart you are, or show that some rando was wrong on the internet.
    +Plenty of other people could be posting about the exact search space needed to enumerate vulnerable seeds and are kindly refraining from doing so. Just because you could figure out that doesn't mean that every would be coin-thief is going to figure it out before the owners sweep their coins.
    +[I'm not picking on anyone here, this is in fact a repost of a comment I just wrote on reddit.]
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: tvbcof on August 06, 2026, 02:44:38 AM
    +Quote from: gmaxwell on Today at 01:59:15 AM
    +It would be prudent to remind people here that there are still a lot of vulnerable funds that could be saved and that it would be anti-social to explain how to reduce the search space of coldcard devices just to brag about how smart you are, or show that some rando was wrong on the internet.
    +Plenty of other people could be posting about the exact search space needed to enumerate vulnerable seeds and are kindly refraining from doing so. Just because you could figure out that doesn't mean that every would be coin-thief is going to figure it out before the owners sweep their coins.
    +[I'm not picking on anyone here, this is in fact a repost of a comment I just wrote on reddit.]
    +Not so sure, Greg.
    +I found out about the 'bug', and the initial details of it, when I had about 3 days left in a foreign land.  I had to decide whether to get an emergency ticket home.  My own musings about such optimizations and growth rates had a lot to do with my catching the next plane home rather than waiting.  I'm very glad I did.
    +I would question the potential for someone who didn't think of some of the optimizations to implement them triggered by general chatter.  Even if they did, they would likely be highly out-competed by sharper minds or groups of minds.  No pun on 'mines' intended.
    +At the end of the day, I almost always tend to lean toward full, accurate, and truthful information availability as a general principle.  Not always, but usually all else being marginally close to equal.
    +Actually one could be mildly suspicious about information which circulate information which drastically overstates some of the metrics such as search space.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  16. source content difference between and source content +204 -1

    The forum thread gained posts about passphrase strength, migration scams, recovery comparisons and Slipstream, and its displayed reported total reached 1485.77 BTC. It also corrected one #ifdef/#ifndef spelling error.

    seen · Captured here 411,503 chars
    What changed from the previous capture 205 lines
     .....
     Gmaxwell detailed exactly what the ColdCard programmer(s) did wrong (https://bitcointalk.org/index.php?topic=5589927.msg66996519#msg66996519)
     Letting such an amateur bug slip through into production software is beyond inexcusable. So they wrote a critical function selection process but never added a followup state check flag? When debugging the software they made no allowances to actually see what RNG was being used? They should be and probably will be massively sued.
    -When I used to write CNC code that used #define and #if/#ifndif to setup key functions I always followed it with 2 lines of code to act as a handshake to verify what I intended to run actually has been the one chosen and is the one running, if it wasn't it would throw a error about it. It just was common sense to do that and I'm not even a 'real' programmer as writing code was just part of what I did designing the systems we used to build. For someone who writes code for a living, not checking the state of critical functions is pure slop.
    +When I used to write CNC code that used #define and #ifdef/#ifndef to setup key functions I always followed it with 2 lines of code to act as a handshake to verify what I intended to run actually has been the one chosen and is the one running, if it wasn't it would throw a error about it. It just was common sense to do that and I'm not even a 'real' programmer as writing code was just part of what I did designing the systems we used to build. For someone who writes code for a living, not checking the state of critical functions is pure slop.
     Worse, others have pointed out that Coinkite was aware of something wrong long ago. They buried the reports. They also have a history of not paying any bug bounties which of course discourages knowledgeable folks from reviewing their code. Their code maybe 'Open View' but they made no effort to respond to any possible issues reported by anyone They never paid any 3rd party security org to certify their code & hardware. The list goes on and on for the probable grounds of lawsuits.
     Title: Re: Large-scale Coldcard compromise (1128.47 BTC stolen so far)
     Post by: JayJuanGee on August 05, 2026, 04:59:37 AM
     Each of them has about 40-50 addresses distributed along 2-3 derivation paths... I have more than 60 addresses with balance and used more than 100 (including the ones without balance)
     And I still have ethereum and some tokens such as PAXG/XAUT. It will take some time to move all those coins which are in the wallet without a passphrase. But I think this is very important. I already set up a new hardware wallet and added a passphrase. I will move the funds soon.
     You are right about being careful with consolidations. I will try not to spend too many addresses together, for privacy reasons
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Catenaccio on August 05, 2026, 02:32:43 PM
    +Quote from: philipma1957 on August 03, 2026, 04:45:13 PM
    +My advice is have a few setups and add strong passphrases
    +I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?
    +It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.
    +Like how many words are considered as strong enough for a wallet passphrase?
    +No recommendation about that in Mastering Bitcoin book.
    +https://github.com/bitcoinbook/bitcoinbook/blob/develop/ch05_wallets.adoc#optional-passphrase-in-bip39
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Comeacross on August 05, 2026, 02:40:48 PM
    +Quote from: ovcijisir on August 04, 2026, 10:02:19 PM
    +Be aware of fake Telegram groups, where they "help" with "wallet migration".
    +Scam telegram groups:
    +Code:
    +https://t.me/coldcardREAL
    +https://t.me/coldcardMigration
    +These groups are swaming with scammers that want victims to use their malicious links:
    +Code:
    +https://swiftprotocolresolvers.web.app/
    +http://migrate.coldcardfirmware.com
    +https://m-coldcard.web.app
    +https://dashboards.protocolsdata.workers.dev
    +https://coldcard-en.web.app
    +https://coldcard-devicenode.net/en/
    +https://coldcard-audit.com
    +https://dapplogin-connect.com
    +https://t.me/AiCustomerSupport247_bot
    +https://onchains-hub.vercel.app
    +Do not enter seed words there! Do not send funds there! Do not download any software from there!
    +Edit. Added new scams
    +If any of the victim fall for this again, they probably should not have any business with Bitcoin.
    +Scammers have no conscience indeed. If you can not sympathise with the victims, you should not attempt to steal more from them. Taking advantage of the hack to scam again is too devilish.
    +These people don't deserve this. Their only mistake was using the device that aim to protect them now they are being punished for silly mistakes by devs.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: jayhex on August 05, 2026, 03:36:14 PM
    +you jest but at least mtgox people got ~20% of their btc/bcash back
    +[/quote]
    +Yep and a long solid hodl so good they made nice money in fiat terms.
    +[/quote]
    +incorrect
    +i think just like FTX they got 20% of the price at the time of theft. so no hodl, just 20% of what u lost at that time 5-6 or more years ago
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: FP91G on August 05, 2026, 03:51:06 PM
    +MARA opens Slipstream to public as a free, permissionless Bitcoin transaction tool
    +link (https://cryptobriefing.com/mara-slipstream-public-permissionless-bitcoin-service/)
    +MARA Holdings has made its Slipstream transaction service free and open to the public, letting any Bitcoin user submit transactions directly through the company�s mining pool without touching the public mempool. The move turns a formerly restricted infrastructure tool into something any Bitcoin holder can use from a browser.
    +The service is live at slipstream.mara.com, requires no client software, and carries no additional fees beyond standard Bitcoin network transaction costs.
    +Quote
    +For users using multi-signature configurations�common among Coldcard holders who share control of their funds across multiple devices�the slipstream process itself is fraught with risk. Publicly broadcasting a transaction reveals wallet keys and the spending details. An attacker with a corresponding vulnerable private key could detect this transaction, create a competing transaction with a higher fee, and exploit the Bitcoin network's "Replace-by-Fee" (RBF) feature to bypass the queue and steal funds before the original transaction is confirmed.
    +MARA's Slipstream feature eliminates this window of vulnerability. Because the transaction never reaches the public mempool, the attacker sees neither the keys nor the spending details until MARA mines the coins in a confirmed block.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: hosemary on August 05, 2026, 03:55:15 PM
    +Quote from: Catenaccio on Today at 02:32:43 PM
    +It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.
    +When it comes to the amount of entropy and the probability of being cracked, I don't see any difference between a passphrase and a password.
    +It's simple. The more random characters you add to your passphrase, the higher entropy it provides.
    +Assuming all the characters you used in your passphrase are completely random and have been drawn from the full set of printable ASCII characters, there are 95 possibilities for each character.
    +For example, if your passphrase contains 10 random printable ASCII characters, there are 9510 possible combinations, which provide around 65.7 bits of entropy.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Cookdata on August 05, 2026, 04:10:09 PM
    +Quote from: Catenaccio on Today at 02:32:43 PM
    +Quote from: philipma1957 on August 03, 2026, 04:45:13 PM
    +My advice is have a few setups and add strong passphrases
    +I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?
    +If a scammer get access to your seed phrase and scan the wallet and see nothing on the wallet, they are not going to walk away immediately, they will try to guess right some common possible words which they know you might use as extension of your seed phrase. They are going to test words like your name, your child name or common strings you use for password, all of these are weak passphrase that scammer can guess right especially if the person knows much about you in detail. You should learn to use words that are uncommon that you can remember any time.
    +Quote
    +It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.
    +I think that's because seed phrase that is generated with a secured entropy is safe for your Bitcoin that's why emphasis are not given to passphrase and some recommendations but it's something you can do. If not for Coldcard negligence, most people don't use passphrase unless they want to use it. Look at numbers of wallet that were swept, it shows most didn't use passphrase else the attacker wouldn't be able to access them.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Princess Leah on August 05, 2026, 04:53:08 PM
    +Quote from: Cookdata on Today at 04:10:09 PM
    +Quote from: Catenaccio on Today at 02:32:43 PM
    +I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?
    +If a scammer get access to your seed phrase and scan the wallet and see nothing on the wallet, they are not going to walk away immediately, they will try to guess right some common possible words which they know you might use as extension of your seed phrase. They are going to test words like your name, your child name or common strings you use for password, all of these are weak passphrase that scammer can guess right especially if the person knows much about you in detail. You should learn to use words that are uncommon that you can remember any time.
    +Quote
    +It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.
    +I think that's because seed phrase that is generated with a secured entropy is safe for your Bitcoin that's why emphasis are not given to passphrase and some recommendations but it's something you can do. If not for Coldcard negligence, most people don't use passphrase unless they want to use it. Look at numbers of wallet that were swept, it shows most didn't use passphrase else the attacker wouldn't be able to access them.
    +A combination of aphabets, numbers and symbols is more better  for instance a common name like Grace or Paul Smith can be guessed correctly but a combination of a nickname number and symbols would be so tough to guess and it should be from 12 to 32 characters something like PsmithY@&80566@.
    +Noticed how the characters contains upper and lowercase alphabets, that's to add extra strength to it and make it tough to decoded. People would begin to see the importance of adding extra security to their wallets by including a passphrase, those who did that to their wallets and also used multi sig wallets would be secured from hack.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: philipma1957 on August 05, 2026, 06:05:01 PM
    +Quote from: Catenaccio on Today at 02:32:43 PM
    +Quote from: philipma1957 on August 03, 2026, 04:45:13 PM
    +My advice is have a few setups and add strong passphrases
    +I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?
    +It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.
    +Like how many words are considered as strong enough for a wallet passphrase?
    +No recommendation about that in Mastering Bitcoin book.
    +https://github.com/bitcoinbook/bitcoinbook/blob/develop/ch05_wallets.adoc#optional-passphrase-in-bip39
    +I can talk to you about trezor as that is what I use.
    +you can use up to 50 character length but don't lost it or you lose your funds.
    +easy ways to make a good one.
    +https://www.amazon.com/Abrrow-Scrabble-Symbols-Great-Pendants-Scrapbooking/dp/B077SDLMLL/ref=sr_1_36?
    +above has
    +0
    +1
    +2
    +3
    +4
    +5
    +6
    +7
    +8
    +9
    +-
    ++
    +/
    +=                       that is 14 different characters
    +put them in a bag all 14 shake pick 1 out write it on paper put it back
    +shake bag  pick 1 out write it on paper put it back do this at least 16 times
    +so 1/14 for each pick
    +a single pick is 14 combos = shit
    +2 picks is 14x14=196 combos =shit
    +3 picks is 14x14x14=2,744  = shit
    +4 pick is   14x14x14x14=38,416 =shit
    +5 picks is 14x14x14x14x14=537,824 =shit
    +6 picks is  14x14x14x14x14x14=7,529,536 =shit
    +7 picks is  14x14x14x14x14x14x14=105,413,504 = meh yeah 105mill is meh
    +8 picks is 14x14x14x14x14x14x14x14=1,475,789,056 = meh  yep 1.4bill is meh
    +9 picks is  14x14x14x14x14x14x14x14x14= 20,661,046,784 = meh yep 20.6 billion is also meh
    +10 picks is  289,254,654,,976              still meh yep 289 bill = so so
    +11 picks is 4,049,565,169,664            this may give you enough time to move the coins out as you would not be the first wave of victims
    +12 picks is 56,693,912,375,296          same here you would likely be a bit longer that the first wave.
    +13 picks is             793,714,773,254,144         I still would want more then a 793 trillion set of protection
    +14 picks is        11,112,006,825,558,016
    +15 picks is   2,177,953,337,809,371,136
    +16 picks is 30,491,346,729,331,195,904      this is 30 million times 1 trillion the weak hacked set on cold card was 1.1 trillion
    +so this would be 30 million times harder to hit than the hack and you also have a seed in front of of it.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Meuserna on August 05, 2026, 06:17:30 PM
    +Quote from: Catenaccio on Today at 02:32:43 PM
    +Quote from: philipma1957 on August 03, 2026, 04:45:13 PM
    +My advice is have a few setups and add strong passphrases
    +I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?
    +It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.
    +Like how many words are considered as strong enough for a wallet passphrase?
    +No recommendation about that in Mastering Bitcoin book.
    +https://github.com/bitcoinbook/bitcoinbook/blob/develop/ch05_wallets.adoc#optional-passphrase-in-bip39
    +Picking a Good BIP39 Passphrase or avoiding a bad one.
    +A guide by the ultimate white-hat Bitcoiner, Crypto-Guide:
    +https://www.youtube.com/watch?v=nhjq_1J0EbU&t=583s
    +His youtube channel is one of the best. No fluff, no hype. Just serious security, well explained.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: suzanne5223 on August 05, 2026, 06:28:12 PM
    +Quote from: abaeze on August 04, 2026, 03:39:59 PM
    +Quote from: philipma1957 on August 04, 2026, 02:47:28 PM
    +Quote from: asUHWEceyc on August 04, 2026, 01:18:16 PM
    +This certainly appears to be an exit scam with good plausible deniability when you look back at JWWeatherman_ badgering coldcard to add external entropy via dice rolls to their quick start guide in the 2020-2021 period, which they refused to do.
    +It also casts a shadow on their podcast promoters, who were most likely mere useful idiots.
    +The company is obviously done, through reputational damage and/or lawsuits, but someone has the coins
    +lets say inside job.
    +the issue is any other wallet company can do the same.
    +firmware 2027 for ledger makes a bug
    +and in 2028 ledger hacked.
    +right down the road.
    +so  back to core only?
    +since if core is bad it is all dead.
    +The Coldcard hacking incident is actually challenging the entire Bitcoin ecosystem
    +No, it actually challenges the hardware wallet ecosystem.
    +Quote from: abaeze on August 04, 2026, 03:39:59 PM
    +no one can say exactly what will happen in the future, but self-custody, which was people's last resort to keep their digital assets Bitcoin safe, is now distrusted.
    +This is exactly why it is a challenge for the hardware sector to focus more on their product security and have more concern about every security flaw that's raised.
    +Quote from: vapourminer on August 04, 2026, 05:28:10 PM
    +Quote from: asUHWEceyc on August 04, 2026, 04:53:22 PM
    +I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time
    +you jest but at least mtgox people got ~20% of their btc/bcash back
    +Not everyone, though, because the final repayment deadline for Mt. Gox was postponed to October 31, 2026 (https://www.coindesk.com/markets/2025/10/27/mt-gox-delays-creditor-repayment-to-october-2026)
    +Quote from: Lucius on August 04, 2026, 01:51:55 PM
    +Quote from: MicroGuy on August 03, 2026, 05:24:21 PM
    +What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?
    +It's okay if you don't have a dog that likes to dig, and you haven't dug deep enough - or if you have a neighbor who watches you just for fun and decides to dig around your yard when you're not home. In addition, in some countries there are laws that say that the owner of the land is the owner of what is found up to a certain depth, and everything else is owned by the state. This is how they protect oil and gas deposits from ordinary people.
    +The ground settles over time, so if you bury something to a depth of, say, half a meter, it will slowly sink over time, especially if the soil is moist and there is a lot of rainfall.
    +I believe the major problem will be the neighbor who likes to watch for fun.
    +According to my research, the country with the lowest owner legal depth is 32 feet / 10 meters, which is Japan (https://note.com/tomadoor/n/neb075b869a9d?hl=en), while the max depth a dog can dig is roughly 3-7 feet.
    +Any depth thats dip to 15 feet deep is far below every active topsoil layer where earthworms and roots can cause slowly sink unless the object buried is something immensely heavy.
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: pawel7777 on August 05, 2026, 07:54:42 PM
    +Due to holiday, I'm a bit behind with all recent news including the coldcard vulnerability thing. But if I understand this correctly:
    +- nobody "hacked" anything per se
    +- the "hacker(s)" didn't have any contact with coldcard hardware
    +- it's all a result of open source code flaw that nobody noticed for like 5 years.
    +I read on social media that this type of flaw was almost impossible to notice for an untrained eye, so unless you're an expert, any self-inspection of the code would unlikely work.
    +I guess there's a sad lesson to be learned here. Even an open source software that has been around for years cannot be trusted blindly.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: NotATether on August 05, 2026, 08:05:22 PM
    +Quote from: OmegaStarScream on August 03, 2026, 07:54:52 PM
    +Quote from: EstherBtc on August 03, 2026, 06:31:45 PM
    +Found this on https://x.com/BitcoinNewsCom/status/2084273394229362780
    +-snip-
    +How would this work exactly? the KYC information are going to be cross checked against what exactly?
    +A signed message is not going to work either. Someone who can access your funds, would also have the ability to sign a message...
    +I understand the intention may be good but with no clear and straightforward way to know the rightful owners of those funds, whoever is going to do this will probably end up in legal trouble, or am I missing something here?
    +It seems they don't care, their only idea it seems is to involve law enforcement and inshallah
    +https://x.com/i/status/2084949932289765633
    +Title: Re: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    +Post by: Ambatman on August 05, 2026, 08:32:57 PM
    +Quote from: pawel7777 on Today at 07:54:42 PM
    +I guess there's a sad lesson to be learned here. Even an open source software that has been around for years cannot be trusted blindly.
    +It wasn't necessarily an open source but a verifiable source code.
    +And yeah open source doesn't mean it's bug free
    +Even bugs were noticed in bitcoin years ago.
    +And this would set a precedence for more to come.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  17. source content difference between and source content +91 -1

    The thread title's reported total increased from 1360.23 BTC to 1485.77 BTC. It also gained posts about reported fund movements, safe migration practices and participants' views of the incident, including two newly listed scam links.

    seen · Captured here 393,384 chars
    What changed from the previous capture 92 lines
     Bitcoin Forum
     Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    -Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
     Post by: flatfly on July 30, 2026, 08:44:17 PM
     https://x.com/Rob1Ham/status/2082896614218203616
     [EDIT]
     https://coldcard-devicenode.net/en/
     https://coldcard-audit.com
     https://dapplogin-connect.com
    +https://t.me/AiCustomerSupport247_bot
    +https://onchains-hub.vercel.app
     Do not enter seed words there! Do not send funds there! Do not download any software from there!
    +Edit. Added new scams
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: NUCLEAR7.1 on August 04, 2026, 10:13:31 PM
     Quote from: shahzadafzal on August 04, 2026, 09:12:58 PM
     Post by: flatfly on August 05, 2026, 07:46:43 AM
     Maybe time to revisit this very simple Python script I made 13 years ago (with support for dice rolls!)
     https://bitcointalk.org/index.php?topic=308972.msg3512786#msg3512786
    +(Not saying this is a good solution - DYOR)
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Danish Ali on August 05, 2026, 08:17:57 AM
    +Quote from: vapourminer on August 04, 2026, 05:28:10 PM
    +Quote from: asUHWEceyc on August 04, 2026, 04:53:22 PM
    +I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time
    +you jest but at least mtgox people got ~20% of their btc/bcash back
    +Getting 20% back after a decade of waiting, truly the gold standard of customer service.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: hedgeh0g on August 05, 2026, 08:24:31 AM
    +Quote from: LoyceV on August 04, 2026, 01:03:42 PM
    +Quote from: Wind_FURY on August 04, 2026, 10:58:59 AM
    +The community in general is still "lucky" that the stupidity came from the ColdCard developers.
    +This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
    +The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.
    +Unfortunately, there is a misconception in our psychology that if something has worked for a long time before us, then we consider it proven, although it may not be so. Every new incoming user thinks, "if everyone is using it so calmly, then someone has checked everything for sure." But it turns out that the system has not been properly tested in five years. And in the age of AI, we will hear more than once about the secrets of systems that were in plain sight, but only the latest AI model will be able to find it.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: LoyceV on August 05, 2026, 09:05:29 AM
    +Quote from: Wind_FURY on Today at 06:40:55 AM
    +But for the truly paranoid, install Bitcoin Core/Electrum in a computer that will NEVER connect to the internet FOREVER, and generate your keys/seed phrase there. Write it down, then keep it in a safe place. The same for the computer, keep it locked in a vault.
    +Keep sending Bitcoin to that address.
    +First, using only one address is terrible for privacy, but also requires exposing all funds if you want to send a transaciton in the future.
    +But worse, this setup is not easy. I can only encourage everyone to try and get familiar with it, but doing it correctly will be a challenge even for many people who consider themselves experienced Bitcoin users.
    +You mentioned writing down keys. That's prone to making mistakes (https://bitcointalk.org/index.php?topic=5363240.0), and with descriptor wallets it's even harder to do. If you use Electrum, you're going to have to update your offline version at some point. I've seen old (offline) versions that couldn't sign a transaction created with a newer (online) version of Electrum. It's time-consuming to do correct, and one small mistake is enough to undo all your efforts to keep your keys offline.
    +Quote from: https://todayinsci.com/C/Coveyou_Robert/CoveyouRobert-Quotations.htm
    +The generation of random numbers is too important to be left to chance.
    +� Robert R. Coveyou, 1970
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Dave1 on August 05, 2026, 09:31:41 AM
    +Let the games begin,
    +https://www.talkimg.com/images/2026/08/05/UoctVo.png
    +https://x.com/CertiKAlert/status/2084920866526114183
    +As one of the biggest blockchain security firm has seen some movement already. So it's going to be a cat and mouse game moving forward and trail where it will go.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: examplens on August 05, 2026, 10:49:36 AM
    +Quote from: Dave1 on Today at 09:31:41 AM
    +Let the games begin,
    +Here are the first Bitcoin transfers from the address bc1q0rvn88w08j75k4h48lf9fvhan7unjp7vjf5q6m, 64 BTC was sent. According to the further flow of transactions, it seems that it is a matter of mixing through the coinjoin method
    +https://mempool.space/tx/e3274a1b87096938d014e1edaa01b06c3dd16e72a48f66ead95c79f83f2b3ddf
    +https://mempool.space/tx/f3ee6e61129b90b4746275a2ea17b08ac53769556d61994c94f03db9bcc37b24
    +https://mempool.space/tx/3bdac8ed822fc4cb123bc78689da3179ea8321d6daa5034c2170100399cdf935
    +https://mempool.space/tx/80f11c778a2f486ffc55b4e8665a94971ae9c350ac53969e9efcbf90478cbf90
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: tvbcof on August 05, 2026, 12:32:46 PM
    +Quote from: DanWalker on Today at 12:34:00 AM
    +Quote from: Cookdata on August 04, 2026, 01:49:35 PM
    +I have seen some creepy tweets of old posts from Coldcard but I don't think this company is worth defending.
    +https://talkimg.com/images/2026/08/04/UoJbgc.jpeg
    +https://x.com/coldcardwallet/status/1447213375398846473
    +I don't think I'm overreacting right!
    +wtf, it seems a retirement attack? ???
    +is it when a developer intentionally inserts a bug into the entropy generation process so that it can later be used to steal user's wallet?
    +Ironically, that old tweet almost exactly describes the type of vulnerability that now appeared in ColdCard's firmware, so sad.
    +It seems they know everything, and made us fools.
    +Remember the 'hack' associated with the ridiculously simple on-line wallet which used only URL's?  What was the name...ah; Instawallet.
    +The hack was to sell it off to a couple of French guys of questionable repute.  They shut it down, but in fact did refund BTC to anyone who asked nice.  The 'hack' was that a lot of people had forgotten about Bitcoin generally.  To someone with only a few BTC (~$30) it simply wasn't worth the hassle to bother with.
    +Did the perps actually steal value from anyone?  It's questionable.  Was it a crime?  Debatable, but actually probably not.  Did they do well financially?  I wouldn't be surprised if they mainly travel in a Gulfstream these days.  They basically picked up what other people had dropped.
    +---
    +As I understand, the RNG used by Coinkite gained entropy from the device state.  It's a relatively simple device running at low clockrates.  Still, enough of a challenge to add some need for work (time).  If one designed and built the hardware, however, they could arrange to be more efficient at 'mining' for the right device states than their competition (e.g., common opertunists/criminals.)  They might actually have the private key to any BTC backed by their hardware almost in real time.
    +On my flight back to save some of my BTC I figured that what would probably form would be something like 'mining pools' looking for Coinkite BTC where the organizers keep track of productive device state data and thus optimize efforts for it.  Also, methods for identifying 'Coinkite-backed' BTC addresses in the blockchain would develop.  e.g., coins associated with other known Coinkite-backed ones would be more likely as users transfer funds around.
    +If Coinkite gave themselves an advantage among a population of criminals, they could pretty much sit on their hands and let the thief population stir up a lot of dust, then periodically pick up a juicy pay-off batch as needed.  Nice retirement.
    +Some tribes have a general understanding that it is ethically OK for their tribe to 'pick up what other people have dropped'.  I'm no Talmudic scholar, but I do wonder what the consensus is about how much helping people drop something in the first place is acceptable?
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: asUHWEceyc on August 05, 2026, 01:17:31 PM
    +Quote from: vapourminer on August 04, 2026, 05:28:10 PM
    +Quote from: asUHWEceyc on August 04, 2026, 04:53:22 PM
    +I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time
    +you jest but at least mtgox people got ~20% of their btc/bcash back
    +Yeah let's say Quadriga instead...for pants pooping consistency's sake
    +Title: Re: Large-scale Coldcard compromise (1128.47 BTC stolen so far)
    +Post by: bitmover on August 05, 2026, 02:08:22 PM
    +Quote from: JayJuanGee on Today at 04:59:37 AM
    +Quote from: bitmover on August 03, 2026, 05:02:19 PM
    +Quote from: philipma1957 on August 03, 2026, 04:45:13 PM
    +My advice is have a few setups and add strong passphrases
    +This is basically mandatory now..
    +I have a second wallet without a passphrase. I will move the funds to a new wallet with passphrase during this week.
    +But I have many coins, many addresses, many derivation paths. It will take some time...
    +In your case, I imagine that you are talking about a wallet that is not a cold card.
    +I recall several years ago, I had a wallet that seemed to have allowed the creation of several accounts, so over the years, I had created more than 50 accounts, and half of them still had some coins on them.
    +I recall that in a haste (or maybe out of expediency), I ended up combining accounts, which I later regretted.  At the time, I did not realize the implications of combining accounts and/or combining addresses
    +If we are not in a rush, then it may well be better to keep some (or even all) of the derivation paths separate.
    +If I were to be able to do that again, I would send each account to a separate address and if I had sub addresses within some of the accounts, each of those subaddresses would have gone to separate addresses too... so maybe I would have had ended up with more than 30 receiving addresses rather than the 1 or 2 that I ended up creating.
    +Actually, it is a hardware wallet with 2 wallets inside (one with a passphrase and 1 without).
    +Each of them has about 40-50 addresses distributed along 2-3 derivation paths... I have more than 60 addresses with balance and used more than 100 (including the ones without balance)
    +And I still have ethereum and some tokens such as PAXG/XAUT. It will take some time to move all those coins which are in the wallet without a passphrase. But I think this is very important. I already set up a new hardware wallet and added a passphrase. I will move the funds soon.
    +You are right about being careful with consolidations. I will try not to spend too many addresses together, for privacy reasons
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1485.77 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  18. source content difference between and source content +119 -0

    The forum thread gained several posts on passphrases, custody, recovery and alternatives, plus a link to a site said to track vulnerable honeypot wallets and a dice-roll script.

    seen · Captured here 383,205 chars
    What changed from the previous capture 119 lines
     Letting such an amateur bug slip through into production software is beyond inexcusable. So they wrote a critical function selection process but never added a followup state check flag? When debugging the software they made no allowances to actually see what RNG was being used? They should be and probably will be massively sued.
     When I used to write CNC code that used #define and #if/#ifndif to setup key functions I always followed it with 2 lines of code to act as a handshake to verify what I intended to run actually has been the one chosen and is the one running, if it wasn't it would throw a error about it. It just was common sense to do that and I'm not even a 'real' programmer as writing code was just part of what I did designing the systems we used to build. For someone who writes code for a living, not checking the state of critical functions is pure slop.
     Worse, others have pointed out that Coinkite was aware of something wrong long ago. They buried the reports. They also have a history of not paying any bug bounties which of course discourages knowledgeable folks from reviewing their code. Their code maybe 'Open View' but they made no effort to respond to any possible issues reported by anyone They never paid any 3rd party security org to certify their code & hardware. The list goes on and on for the probable grounds of lawsuits.
    +Title: Re: Large-scale Coldcard compromise (1128.47 BTC stolen so far)
    +Post by: JayJuanGee on August 05, 2026, 04:59:37 AM
    +Quote from: philipma1957 on August 02, 2026, 01:58:20 AM
    +also if you have a trezor
    +you can add five passphrase wallets
    +With Trezor, you can add an unlimited number of passphrase wallets.
    +Trezor refers to the wallet that is generated from the seedphrase by itself as the standard wallet, and the wallet that is generated from the addition of the passphrase is referred to as a hidden wallet.
    +Quote from: philipma1957 on August 02, 2026, 05:35:19 AM
    +well if you have a trezor adding a 24 passphrase means
    +a lot of safety
    +Of course, I do not know the accuracy of the math (like you had shown in your earlier post (https://bitcointalk.org/index.php?topic=5589927.msg67002782#msg67002782)), and surely your random 24 passphrase from 94 characters leads to quite a bit of difficulty, which may well be quite a bit more than enough... even 12 characters with randomness would be quite a lot of difficulty in breaking.
    +There are surely some folks who had used the passphrase with a lot less difficulty (randomness), and something like 12 characters, even if not random, would seem like a minimum preference level.
    +Quote from: BlackHatCoiner on August 02, 2026, 12:39:54 PM
    +Quote from: m2017 on August 02, 2026, 12:36:27 PM
    +That's why they're now in trouble. They either weren't aware of what was happening (the first wave and the vulnerability) or ignored the possibility of a repeat theft.
    +Or they were aware, but could not get access to their wallets. The purpose of a cold storage is to not be accessible at any point and time. It's August, people are in vacations. It's entirely possible that they saw the news and were in a foreign country, far away from their homes, or wherever they keep their seed phrases.
    +I am a bit reluctant to create my own "watch only" wallets, yet for sure there are times in which I am in places in which I don't have access to my hardware, yet there could sometimes be abilities to access the seedwords even though the device might be in another location - and some of the ability to access could be coincidence depending on where a person is at and what kind of information he has at the tip of his fingers (or within reasonable reach).
    +Quote from: Wind_FURY on August 02, 2026, 01:22:37 PM
    +The ColdCard situation showed the community that Bitcoin still has a very long journey before it actually reaches mass adoption.
    +But TODAY, we lost some users. We can't blame those people. You would probably have the same viewpoint if you lost your entire life-savings held in Bitcoin.
    +:'(
    +Quote
    +8 years of stacking, gone. I think it's time to move on.
    +I believed in Bitcoin. Holding it gave me peace of mind because my country has faced several FATF sanctions. I was glad to find a kind of money that cannot be censored or debased because I just want to protect myself from the money printing and my country's weak and inflated currency comapred to the dollar.
    +I�m 39, and I was hoping to have a good financial cushion before 50. But today, my 2 BTC were drained.
    +Losing my Bitcoin has changed my mindset. It�s no longer about finishing the race first. At this point, I just want to finish it. But losing my BTC feels like I�m back at the starting line. I lost years of hard work and time.
    +I thought I was secure because Cold Card was always praised as one of the best and most secure wallets. It�s open source, so anyone can verify.
    +I�m done with Bitcoin. I�m not even sure if I still believe in it. I don�t know what the future holds for it anymore. I could have stayed with traditional investments and lived a normal life. Maybe I should have just moved everything into a Bitcoin ETF when they launched. But I don't know. It's too late to do it.
    +To everyone who has lost their BTC, I wish you the best and good health. I hope you find the strength to start again.
    +https://www.reddit.com/r/Bitcoin/comments/1vclm91/8_years_of_stacking_gone_i_think_its_time_to_move/
    +For sure people can end up feeling disgruntled based on a large loss (or large losses), and yeah, if we take the guy at his word that he lost everything related to his bitcoin stash, then that is a pretty BIG set back. I measure 8 years of stacking to have had been about $33.5k invested at about $80 per week, in order to get to that stack size in 8 years.
    +It seems to me that 39 years old is not too young to start again with the bitcoin stash, even if maybe the stacking rate might be less and even the ability to recover the coins that had already been lost is not possible, but there still could be a possibility to stack somewhere in the ballpark of $80 per week or even more - even though surely confidence may well could have had been shattered.. yet I have difficulties imagining other places to put value that is as good as bitcoin - even though for sure we know that the future of bitcoin and/or its price is not guaranteed, yet it seems if anyone already spent around 8 years stacking bitcoin at $80-ish per week, then from my perspective, a total loss at 39 years old, is still not automatically a reason to stop stacking...even though I can understand the current sentiment is negative.
    +Surely.  Opinions are going to vary, and guys who are much older than 39 years old would love to be 39 years old again... so there still can be ways to attempt to figure out positive things in terms of learning that might not necessarily involve abandoning bitcoin.
    +Quote from: bitmover on August 03, 2026, 05:02:19 PM
    +Quote from: philipma1957 on August 03, 2026, 04:45:13 PM
    +My advice is have a few setups and add strong passphrases
    +This is basically mandatory now..
    +I have a second wallet without a passphrase. I will move the funds to a new wallet with passphrase during this week.
    +But I have many coins, many addresses, many derivation paths. It will take some time...
    +In your case, I imagine that you are talking about a wallet that is not a cold card.
    +I recall several years ago, I had a wallet that seemed to have allowed the creation of several accounts, so over the years, I had created more than 50 accounts, and half of them still had some coins on them.
    +I recall that in a haste (or maybe out of expediency), I ended up combining accounts, which I later regretted.  At the time, I did not realize the implications of combining accounts and/or combining addresses
    +If we are not in a rush, then it may well be better to keep some (or even all) of the derivation paths separate.
    +If I were to be able to do that again, I would send each account to a separate address and if I had sub addresses within some of the accounts, each of those subaddresses would have gone to separate addresses too... so maybe I would have had ended up with more than 30 receiving addresses rather than the 1 or 2 that I ended up creating.
    +Quote from: MicroGuy on August 03, 2026, 05:24:21 PM
    +What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?
    +My first thought was:  cooked rice or raw?  hahahaha.. but that is a dumb joke since I understand the rice is meant to absorb  moisture, so it would be raw.
    +We know that the paper wallet does not solve your problem if it was created by a cold card wallet or if the random number generator was lacking in randomness.
    +For the kind of attack against cold card wallets, burying it does not help, either.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: cygan on August 05, 2026, 05:55:06 AM
    +the following new website lists 'honeypot' wallets on the mainnet that are vulnerable to this specific ColdCard exploit � some wallets are protected by additional dice rolls or a passphrase.
    +this site tracks which of these an attacker is draining and how quickly. this makes it possible to determine which coins are currently being seized...
    +https://cktripwire.com/
    +https://talkimg.com/images/2026/08/05/UoLsLq.jpg
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: stompix on August 05, 2026, 06:27:59 AM
    +Quote from: Lucius on August 04, 2026, 01:51:55 PM
    +Quote from: MicroGuy on August 03, 2026, 05:24:21 PM
    +What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?
    +It's okay if you don't have a dog that likes to dig, and you haven't dug deep enough - or if you have a neighbor who watches you just for fun and decides to dig around your yard when you're not home.
    +Flood, earthquakes, some company coming out of nowhere and digging in your yard for an emergency gas/electric line repair and many others.
    +Also, about the rice thing, just grab a pair of new sneakers and use the silica gel from them, rice that absorbs humidity will be a problem itself.
    +There is no perfect solution for anything, there is always a risk.
    +Quote from: BlackHatCoiner on August 04, 2026, 06:51:25 PM
    +Quote from: LoyceV on August 04, 2026, 05:41:33 PM
    +Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
    +So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
    +They could have taken most of the coins though, and give it back to the soon-to-be-victims though. Regardless, however, I agree that either way their business would be completely over.
    +And nobody would have believed them when they said they were giving all the coins back to the owners, everyone would have said they are preying on people who can't prove they are the owners of those coins.
    +A cold wallet manufacturer taking your money without your knowledge would have been the end of any company.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: JayJuanGee on August 05, 2026, 06:31:21 AM
    +Quote from: philipma1957 on August 04, 2026, 12:48:22 AM
    +Quote from: rdluffy on August 03, 2026, 10:13:24 PM
    +[edited out]
    +Yeah kyc helps in this case.
    +Say I have kyc at kraken. And by  Buying 0.001 btc a week to be like jjg and dca
    +deposit it every week to the cold card.
    +Since my name was dropped, I would like to clarify what I would do if I were DCA'ing anywhere between $40 to $100 worth of bitcoin every week on an exchange.
    +Most likely I would let the value of BTC on the exchange get up to anywhere between $500 and $1k before I would transfer the amount to my hardware wallet.  I would not transfer relatively small UTXOs that are anywhere between $40 and $100, and I probably would not even transfer any below $500 since I would not want to have a bunch of small UTXOs to deal with, either in the present or in the future (even though we don't exactly know what is going to happen in the future in relation to bitcoin and/or transaction fees).
    +Quote from: philipma1957 on August 04, 2026, 12:48:22 AM
    +Plus you have the bank statements for the cash you added to kraken
    +And the actual cold card
    +lastly the paper work for buying the cold card.
    +If you did this you can show all the withdrawals you made from kraken and the deposits to the cold card.
    +The ones to be fucked are all gray buys of coins.
    +If you have a bunch of UTXOs in one wallet, it is most likely that you would be able to show that all of those UTXOs are yours, as long as you were able to show one or more of them were yours.  There should not be any obligation to show from where all of the UTXOs came from as long as at least one of them (or maybe more than one) can be traced to your identity, such as the Kraken purchases, as you mentioned.  There might even be several sub accounts within a same wallet that has hundreds of bitcoin addresses (UTXOs), and it does not matter, since they are all controlled by the same wallet, so once you show that you are owner of the wallet, then all of the UTXOs o not need to be shown to be ones that you can (or even need to) identify, unless there is some state actor that is requiring such, and then you would have to get an attorney to sue the government for lack of due process (trying to take your property) and/or lack of a rational basis for requiring you to show anything beyond your ownership of the wallet.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Wind_FURY on August 05, 2026, 06:40:55 AM
    +Quote from: LoyceV on August 04, 2026, 01:03:42 PM
    +Quote from: Wind_FURY on August 04, 2026, 10:58:59 AM
    +The community in general is still "lucky" that the stupidity came from the ColdCard developers.
    +This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
    +The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.
    +But for the truly paranoid, install Bitcoin Core/Electrum in a computer that will NEVER connect to the internet FOREVER, and generate your keys/seed phrase there. Write it down, then keep it in a safe place. The same for the computer, keep it locked in a vault.
    +Keep sending Bitcoin to that address.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: NotATether on August 05, 2026, 06:44:16 AM
    +Quote from: MicroGuy on August 03, 2026, 05:24:21 PM
    +What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?
    +That only works if you have a backyard.
    +I'd get in trouble if I drilled through the patio concrete for this purpose.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: decodx on August 05, 2026, 06:56:46 AM
    +Quote from: Wind_FURY on Today at 06:40:55 AM
    +Quote from: LoyceV on August 04, 2026, 01:03:42 PM
    +Quote from: Wind_FURY on August 04, 2026, 10:58:59 AM
    +The community in general is still "lucky" that the stupidity came from the ColdCard developers.
    +This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
    +The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.
    +But for the truly paranoid, install Bitcoin Core/Electrum in a computer that will NEVER connect to the internet FOREVER, and generate your keys/seed phrase there. Write it down, then keep it in a safe place. The same for the computer, keep it locked in a vault.
    +Keep sending Bitcoin to that address.
    +To be honest, I don't think this is a good solution for the truly paranoid (or even for the mildly paranoid).   You've just switched from using hardware wallets over to Electrum as your preferred solution.
    +What if there was some vulnerability exposed within the Electrum development? It really wouldn't make that much difference to the final outcome.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: flatfly on August 05, 2026, 07:46:43 AM
    +Maybe time to revisit this very simple Python script I made 13 years ago (with support for dice rolls!)
    +https://bitcointalk.org/index.php?topic=308972.msg3512786#msg3512786
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  19. source content difference between and source content +18 -0

    The BitcoinTalk thread gained two posts, one speculating about a retirement attack and one criticizing the firmware controls and alleging earlier ignored reports.

    seen · Captured here 367,841 chars
    What changed from the previous capture 18 lines
     I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time
     you jest but at least mtgox people got ~20% of their btc/bcash back
     Yep and a long solid hodl so good they made nice money in fiat terms.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: DanWalker on August 05, 2026, 12:34:00 AM
    +Quote from: Cookdata on August 04, 2026, 01:49:35 PM
    +I have seen some creepy tweets of old posts from Coldcard but I don't think this company is worth defending.
    +https://talkimg.com/images/2026/08/04/UoJbgc.jpeg
    +https://x.com/coldcardwallet/status/1447213375398846473
    +I don't think I'm overreacting right!
    +wtf, it seems a retirement attack? ???
    +is it when a developer intentionally inserts a bug into the entropy generation process so that it can later be used to steal user's wallet?
    +Ironically, that old tweet almost exactly describes the type of vulnerability that now appeared in ColdCard's firmware, so sad.
    +It seems they know everything, and made us fools.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: NotFuzzyWarm on August 05, 2026, 12:46:18 AM
    +.....
    +Gmaxwell detailed exactly what the ColdCard programmer(s) did wrong (https://bitcointalk.org/index.php?topic=5589927.msg66996519#msg66996519)
    +Letting such an amateur bug slip through into production software is beyond inexcusable. So they wrote a critical function selection process but never added a followup state check flag? When debugging the software they made no allowances to actually see what RNG was being used? They should be and probably will be massively sued.
    +When I used to write CNC code that used #define and #if/#ifndif to setup key functions I always followed it with 2 lines of code to act as a handshake to verify what I intended to run actually has been the one chosen and is the one running, if it wasn't it would throw a error about it. It just was common sense to do that and I'm not even a 'real' programmer as writing code was just part of what I did designing the systems we used to build. For someone who writes code for a living, not checking the state of critical functions is pure slop.
    +Worse, others have pointed out that Coinkite was aware of something wrong long ago. They buried the reports. They also have a history of not paying any bug bounties which of course discourages knowledgeable folks from reviewing their code. Their code maybe 'Open View' but they made no effort to respond to any possible issues reported by anyone They never paid any 3rd party security org to certify their code & hardware. The list goes on and on for the probable grounds of lawsuits.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  20. source content difference between and source content +7 -0

    The thread gained a reply about Mt. Gox, BTC-e and FTX custody failures.

    seen · Captured here 365,206 chars
    What changed from the previous capture 7 lines
     Hindsight also does a lot of heavy lifting here. Once the bug is public and everyone knows to look at seed/entropy generation, of course a model (or a human researcher) zeroes in on it fast. That's not really comparable to a blind review of the full codebase before anyone knew where the problem was.
     That said, the underlying question is fair. If Coinkite actually ran targeted reviews of the RNG logic specifically, with well-crafted prompts, across multiple frontier models, and still came back empty � that would be a real red flag worth pressing them on. But without knowing exactly what they tested, how, and against what scope, there's no way to call this a "lie" with any confidence. It's either a genuine limitation of AI-assisted review under generic prompting, or a case of "we didn't look hard enough in the right place" � and those are two very different admissions.
     Would be good to see Coinkite actually publish the prompts and methodology they used for both the pre- and post-incident reviews. That's the only way this gets resolved instead of argued about.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: philipma1957 on August 04, 2026, 11:43:50 PM
    +Quote from: vapourminer on Today at 05:28:10 PM
    +Quote from: asUHWEceyc on Today at 04:53:22 PM
    +I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time
    +you jest but at least mtgox people got ~20% of their btc/bcash back
    +Yep and a long solid hodl so good they made nice money in fiat terms.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  21. source content difference between and source content +2 -2

    A participant added coldcard-audit.com to the thread's scam-site warning list and corrected a typo in that warning.

    seen · Captured here 364,770 chars
    What changed from the previous capture 4 lines
     https://dashboards.protocolsdata.workers.dev
     https://coldcard-en.web.app
     https://coldcard-devicenode.net/en/
    +https://coldcard-audit.com
     https://dapplogin-connect.com
    -Do not enter seed words there! Do not send funds there! Do kot download any software from there!
    +Do not enter seed words there! Do not send funds there! Do not download any software from there!
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: NUCLEAR7.1 on August 04, 2026, 10:13:31 PM
     Quote from: shahzadafzal on Today at 09:12:58 PM
     Hindsight also does a lot of heavy lifting here. Once the bug is public and everyone knows to look at seed/entropy generation, of course a model (or a human researcher) zeroes in on it fast. That's not really comparable to a blind review of the full codebase before anyone knew where the problem was.
     That said, the underlying question is fair. If Coinkite actually ran targeted reviews of the RNG logic specifically, with well-crafted prompts, across multiple frontier models, and still came back empty � that would be a real red flag worth pressing them on. But without knowing exactly what they tested, how, and against what scope, there's no way to call this a "lie" with any confidence. It's either a genuine limitation of AI-assisted review under generic prompting, or a case of "we didn't look hard enough in the right place" � and those are two very different admissions.
     Would be good to see Coinkite actually publish the prompts and methodology they used for both the pre- and post-incident reviews. That's the only way this gets resolved instead of argued about.
    -Just my two sats.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  22. source content difference between and source content +33 -0

    The thread gained two posts, one warning of fake migration groups and one cautioning against conclusions about Coinkite's AI review without its prompts and scope.

    seen · Captured here 364,761 chars
    What changed from the previous capture 33 lines
     Coinkite's attempt to downplay the severity of the attack gave owners of MK4, MK5, and Q devices false assurance their coins were safe while also giving thieves more time to work on finding and draining those users' wallets.
     Every step of the way, Coinkite's handling of the catastrophe has been inexcusable.
     Meanwhile, @NVK has been on Xwitter (https://x.com/nvk) for days. He's been doing lots of reposting, but saying nothing.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: ovcijisir on August 04, 2026, 10:02:19 PM
    +Be aware of fake Telegram groups, where they "help" with "wallet migration".
    +Scam telegram groups:
    +Code:
    +https://t.me/coldcardREAL
    +https://t.me/coldcardMigration
    +These groups are swaming with scammers that want victims to use their malicious links:
    +Code:
    +https://swiftprotocolresolvers.web.app/
    +http://migrate.coldcardfirmware.com
    +https://m-coldcard.web.app
    +https://dashboards.protocolsdata.workers.dev
    +https://coldcard-en.web.app
    +https://coldcard-devicenode.net/en/
    +https://dapplogin-connect.com
    +Do not enter seed words there! Do not send funds there! Do kot download any software from there!
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: NUCLEAR7.1 on August 04, 2026, 10:13:31 PM
    +Quote from: shahzadafzal on Today at 09:12:58 PM
    +Quote from:  https://x.com/coldcardwallet/status/2084731768632991801?s=46&t=EYlgQnpcCaCtcz2k1MwkNg
    +We've run AI-assisted review against our critical codebases, including in the weeks before the exploit. It did not catch this vulnerability. Since the incident, we've also tested our code against frontier models, including Kimi K3, Claude Fable, and Codex 5.6. None of them caught it.
    +Now that�s a straight lie.
    +Coinkite�s latest post claims they performed AI-assisted code reviews weeks before the vulnerability was discovered. Yet people have shown that Claude can identify the bug in just a 8 minutes.
    +Yes, it depends on the prompt too, but I�d expect the entropy generation logic to be one of the first areas reviewed. Instead of prompts like �Find a security issue in this code� or �find a bug in this code� will never expose the issue.
    +Of course, I�m only speculating about the prompts they actually used before the vulnerability was discovered.
    +You can read the full post here https://x.com/coldcardwallet/status/2084731768632991801?s=46&t=EYlgQnpcCaCtcz2k1MwkNg
    +Calling this a "straight lie" is jumping the gun a bit.
    +AI review results are heavily prompt-dependent. Running "find a bug in this code" against an entire firmware codebase is a very different task than pointing a model directly at the RNG function once you already know it's an entropy issue. Nobody outside Coinkite knows what prompts or scope they actually used pre-disclosure � that's the missing piece in this whole argument.
    +Hindsight also does a lot of heavy lifting here. Once the bug is public and everyone knows to look at seed/entropy generation, of course a model (or a human researcher) zeroes in on it fast. That's not really comparable to a blind review of the full codebase before anyone knew where the problem was.
    +That said, the underlying question is fair. If Coinkite actually ran targeted reviews of the RNG logic specifically, with well-crafted prompts, across multiple frontier models, and still came back empty � that would be a real red flag worth pressing them on. But without knowing exactly what they tested, how, and against what scope, there's no way to call this a "lie" with any confidence. It's either a genuine limitation of AI-assisted review under generic prompting, or a case of "we didn't look hard enough in the right place" � and those are two very different admissions.
    +Would be good to see Coinkite actually publish the prompts and methodology they used for both the pre- and post-incident reviews. That's the only way this gets resolved instead of argued about.
    +Just my two sats.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  23. source content difference between and source content +19 -0

    The thread gained a post criticizing Coinkite's early device-risk guidance.

    seen · Captured here 361,280 chars
    What changed from the previous capture 19 lines
     Yes, it depends on the prompt too, but I�d expect the entropy generation logic to be one of the first areas reviewed. Instead of prompts like �Find a security issue in this code� or �find a bug in this code� will never expose the issue.
     Of course, I�m only speculating about the prompts they actually used before the vulnerability was discovered.
     You can read the full post here https://x.com/coldcardwallet/status/2084731768632991801?s=46&t=EYlgQnpcCaCtcz2k1MwkNg
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Meuserna on August 04, 2026, 09:47:19 PM
    +Quote from: shahzadafzal on Today at 09:12:58 PM
    +Quote from:  https://x.com/coldcardwallet/status/2084731768632991801?s=46&t=EYlgQnpcCaCtcz2k1MwkNg
    +We've run AI-assisted review against our critical codebases, including in the weeks before the exploit. It did not catch this vulnerability. Since the incident, we've also tested our code against frontier models, including Kimi K3, Claude Fable, and Codex 5.6. None of them caught it.
    +Now that�s a straight lie.
    +Coinkite�s latest post claims they performed AI-assisted code reviews weeks before the vulnerability was discovered. Yet people have shown that Claude can identify the bug in just a 8 minutes.
    +Yes, it depends on the prompt too, but I�d expect the entropy generation logic to be one of the first areas reviewed. Instead of prompts like �Find a security issue in this code� or �find a bug in this code� will never expose the issue.
    +Of course, I�m only speculating about the prompts they actually used before the vulnerability was discovered.
    +You can read the full post here https://x.com/coldcardwallet/status/2084731768632991801?s=46&t=EYlgQnpcCaCtcz2k1MwkNg
    +Coinkite also downplayed the attack. Their initial warning, published July 30, 2026, specifically said:
    +Quote
    +�Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk.�
    +�Mk4, Q and Mk5 are not affected based on our early analysis of the issue.�
    +Coinkite told users their Mk4, Mk5, and Q devices were safe before Coinkite established that was true.
    +It was not true.
    +Coinkite's attempt to downplay the severity of the attack gave owners of MK4, MK5, and Q devices false assurance their coins were safe while also giving thieves more time to work on finding and draining those users' wallets.
    +Every step of the way, Coinkite's handling of the catastrophe has been inexcusable.
    +Meanwhile, @NVK has been on Xwitter (https://x.com/nvk) for days. He's been doing lots of reposting, but saying nothing.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  24. source content difference between and source content +9 -0

    The thread gained a post disputing Coinkite's account of its AI-assisted code review.

    seen · Captured here 359,119 chars
    What changed from the previous capture 9 lines
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: CryptoCrookz on August 04, 2026, 08:25:31 PM
     Seems diversification is the only real answer, with a preselection of suppliers based on some code aspects like rng characteristics - though let's see what the next 'hack of the month' will be. Including custodial options in the approach is also not bad idea, 'not your keys not your coins' is not the answer to everything.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: shahzadafzal on August 04, 2026, 09:12:58 PM
    +Quote from:  https://x.com/coldcardwallet/status/2084731768632991801?s=46&t=EYlgQnpcCaCtcz2k1MwkNg
    +We've run AI-assisted review against our critical codebases, including in the weeks before the exploit. It did not catch this vulnerability. Since the incident, we've also tested our code against frontier models, including Kimi K3, Claude Fable, and Codex 5.6. None of them caught it.
    +Now that�s a straight lie.
    +Coinkite�s latest post claims they performed AI-assisted code reviews weeks before the vulnerability was discovered. Yet people have shown that Claude can identify the bug in just a 8 minutes.
    +Yes, it depends on the prompt too, but I�d expect the entropy generation logic to be one of the first areas reviewed. Instead of prompts like �Find a security issue in this code� or �find a bug in this code� will never expose the issue.
    +Of course, I�m only speculating about the prompts they actually used before the vulnerability was discovered.
    +You can read the full post here https://x.com/coldcardwallet/status/2084731768632991801?s=46&t=EYlgQnpcCaCtcz2k1MwkNg
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  25. source content difference between and source content +3 -0

    The thread gained a post advocating diversification, including custodial options, after the compromise.

    seen · Captured here 357,925 chars
    What changed from the previous capture 3 lines
     They could have taken most of the coins though, and give it back to the soon-to-be-victims though. Regardless, however, I agree that either way their business would be completely over.
     And yes, they could have warned the user of a vulnerability, but that should be worded in a way that it does not reveal your cold storage is at risk, or attackers would have got sooner than the victims by just scanning the codebase.
     Would it be illogical to think that this might not be just a random attack but a preplanned one? For which the bug or vulnerability was planted years ago, and was never found or patched on purpose to keep collecting information for a major attack, but doing it in a way that shouldn't make it suspicious for those in control of everything? Because there are cases unfolding where users reported similar problems years ago, but the developers or their support never took them seriously or looked into it. Maybe those few people who got their funds stolen back then were just victims of a few test tries if it actually works or not?  ::)
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: CryptoCrookz on August 04, 2026, 08:25:31 PM
    +Seems diversification is the only real answer, with a preselection of suppliers based on some code aspects like rng characteristics - though let's see what the next 'hack of the month' will be. Including custodial options in the approach is also not bad idea, 'not your keys not your coins' is not the answer to everything.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  26. source content difference between and source content +20 -0

    The BitcoinTalk thread gained new posts discussing whether and how users could have been warned, and broader hardware-wallet security concerns.

    seen · Captured here 357,476 chars
    What changed from the previous capture 20 lines
     https://www.talkimg.com/images/2026/08/04/UoYhdj.png
     For instance, giving a response from a solution aspect to the firmware bugs. They respond to the bug on the latest firmware by giving a new device COLDCARD. Man, you own COLDCARD.... these what you should do on COLDCARD.
     https://i.bitlist.co/bJbyj2VAGyt1.gif
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Forsyth Jones on August 04, 2026, 07:49:23 PM
    +Quote from: Cookdata on Today at 01:49:35 PM
    +I have seen some creepy tweets of old posts from Coldcard but I don't think this company is worth defending.
    +https://talkimg.com/images/2026/08/04/UoJbgc.jpeg
    +https://x.com/coldcardwallet/status/1447213375398846473
    +I don't think I'm overreacting right!
    +He is very arrogant, which makes it harder not to think it was intentional, because when dealing with a data security device, the first thing a expert cryptography/dev must know is how to generate sensitive data with a good source of entropy. Coldcard is a hardware wallet, which has all the security features we can imagine, but they failed in the most critical aspect: the entropy used to generate wallets. Only those who used a strong passphrase were safe.
    +Owners of hardware wallets should know what passphrase is, this also makes me have the following question: and other devices from other brands, how can we guarantee that such devices do not have some other flaw that could cause potential losses, we are in the age of AI guys, while there are millions of pcs using AI to search for hardware/software failures out there and they are evolving every day, we cannot do what the arrogant Nvk from coldcard did, which was ignore all the warnings from 2021 (like this tweet on the image for example).
    +Ledger, its competitor that also did a lot of shit (like Recover), has a team of white hat who scour their competitors' devices in search of bugs, and mainly, very serious vulnerabilities, while nvk didn't review its own code, and if it did, it probably used vibe coding that did a lousy analysis, at the very least, as a developer, he should have a team responsible for reviewing the all code.
    +I just haven't bought a coldcard yet, besides its price, I would have to pay between 60% - 300% in customs fees (yes, I live in a country that outrageously abuses taxing its own citizens).
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Alone055 on August 04, 2026, 08:16:12 PM
    +Quote from: BlackHatCoiner on Today at 06:51:25 PM
    +Quote from: LoyceV on Today at 05:41:33 PM
    +Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
    +So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
    +They could have taken most of the coins though, and give it back to the soon-to-be-victims though. Regardless, however, I agree that either way their business would be completely over.
    +And yes, they could have warned the user of a vulnerability, but that should be worded in a way that it does not reveal your cold storage is at risk, or attackers would have got sooner than the victims by just scanning the codebase.
    +Would it be illogical to think that this might not be just a random attack but a preplanned one? For which the bug or vulnerability was planted years ago, and was never found or patched on purpose to keep collecting information for a major attack, but doing it in a way that shouldn't make it suspicious for those in control of everything? Because there are cases unfolding where users reported similar problems years ago, but the developers or their support never took them seriously or looked into it. Maybe those few people who got their funds stolen back then were just victims of a few test tries if it actually works or not?  ::)
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  27. source content difference between and source content +26 -0

    The BitcoinTalk thread gained new posts discussing whether and how users could have been warned, and broader hardware-wallet security concerns.

    seen · Captured here 353,781 chars
    What changed from the previous capture 26 lines
     Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
     So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
     Not true, they could have advised moving funds without disclosing the vulnerability up front.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: BlackHatCoiner on August 04, 2026, 06:51:25 PM
    +Quote from: LoyceV on Today at 05:41:33 PM
    +Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
    +So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
    +They could have taken most of the coins though, and give it back to the soon-to-be-victims though. Regardless, however, I agree that either way their business would be completely over.
    +And yes, they could have warned the user of a vulnerability, but that should be worded in a way that it does not reveal your cold storage is at risk, or attackers would have got sooner than the victims by just scanning the codebase.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: tvbcof on August 04, 2026, 07:01:07 PM
    +Quote from: negotiation4 on Today at 06:32:28 PM
    +Quote from: LoyceV on Today at 05:41:33 PM
    +Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
    +So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
    +Not true, they could have advised moving funds without disclosing the vulnerability up front.
    +The only feasible way to 'get the word out' would be via an 'emergency' such as we are seeing now.
    +Of course I am very interested in whether these guys are crooks or not, so I try to look at things from all angles.  What if there was an even better reason (e.g., and even bigger back-door.)  The 'responsible' thing to do would be to scare the shit out of people with a relatively bogus defect and a dose of social media engineering.  In that way, everyone would hear it pretty soon, and would take the desired action of draining their Coldcard-based wallets ASAP while in the scheme of things the userbase would not actually lose all that much.  I'm pleasantly surprised that none of my stuff was hit.
    +Anyway, that's a charitable hypothetical excuse for Coinkite's activities and proclivities.
    +---
    +As for keeping this particular vulnerability undisclosed, it's not real practical.  The problem was really a pretty basic one which happens all the time.  [There may be some code running in space built against header files inappropriate for the Linux kernel installed due to problems much like this one.  Who knows?]
    +I don't do almost any coding any more, but my friends who do are ga-ga over AI.  All I can say is that if AI missed a very common pre-processor issue like this, it's not very good at code checking.  Did they forget to teach the model that RNG was extra critical?  Do they even need to?  Not impressed!
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: ryzaadit on August 04, 2026, 07:16:08 PM
    +Seeing the response from a bug on the newest firmware from Coinkite Support Specialist is funny.
    +https://www.talkimg.com/images/2026/08/04/UoYhdj.png
    +For instance, giving a response from a solution aspect to the firmware bugs. They respond to the bug on the latest firmware by giving a new device COLDCARD. Man, you own COLDCARD.... these what you should do on COLDCARD.
    +https://i.bitlist.co/bJbyj2VAGyt1.gif
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  28. source content difference between and source content +6 -0

    The BitcoinTalk thread gained new posts discussing whether and how users could have been warned, and broader hardware-wallet security concerns.

    seen · Captured here 350,110 chars
    What changed from the previous capture 6 lines
     Post by: LoyceV on August 04, 2026, 05:41:33 PM
     Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
     So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: negotiation4 on August 04, 2026, 06:32:28 PM
    +Quote from: LoyceV on Today at 05:41:33 PM
    +Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
    +So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
    +Not true, they could have advised moving funds without disclosing the vulnerability up front.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  29. source content difference between and source content +9 -0

    The BitcoinTalk thread gained 2 new posts.

    seen · Captured here 349,433 chars
    What changed from the previous capture 9 lines
     I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time
     All wallets are hardware wallets; some consist of electronic, analog and/or auditable components. Bitcoin has been more or less "working" for a long time and is highly scrutinized, with fewer LOC and less stuff bolted on the farther you go back. Intel CPUs commonly relied on, on the other hand, are implicitly un-examinable.
     If someone's selling a cheap turnkey solution it might be too good to be true. It seems reasonable that a company marketing such a product in the future may need to insure every device sold with an implementation loss warranty up to some nominal fiat amount.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: vapourminer on August 04, 2026, 05:28:10 PM
    +Quote from: asUHWEceyc on Today at 04:53:22 PM
    +I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time
    +you jest but at least mtgox people got ~20% of their btc/bcash back
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: LoyceV on August 04, 2026, 05:41:33 PM
    +Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
    +So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  30. source content difference between and source content +17 -0

    The BitcoinTalk thread gained 1 new post.

    seen · Captured here 348,582 chars
    What changed from the previous capture 17 lines
     That recommendation list on Lopp's is losing trust is fair concern. However, SeedSigner trust model is quite different from that of Coldcard. Risk of Coldcard was centralized decision of a company owned maker. SeedSigner does not have maker, it's made out of everyday parts, so that type of failure is not relevant.
     Price factor plays a different role here as well. It is not about cost of the product you are buying, it is about removing risk from your shipping and parts supply. That is different type of benefit.
     It is still on Lopp's list and WalletScrutiny passes it, that is pretty good starting point for open source hardware.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: asUHWEceyc on August 04, 2026, 04:53:22 PM
    +Quote from: philipma1957 on Today at 02:47:28 PM
    +Quote from: asUHWEceyc on Today at 01:18:16 PM
    +This certainly appears to be an exit scam with good plausible deniability when you look back at JWWeatherman_ badgering coldcard to add external entropy via dice rolls to their quick start guide in the 2020-2021 period, which they refused to do.
    +It also casts a shadow on their podcast promoters, who were most likely mere useful idiots.
    +The company is obviously done, through reputational damage and/or lawsuits, but someone has the coins
    +lets say inside job.
    +the issue is any other wallet company can do the same.
    +firmware 2027 for ledger makes a bug
    +and in 2028 ledger hacked.
    +right down the road.
    +so  back to core only?
    +since if core is bad it is all dead.
    +I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time
    +All wallets are hardware wallets; some consist of electronic, analog and/or auditable components. Bitcoin has been more or less "working" for a long time and is highly scrutinized, with fewer LOC and less stuff bolted on the farther you go back. Intel CPUs commonly relied on, on the other hand, are implicitly un-examinable.
    +If someone's selling a cheap turnkey solution it might be too good to be true. It seems reasonable that a company marketing such a product in the future may need to insure every device sold with an implementation loss warranty up to some nominal fiat amount.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  31. source content difference between and source content +11 -0

    The BitcoinTalk thread gained 1 new post.

    seen · Captured here 347,039 chars
    What changed from the previous capture 11 lines
     so  back to core only?
     since if core is bad it is all dead.
     The Coldcard hacking incident is actually challenging the entire Bitcoin ecosystem, no one can say exactly what will happen in the future, but self-custody, which was people's last resort to keep their digital assets Bitcoin safe, is now distrusted. You are right that there is no guarantee that other companies will not do the same in the near future. Without people's trust and confidence, no security system is effectively secure, no matter how much companies say "your assets are 100% safe through our products", the public and companies must understand these things.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Danish Ali on August 04, 2026, 04:29:39 PM
    +Quote from: Catenaccio on Today at 12:44:35 PM
    +Seedsigner looks good by passing 10 tests there.
    +https://walletscrutiny.com/hardware/seedsigner/
    +It is recommended by Jameson Lopp in his list of recommended wallets (https://www.lopp.net/bitcoin-information/recommended-wallets.html) but honestly I don't know and I am unsure because he recommended Coldcard and has yet removed this terrible hardware wallet from the list.
    +In this What are best Bitcoin wallets (https://learnmeabitcoin.com/beginners/wallets/#best-wallets), there is no recommendation for SeedSigner.
    +Personally I don't consider saving cost is important when I buy a hardware wallet because I understand its importance and there are free open source software wallets to use. If I spend money to buy a hardware wallet, I buy a best one and don't mind to save cost that possibly puts my fund at risk if I buy a bad hardware wallet.
    +That recommendation list on Lopp's is losing trust is fair concern. However, SeedSigner trust model is quite different from that of Coldcard. Risk of Coldcard was centralized decision of a company owned maker. SeedSigner does not have maker, it's made out of everyday parts, so that type of failure is not relevant.
    +Price factor plays a different role here as well. It is not about cost of the product you are buying, it is about removing risk from your shipping and parts supply. That is different type of benefit.
    +It is still on Lopp's list and WalletScrutiny passes it, that is pretty good starting point for open source hardware.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  32. source content difference between and source content +15 -0

    A new forum reply said the incident had undermined trust in self-custody and other wallet companies.

    seen · Captured here 345,389 chars
    What changed from the previous capture 15 lines
     right down the road.
     so  back to core only?
     since if core is bad it is all dead.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: abaeze on August 04, 2026, 03:39:59 PM
    +Quote from: philipma1957 on Today at 02:47:28 PM
    +Quote from: asUHWEceyc on Today at 01:18:16 PM
    +This certainly appears to be an exit scam with good plausible deniability when you look back at JWWeatherman_ badgering coldcard to add external entropy via dice rolls to their quick start guide in the 2020-2021 period, which they refused to do.
    +It also casts a shadow on their podcast promoters, who were most likely mere useful idiots.
    +The company is obviously done, through reputational damage and/or lawsuits, but someone has the coins
    +lets say inside job.
    +the issue is any other wallet company can do the same.
    +firmware 2027 for ledger makes a bug
    +and in 2028 ledger hacked.
    +right down the road.
    +so  back to core only?
    +since if core is bad it is all dead.
    +The Coldcard hacking incident is actually challenging the entire Bitcoin ecosystem, no one can say exactly what will happen in the future, but self-custody, which was people's last resort to keep their digital assets Bitcoin safe, is now distrusted. You are right that there is no guarantee that other companies will not do the same in the near future. Without people's trust and confidence, no security system is effectively secure, no matter how much companies say "your assets are 100% safe through our products", the public and companies must understand these things.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  33. source content difference between and source content +13 -0

    A new forum reply speculated about an insider and broadened the discussion to risks at other wallet vendors.

    seen · Captured here 343,941 chars
    What changed from the previous capture 13 lines
     What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?
     It's okay if you don't have a dog that likes to dig, and you haven't dug deep enough - or if you have a neighbor who watches you just for fun and decides to dig around your yard when you're not home. In addition, in some countries there are laws that say that the owner of the land is the owner of what is found up to a certain depth, and everything else is owned by the state. This is how they protect oil and gas deposits from ordinary people.
     The ground settles over time, so if you bury something to a depth of, say, half a meter, it will slowly sink over time, especially if the soil is moist and there is a lot of rainfall.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: philipma1957 on August 04, 2026, 02:47:28 PM
    +Quote from: asUHWEceyc on Today at 01:18:16 PM
    +This certainly appears to be an exit scam with good plausible deniability when you look back at JWWeatherman_ badgering coldcard to add external entropy via dice rolls to their quick start guide in the 2020-2021 period, which they refused to do.
    +It also casts a shadow on their podcast promoters, who were most likely mere useful idiots.
    +The company is obviously done, through reputational damage and/or lawsuits, but someone has the coins
    +lets say inside job.
    +the issue is any other wallet company can do the same.
    +firmware 2027 for ledger makes a bug
    +and in 2028 ledger hacked.
    +right down the road.
    +so  back to core only?
    +since if core is bad it is all dead.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  34. source content difference between and source content +12 -0

    Additional forum posts were added to the ongoing discussion, including further debate over the incident’s cause and wallet choices.

    seen · Captured here 343,108 chars
    What changed from the previous capture 12 lines
     This certainly appears to be an exit scam with good plausible deniability when you look back at JWWeatherman_ badgering coldcard to add external entropy via dice rolls to their quick start guide in the 2020-2021 period, which they refused to do.
     It also casts a shadow on their podcast promoters, who were most likely mere useful idiots.
     The company is obviously done, through reputational damage and/or lawsuits, but someone has the coins
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Cookdata on August 04, 2026, 01:49:35 PM
    +I have seen some creepy tweets of old posts from Coldcard but I don't think this company is worth defending.
    +https://talkimg.com/images/2026/08/04/UoJbgc.jpeg
    +https://x.com/coldcardwallet/status/1447213375398846473
    +I don't think I'm overreacting right!
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Lucius on August 04, 2026, 01:51:55 PM
    +Quote from: MicroGuy on August 03, 2026, 05:24:21 PM
    +What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?
    +It's okay if you don't have a dog that likes to dig, and you haven't dug deep enough - or if you have a neighbor who watches you just for fun and decides to dig around your yard when you're not home. In addition, in some countries there are laws that say that the owner of the land is the owner of what is found up to a certain depth, and everything else is owned by the state. This is how they protect oil and gas deposits from ordinary people.
    +The ground settles over time, so if you bury something to a depth of, say, half a meter, it will slowly sink over time, especially if the soil is moist and there is a lot of rainfall.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  35. source content difference between and source content +90 -25

    Several new posts expanded the discussion of responsibility, passphrases, dice-generated seeds and alternative hardware wallets. Two earlier posts were no longer served in the print view.

    seen · Captured here 341,817 chars
    What changed from the previous capture 115 lines
     So I don�t think the real question is whether AI can somehow �break Bitcoin�. That�s probably the wrong way to look at it.
     The more interesting question is how much vulnerable code is still sitting somewhere in the Bitcoin ecosystem, considered safe mainly because nobody has managed to find the bug yet.
     My guess is that over the next few years we�re going to find out. In a brutal way, probably.
    -Title: Re: Large-scale Coldcard compromise (600 BTC stolen so far)
    -Post by: ColdcardVictim on July 31, 2026, 12:54:38 PM
    -Quote from: BlackBoss_ on July 31, 2026, 12:16:16 PM
    -Quote from: ColdcardVictim on July 31, 2026, 11:19:26 AM
    -This forum is one of the largest Bitcoin communities in the world. If the person responsible for taking my coins is active anywhere, there's a chance they've visited this forum or will someday. That's why I wanted my message to exist here.
    -I'm not accusing anyone on this forum. I have no evidence to do that. I just wanted there to be a chance that the person who now controls those coins might eventually read the words of the family they affected.
    -Lost 1.8 BTC due to ColdCard https://bitcointalk.org/index.php?topic=5589972.0 (https://bitcointalk.org/index.php?topic=5589972.0)
    -It is your hope that I can understand, if I had fallen into such situation like you did, I would have made my terrible action already but please stay strong and fight because you have your family behind to take care of them and surely they are really ready to take care of you, share the pain and loss you have now.
    -About the attacker(s), I don't know, maybe they visited the forum or will do it in the future, but honestly even I wish the best for you, I don't believe that such people will be ready to do the right things like returning bitcoins they hacked to victims including you. If they were good people, they would not do that already.
    -Will hackers behind this again come from North Korea like Lazzarus, let's wait for investigation and results later.
    -Quote
    -Lost 1.8 BTC due to ColdCard https://bitcointalk.org/index.php?topic=5589972.0 (https://bitcointalk.org/index.php?topic=5589972.0)
    -If you have a draft of that thread, you can make a new one in another board.
    -Hardware wallets (https://bitcointalk.org/index.php?board=261.0)
    -If you did not save it on your computer, you can find it in your draft page https://bitcointalk.org/index.php?action=drafts
    -Thank you very much for your kind words. They genuinely mean a lot to me.
    -You're probably right. Someone willing to steal life savings is unlikely to suddenly have a change of heart. Still, I felt that if there was even the smallest chance my message could reach them, it was worth trying. I think I would have regretted staying silent more than writing the post.
    -My family is the reason I'm still fighting. There are days when this feels overwhelming, but giving up isn't an option. I have to keep moving forward for my son.
    -I also appreciate you mentioning the drafts page and suggesting I repost it in the Hardware Wallets board. I'll definitely check if I still have a copy there. Thank you for taking the time to read my story and for offering both your encouragement and practical advice. I truly appreciate it.
     Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
     Post by: suzanne5223 on July 31, 2026, 12:57:28 PM
     Quote from: NotATether on July 31, 2026, 06:40:39 AM
     When a passphrase is optional and users choose not to use it, they significantly increase the risk of becoming victims sooner or later. Unfortunately, that's the direction it almost inevitably leads.
     It was also optional to keep the hardware device with a seed phrase created from 256 manual coin tosses offline, and sign only transactions manually entered on the keyboard. My point is: there's always more "the victims could have done". By your logic, it's always at least partially the victim's fault. I disagree. This is basic functionaly for a hardware wallet they sold for hundreds of dollars. The only reason to pay that much for such a simple piece of hardware is that it should be absolutely secure.
     Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    -Post by: brokebitcoiner on August 04, 2026, 08:01:29 AM
    -well guys if you own the keys you own the coins
    -if you are trusting someone to safeuard your assest the whole point of btc is lost make your own wallet dont let someone make it for you or their software before investing try to understand a bit about what the technology is and if you dont understand it then its just simply isnt for you. I heard about bitcoin in 2025 for the first time and people from 2015 0r 2020 dosent seem to understad what bitcoin is.
    -the coldcard company is to blame but no one was force to use thier wallet
    -always do your own due deligence to make sure what you own is secure and safe .
    -Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
     Post by: flatt on August 04, 2026, 08:05:11 AM
     Quote from: EstherBtc on Today at 07:24:35 AM
     I also thought about this whole thing as being an inside job. Because, why would a company neglect security alert that they know is a threat to their reputation. They knew their security was weak yet they neglected the warnings and didn't even come out publicly to warn their users. Also, they have been quiet on how to recover the coins that has been stolen, they are not providing solutions. lastly, why is it only Coldcard that is being attacked?
     I've a distaste for anything which uses electromagnetic radiation for comms (or dicking with uSD cards is a hassle with it's own security and usability issues.)  When I was shopping, Coldcard Q was the only device which made use of two-way QR-code interactions, and as a bonus, one could physically cut the radio options.  Mostly the device was powerful and usable for more complex work given it's form-factor, but I only appreciated that _fully_ after using it.
     In my initial research I actually did find and note at least one report of Coldcard funds vanishing, and it did give me pause.  Not seeing a huge number of them I decided, with reluctance, to chalk them up to probable user-error, competitor FUD, or some such.  Now it looks more like proof-of-concept and getting a little spending money by someone somewhere.  If Coinkite really did ignore and bury the complaints, that is not at all a good look.
     I am hopeful that in order to make amends to the community, Coinkite donates the whole Coldcard Q effort, including supply chain info, to the community.  Code development _INCLUDING TESTING_, profiling, distribution, etc might then be able to be done by people who have a wider range of skills and interests.  It would be great if such firmware would be distributed with a bootstrapped environment (compilers, test harnesses, etc) which may foster more interest among users to undertake more complex tasks.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: vapourminer on August 04, 2026, 10:34:44 AM
    +Quote from: crypto_curious on August 03, 2026, 11:53:42 AM
    +The victim does bear some responsibility here. There is no denying that, no matter how much people dislike hearing it.
    +When a passphrase is optional and users choose not to use it, they significantly increase the risk of becoming victims sooner or later. Unfortunately, that's the direction it almost inevitably leads.
    +some people have a non passphrase wallet as a decoy with passphrases behind it. but that doesnt mean they want to lose those coins, even as warning.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Wind_FURY on August 04, 2026, 10:58:59 AM
    +Quote from: negotiation4 on August 03, 2026, 07:59:26 AM
    +Seeing some of the responses to this makes my blood boil a bit on behalf of the victims.
    +"Oh they should have added passphrase, should have used dice, etc."
    +Sure - in hindsight, obviously, that would have protected them from this attack. But this is not correlated with whether this is something they should have done. In my mind - this is not what a passphrase is meant to protect against. It is for the case where your exact seed gets exposed, if your backup gets stolen, if it's accidentally uploaded to the internet, etc.
    +An equivalent bug could have seen the initial seed be perfectly fine, and then adding a passphrase through some bug eliminates a lot of that initial seed entropy. Or that the dice roll entries delete the initial entropy. Then what would people say? "Oh you should have verified the code and trusted the hardware RNG." It's easy to be wise after the fact.
    +It's just a mixture of bad luck and negligence on the part of the developer(s).
    +What scares me about this is that it just feels so random, so unavoidable on the part of the users. It feels like how when you get on a plane you're hoping it doesn't crash, but one in a few million will go down just out of sheer bad luck, through no fault of your own.
    +I think my biggest taking from this is just that spreading across 2-4 different technologies is probably worthwhile. Other than that I'm not sure there is much of a lesson here for the end user. It just sucks.
    +I'm sorry.
    +The Silver Lining - At least ColdCard didn't sell as much hardware devices as Trezor or Ledger. If ColdCard was the most successful hardware wallet that sold devices to millions of users, I'm very confident that the current situation would be more like the FTX crash or the Terra Luna crash.
    +The community in general is still "lucky" that the stupidity came from the ColdCard developers.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: suzanne5223 on August 04, 2026, 11:17:45 AM
    +Quote from: vapourminer on Today at 10:34:44 AM
    +Quote from: crypto_curious on August 03, 2026, 11:53:42 AM
    +The victim does bear some responsibility here. There is no denying that, no matter how much people dislike hearing it.
    +When a passphrase is optional and users choose not to use it, they significantly increase the risk of becoming victims sooner or later. Unfortunately, that's the direction it almost inevitably leads.
    +some people have a non passphrase wallet as a decoy with passphrases behind it. but that doesnt mean they want to lose those coins, even as warning.
    +While some people dont use a passphrase due to their level of understanding (newbie) and the trust they have in the wallet based on their security claim, with the inclusion of influencer marketing hype on YouTube, etc.
    +Therefore, the people who should be responsible the most are the wallet manufacturing company.
    +1. An alarm was raised about the issue years ago, but they ignore
    +2. They used the entropy bits that are not advisable for security
    +One of the thing i believe this incident demonstrates is that every security flaw alarm raised shouldn't be ignore; wallet manufacturers should always work with white hackers in doing security check on their devices because technology is always dvncing, wllet mnufacturer should lways consider the newbie level of understanding when they are creating their device, nd we as a community should also reconsider some hardware wallets to sure there's no hardware people are currently using that will be next Coldcard because nothing is totally perfect.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Pmalek on August 04, 2026, 11:27:28 AM
    +The Bitcoin Policy Institute created a visual overview of the Coldcard vulnerability, comparing seed phrases to atoms. In their video they describe a properly generated seed as an atom hidden somewhere across two billion galaxies, impossible to find by any computer/AI. Compared to that huge space, Coldcard's seed generation is presented as one atom in a virus. A computer could find it in a few hours. It's an interesting watch, so take a look:
    +https://www.youtube.com/watch?v=IwrKWdxt0YM
    +One person found a new use case for his Coldcard Q. He created a game, The Bitcoin Dungeon. You run around the different levels, collecting bitcoin and staying away from bankers. It's not meant to make fun of the victims that lost their coins. It just shows what's possible.
    +https://www.talkimg.com/images/2026/08/04/UoJP0D.jpg
    +https://x.com/pastorcoin/status/2084438312803090648
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Cookdata on August 04, 2026, 11:43:48 AM
    +Quote from: brokebitcoiner on Today at 08:01:29 AM
    +well guys if you own the keys you own the coins
    +if you are trusting someone to safeuard your assest the whole point of btc is lost make your own wallet dont let someone make it for you or their software before investing try to understand a bit about what the technology is and if you dont understand it then its just simply isnt for you. I heard about bitcoin in 2025 for the first time and people from 2015 0r 2020 dosent seem to understad what bitcoin is.
    +What are you saying? The coldcard mistake is a bug(deliberately or not, nobody can confirm if it was intentional), this does not makes other hardware trash or other random number generators invalid, there are plenty of wallet with good entropy. Hardware wallet are still the safest way to keep coins from scammers like this.
    +You can actually generate a good entropy of seed phrase  if you don't trust the wallet to do it for you, do it yourself with a dice or let a secure device does it for you. However, you still need a hardware wallet to keep your keys from the internet.
    +Quote
    +the coldcard company is to blame but no one was force to use thier wallet
    +always do your own due deligence to make sure what you own is secure and safe .
    +This is bullshit though, do you think people that bought the hardware wallet had the intention of losing their Bitcoin. I myself once fancy cold card, it was a matter of time before I get one until this incident.
    +You know why your comment is funny? What happened to Coldcard can happen to any device, this is not the first time a device with bad entropy is been reported, it just happen that we are in AI era where things are made easy for scammers.
    +I'm not sure if you have a hardware wallet the what you wrote up there.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Danish Ali on August 04, 2026, 12:15:38 PM
    +Quote from: The Sceptical Chymist on August 03, 2026, 05:06:40 AM
    +I'm wondering if this situation demonstrates the need for more than what you've suggested--what that is I don't know, but I've been seeing a lot of vulnerabilities exploited/pointed out by hackers using AI, which includes HW wallets, altcoin blockchains (if I'm not mistaken), and other miscellaneous things that were once thought to be safe but turned out weren't.
    +I've always liked the concept of DIY HW wallets but haven't ever given one a shot.  Has there been any code written to make any for BTC?  Would one of those not potentially be safer overall?
    +Shit's scary out there right now.
    +Honestly the concern is justified, attack area has grown by leaps and bounds and what was once considered safe two years ago is no longer safe.
    +SeedSigner is good option for Bitcoin in particular. Open source, air gapped, parts cost around $50, and community guides are good enough that technically curious person could make one without too much trouble. With no company owned software, there is no need to blindly trust maker code.
    +You should be able to follow build process easily, as you have some experience with it. Could be a good time to finally take that shot.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: Catenaccio on August 04, 2026, 12:44:35 PM
    +Quote from: Danish Ali on Today at 12:15:38 PM
    +SeedSigner is good option for Bitcoin in particular. Open source, air gapped, parts cost around $50, and community guides are good enough that technically curious person could make one without too much trouble.
    +Seedsigner looks good by passing 10 tests there.
    +https://walletscrutiny.com/hardware/seedsigner/
    +It is recommended by Jameson Lopp in his list of recommended wallets (https://www.lopp.net/bitcoin-information/recommended-wallets.html) but honestly I don't know and I am unsure because he recommended Coldcard and has yet removed this terrible hardware wallet from the list.
    +In this What are best Bitcoin wallets (https://learnmeabitcoin.com/beginners/wallets/#best-wallets), there is no recommendation for SeedSigner.
    +Personally I don't consider saving cost is important when I buy a hardware wallet because I understand its importance and there are free open source software wallets to use. If I spend money to buy a hardware wallet, I buy a best one and don't mind to save cost that possibly puts my fund at risk if I buy a bad hardware wallet.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: LoyceV on August 04, 2026, 01:03:42 PM
    +Quote from: Wind_FURY on Today at 10:58:59 AM
    +The community in general is still "lucky" that the stupidity came from the ColdCard developers.
    +This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
    +The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.
    +Quote from: Catenaccio on Today at 12:44:35 PM
    +Personally I don't consider saving cost is important when I buy a hardware wallet because I understand its importance and there are free open source software wallets to use. If I spend money to buy a hardware wallet, I buy a best one and don't mind to save cost that possibly puts my fund at risk if I buy a bad hardware wallet.
    +Paying more doesn't guarantee a better hardware wallet, Coldcard wasn't cheap.
    +Verify, don't trust. Easier said than done.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: EstherBtc on August 04, 2026, 01:09:12 PM
    +https://talkimg.com/images/2026/08/04/UoJLgC.png
    +Got this from X https://x.com/COLDCARDwallet/status/2084596971268956161
    +Someone's comment on this post made me sad, he said "Thank you cold card and coinkite for destroying trust in hardware device manufacturers for an entire class of Bitcoiners. Your lesson will be taught for decades to come".
    +Coldcard should just refund those affected. Unfortunately, some users who are not online don't even know that their bitcoin is under attack and has been wiped or about to be.
    +Title: Re: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    +Post by: asUHWEceyc on August 04, 2026, 01:18:16 PM
    +This certainly appears to be an exit scam with good plausible deniability when you look back at JWWeatherman_ badgering coldcard to add external entropy via dice rolls to their quick start guide in the 2020-2021 period, which they refused to do.
    +It also casts a shadow on their podcast promoters, who were most likely mere useful idiots.
    +The company is obviously done, through reputational damage and/or lawsuits, but someone has the coins
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  36. Earliest copy held
    seen · Captured here 333,209 chars
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: flatfly on July 30, 2026, 08:44:17 PM
    Title: Large-scale Coldcard compromise (1360.23 BTC stolen so far)
    Post by: flatfly on July 30, 2026, 08:44:17 PM
    https://x.com/Rob1Ham/status/2082896614218203616
    [EDIT]
    Vendor advisory post:
    https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
    Technical deep dive:
    https://blog.coinkite.com/entropy-technical-backgrounder/
    From Reddit:
    Quote
    Hoax__
    It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.
    The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.
    Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: Charles-Tim on July 30, 2026, 08:53:07 PM
    Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx (http://Ill Bloom reports made me remember bx)
    Who knows if it has something to do with it.
    Just use an open source reputed wallet.
    Quote from: flatfly on July 30, 2026, 08:44:17 PM
    Right now not much is known about the exact vulnerability.
    So why did you mention Coldcard in the topic title?
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OmegaStarScream on July 30, 2026, 08:58:06 PM
    Quote from: Charles-Tim on July 30, 2026, 08:53:07 PM
    So why did you mention Coldcard in the topic title?
    Looking at the replies of the tweet, it looks like the post is related to this:
    https://x.com/i/status/2082919505819304343
    https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/
    But nothing is confirmed yet.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: OgNasty on July 30, 2026, 09:09:17 PM
    Very concerning. I�ve never touched a coldcard but I�ve seen them mentioned enough around these forums to where I�m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I�ll have to do some reading up about this one.
    Title: Re: Large-scale coldcard compromise underway. 600 BTC drained so far
    Post by: flatfly on July 30, 2026, 09:13:43 PM
    True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.
    Title: Re: Large-scale compromise, possibly affecting coldcard (600 BTC stolen so far)
    Post by: knuckey on July 30, 2026, 09:58:46 PM

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

1 presentation-noise difference. Sidebar, ticker and other page chrome churn that our review classified as not being a change to what the source says.
  • +27 -27 Only Bitcointalk's relative quote dates rolled from Today to absolute dates.
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.