We can all learn one or two from this ColdCard incident
bitcointalk-learn-from-incident
Latest reviewed change
source content difference between and
The thread gained new posts by arwin100, Supreme Donvic and Dogedegen debating airgapped computers, diversification across wallets, and cracked operating systems.
Post by: yhiaali3 on August 07, 2026, 04:04:12 AM
Yes, this incident taught us many lessons, the most important of which is that there is no complete security in crypto unless you take the highest security and safety standards. The biggest mistake is to think you are safe just because you use a hardware wallet.
The security level should be increased to the highest level by adding a passphrase to the seed, or by using multiple signatures and most importantly, not putting all your eggs in one basket. It is very important to distribute assets across more than one wallet in anticipation of the worst-case scenario.
+Title: Re: We can all learn one or two from this ColdCard incident
+Post by: arwin100 on August 07, 2026, 02:23:58 PM
+Quote from: bitmover on August 06, 2026, 10:12:18 AM
+Quote from: X-ray on August 06, 2026, 03:23:13 AM
+I've used airgapped computers for my wallet for quite sometime, I don't find it any more riskier than hardware wallet. You installed latest OS to an airgapped computer, you never connect it to the Internet and the wallet stays on the computer.
First lines only. The complete diff is in the timeline below.
- Organisation
- BitcoinTalk
- Evidence role
- Community discussion
- Published
- 2026-08-03
- Source changes
- 7
- Detected differences
- 8
- Unreviewed
- 0
- Copies held
- 9
YellowSwap opening a lessons-learned thread on the Bitcoin Discussion board, drawing one of the longer forum discussions of the incident's takeaways for holders. A community response and sentiment record alongside bitcointalk-bright-side-opinion. The lessons and claims in the thread are the posters' own, not verified here.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The thread gained new posts by arwin100, Supreme Donvic and Dogedegen debating airgapped computers, diversification across wallets, and cracked operating systems.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 37 lines
Post by: yhiaali3 on August 07, 2026, 04:04:12 AM Yes, this incident taught us many lessons, the most important of which is that there is no complete security in crypto unless you take the highest security and safety standards. The biggest mistake is to think you are safe just because you use a hardware wallet. The security level should be increased to the highest level by adding a passphrase to the seed, or by using multiple signatures and most importantly, not putting all your eggs in one basket. It is very important to distribute assets across more than one wallet in anticipation of the worst-case scenario. +Title: Re: We can all learn one or two from this ColdCard incident +Post by: arwin100 on August 07, 2026, 02:23:58 PM +Quote from: bitmover on August 06, 2026, 10:12:18 AM +Quote from: X-ray on August 06, 2026, 03:23:13 AM +I've used airgapped computers for my wallet for quite sometime, I don't find it any more riskier than hardware wallet. You installed latest OS to an airgapped computer, you never connect it to the Internet and the wallet stays on the computer. +No supply chain attack which hardware wallet could be infected from, no accidental seed phrase leak because the internet isn't there in the first place, your wallet stay safe until the day you decided to withdraw it. I think it's robust enough solution for me, but it's just my opinion. +To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet. +There is a risk of supply chain attack, accidental seed phrase leak, everything. +The risk is exactly in the step you called a "pain to do". Setting it up. If you dont know exactly what you are doing, you can expose yourself to those risks +When you buy a good hardware wallet (not coldcard), you are theoretically free of all those risks. +Yeah that situation is really possible to happen. Usually the risk occur in crucial stage on which lots of people made a mistake when setting up their wallet. +Many of them exposed themselves on the risk especially if they don't know how to back up their verify, do back ups and know how to handle properly their seed phrase. +What people need to understand that those incidents didn't happen because the hardware wallet they are using is not safe. But rather they just made a mistake for not paying close attention following the guide. +Title: Re: We can all learn one or two from this ColdCard incident +Post by: Supreme Donvic on August 07, 2026, 03:27:01 PM +Quote from: KiaKia on August 01, 2026, 12:17:17 PM +The only lesson I learnt here is that nowhere is safe, putting all your eggs in one basket is totally wrong, as for that passphrase thing, hardware wallets are the only ones offering it? +If any mobile wallet has passphrase+ recovery seeds then there is really no reason to run after hardware wallets anymore, I am really disappointed in this ColdCard company and their team together. +Many people might never return to Bitcoin investment after this, there are people who have been holding and stacking Bitcoin since 2019 on that list of victims, someone whom I never thought would use ColdCard because I've never heard the name from him before. +I agree with you, nowhere is actually safe and it is wrong for someone to put his eggs in one basket. Many people have lost everything because they decided to put all their finance in one place. I can't be relaxed if all my money is just in one place, it is a very risky thing to do. Those that spread their Bitcoin are more safe. If you want to be safe spread your Bitcoin don't keep it in one place. +Sure, a lot of those that are affected will not return back to bitcoin investment, I believe 80% of those that we were affected will not talk about bitcoin investment ever again. Just like you have said, a lot of them that was affected has been accumulating Bitcoin since the creation of Bitcoin. The pain of losing everything will never allow them to come back to Bitcoin. +Title: Re: We can all learn one or two from this ColdCard incident +Post by: Dogedegen on August 07, 2026, 07:24:33 PM +Quote from: hd49728 on Today at 03:34:16 AM +Quote from: X-ray on Today at 01:24:02 AM +Setting it up, installing OS etc is easy, the hard part is exactly what you mentioned, keeping up with the exploit updates and verify that you got the right files. +People must avoid using cracked OS because it is very dangerous in security. If it's not feasible for them to buy it to use, they can consider to use open source OS like Linux. +https://linuxmint.com/ +This is true, but this is very rare so we must be careful what we write and how we write about it. There have been only a few times when this kind of case ended up in the news and this was mainly because the source of those cracked versions was not reputable, and if you think that there have been billions of installs of cracked OS and software the risk is very low. Actually the much higher risk comes from other attack vectors like malicious software, using very weak wallets like browser wallets as your main wallets and stuff like that. Anyway, using Windows as a primary OS for keeping cryptocurrency safe is very bad for both security and privacy and using a real license does not help with this. So you are very right to suggest Linux Mint, I have been using that and Ubuntu for a very long time and I have never had any issues of any kind when it comes to security. Simply by switching to such an OS the risk of a hack decreases considerably! +Quote from: Supreme Donvic on Today at 03:27:01 PM +Quote from: KiaKia on August 01, 2026, 12:17:17 PM +The only lesson I learnt here is that nowhere is safe, putting all your eggs in one basket is totally wrong, as for that passphrase thing, hardware wallets are the only ones offering it? +If any mobile wallet has passphrase+ recovery seeds then there is really no reason to run after hardware wallets anymore, I am really disappointed in this ColdCard company and their team together. +Many people might never return to Bitcoin investment after this, there are people who have been holding and stacking Bitcoin since 2019 on that list of victims, someone whom I never thought would use ColdCard because I've never heard the name from him before. +I agree with you, nowhere is actually safe and it is wrong for someone to put his eggs in one basket. Many people have lost everything because they decided to put all their finance in one place. I can't be relaxed if all my money is just in one place, it is a very risky thing to do. Those that spread their Bitcoin are more safe. If you want to be safe spread your Bitcoin don't keep it in one place. +Sure, a lot of those that are affected will not return back to bitcoin investment, I believe 80% of those that we were affected will not talk about bitcoin investment ever again. Just like you have said, a lot of them that was affected has been accumulating Bitcoin since the creation of Bitcoin. The pain of losing everything will never allow them to come back to Bitcoin. +This is also not the right advice, because the right advice is always about the balance. Somebody has a single basket that is more secure than somebody's 10 baskets combined. It depends on the situation, the setup and the actual need. There is a breaking point after which adding more baskets does not increase security, it reduces your security because of the complexity involved. Always be reasonable and try to find some kind of middle point when it comes to questions of security. Powered by SMF 1.1.19 | SMF © 2006-2009, Simple MachinesExtracted text as captured
Bitcoin Forum Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM Title: We can all learn one or two from this ColdCard incident Post by: YellowSwap on August 01, 2026, 08:19:47 AM I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator). This should not in anyway makes you look less on hardware wallets still. The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices. If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day. This kind of incidents rarely happens with hardware wallet but it's the case with software wallets. It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids. https://talkimg.com/images/2026/08/01/UomI9C.jpg The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. - let's start considering multisig if possible. - let's start considering the Dice 🎲 rolling method for entropy While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this. Title: Re: We can all learn one or two from this ColdCard incident Post by: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - Title: Re: We can all learn one or two from this ColdCard incident Post by: Crypto Library on August 01, 2026, 10:19:36 AM Quote from: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet. I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there. And this new incident is already what we can see so far, about 1128.47 which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47¤cy=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection. Title: Re: We can all learn one or two from this ColdCard incident Post by: MusaMohamed on August 01, 2026, 10:29:57 AM Quote from: YellowSwap on August 01, 2026, 08:19:47 AM The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets. You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet. Quote - let's start considering multisig if possible. It's right but multisig wallet will cost you more in transaction fees.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Three new posts (X-ray on verification and watch-only workflows, hd49728 linking Electrum and Bitcoin Core verification guides, yhiaali3 on passphrases and distributing assets). The diff also contains SMF "Today at" relative-date rollover, which is presentation noise.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 41 lines
To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet. Title: Re: We can all learn one or two from this ColdCard incident Post by: Outhue on August 06, 2026, 07:35:59 AM -Quote from: X-ray on Today at 03:23:13 AM +Quote from: X-ray on August 06, 2026, 03:23:13 AM Quote from: PostQuantumBTC on August 02, 2026, 12:36:35 AM Quote from: bitmover on August 01, 2026, 04:59:06 PM Airgapped computers are risky to setup and use. Also airgapped devices comes with extra security, if anyone tries to tamper with em they can self wiped themselves, talking for Keystone wallet though, I don't know about the rest, but if someone wants to tampered with that PC or Laptop behind your back they would successfully do it, but like I've just said, if you can handle it right then no problem, only that it's not for everyone. Title: Re: We can all learn one or two from this ColdCard incident Post by: PostQuantumBTC on August 06, 2026, 09:13:25 AM -Quote from: X-ray on Today at 03:23:13 AM +Quote from: X-ray on August 06, 2026, 03:23:13 AM To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet. I do not see any difficulty in setting up a wallet on an airgapped device, it was simple for me to do. Another thing is that if you are also not updated with exploit updates and knowing how to avoid hackers, hardware wallet can not save your coins from the hackers. Hackers also target hardware wallet users specifically. Title: Re: We can all learn one or two from this ColdCard incident Post by: bitmover on August 06, 2026, 10:12:18 AM -Quote from: X-ray on Today at 03:23:13 AM +Quote from: X-ray on August 06, 2026, 03:23:13 AM Quote from: PostQuantumBTC on August 02, 2026, 12:36:35 AM Quote from: bitmover on August 01, 2026, 04:59:06 PM Airgapped computers are risky to setup and use. When you buy a good hardware wallet (not coldcard), you are theoretically free of all those risks. Title: Re: We can all learn one or two from this ColdCard incident Post by: Z-tight on August 06, 2026, 05:14:28 PM -Quote from: X-ray on Today at 03:23:13 AM +Quote from: X-ray on August 06, 2026, 03:23:13 AM To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet. Setting up a wallet in an airgapped device is not so newbie-friendly, that's why the community recommends hardware wallets to newbies, as it is easier for them to use safely. An airgapped wallet has to be set up in a safe environment and you ought to know what you are doing, so you don't lock yourself out of your funds. However, if you are using a recommended wallet software, you do not need to constantly verify anything. E.G., if you set up Electrum in an airgapped device, which is a well-reviewed wallet, then you're good if you do everything correctly locally. Title: Re: We can all learn one or two from this ColdCard incident Post by: I_Anime on August 06, 2026, 07:34:03 PM Hardware wallet is the best to store your assets but don�t make it 100% safe there�s nothing like 100% when come to the crypto space. Hardware wallet has its own disadvantages too , like sometimes physical effects can damage it , like fire, water or you lose it (but can be recover if you have your seed phrase well save). And for those that are too lazy to write down their seed phrase and keep to a place safe and accessible, start writing it down now and stop saving it in your device just writing it down will save you a fortune . +Title: Re: We can all learn one or two from this ColdCard incident +Post by: X-ray on August 07, 2026, 01:24:02 AM +Quote from: PostQuantumBTC on August 06, 2026, 09:13:25 AM +I do not see any difficulty in setting up a wallet on an airgapped device, it was simple for me to do. Another thing is that if you are also not updated with exploit updates and knowing how to avoid hackers, hardware wallet can not save your coins from the hackers. Hackers also target hardware wallet users specifically. +Setting it up, installing OS etc is easy, the hard part is exactly what you mentioned, keeping up with the exploit updates and verify that you got the right files. +You need to verify authenticity with checksums for all the software you're going to install and search for latest exploit to make sure you're not installing vulnerable version. +If you want to be able to spend from the wallet inside airgapped computer, you also need to set up watch only wallet to create unsigned tx, sign it on your airgapped computer, then send it back again. If you've got time to do that, it is doable but honestly you almost certainly will crave for a simpler method but also secure which is hardware wallet. +Quote from: Z-tight on August 06, 2026, 05:14:28 PM +Setting up a wallet in an airgapped device is not so newbie-friendly, that's why the community recommends hardware wallets to newbies, as it is easier for them to use safely. An airgapped wallet has to be set up in a safe environment and you ought to know what you are doing, so you don't lock yourself out of your funds. +However, if you are using a recommended wallet software, you do not need to constantly verify anything. E.G., if you set up Electrum in an airgapped device, which is a well-reviewed wallet, then you're good if you do everything correctly locally. +Exactly and the price if compared to buying a brand new hardware wallet, almost roughly the same if you don't have old laptops lying around, even then old laptop might have security flaw on its old hardware. +Title: Re: We can all learn one or two from this ColdCard incident +Post by: hd49728 on August 07, 2026, 03:34:16 AM +Quote from: X-ray on Today at 01:24:02 AM +Setting it up, installing OS etc is easy, the hard part is exactly what you mentioned, keeping up with the exploit updates and verify that you got the right files. +People must avoid using cracked OS because it is very dangerous in security. If it's not feasible for them to buy it to use, they can consider to use open source OS like Linux. +https://linuxmint.com/ +Quote +You need to verify authenticity with checksums for all the software you're going to install and search for latest exploit to make sure you're not installing vulnerable version. +For examples, there are guides to verify Bitcoin Core software and Electrum wallet software. +[GUIDE] How to Safely Download and Verify Electrum. (https://bitcointalk.org/index.php?topic=5240594.0) +The paranoid user's security guide for using Electrum safely. (https://bitcointalk.org/index.php?topic=5456886.0) +Bitcoin Core download and verification guide. (https://bitcoincore.org/en/download/) +Quote +If you want to be able to spend from the wallet inside airgapped computer, you also need to set up watch only wallet to create unsigned tx, sign it on your airgapped computer, then send it back again. If you've got time to do that, it is doable but honestly you almost certainly will crave for a simpler method but also secure which is hardware wallet. +This guide +How to create a cold storage wallet in Electrum. (https://bitcoinelectrum.com/creating-a-cold-storage-wallet-in-electrum/) +Not all people understand correctly about air-gapped devices and necessary steps to have an air-gapped device. Physical items that can connect the device to Internet need to be removed all. +[Guide] Secure air-gapped crypto wallet storage method. (https://bitcointalk.org/index.php?topic=2828437.0) +Title: Re: We can all learn one or two from this ColdCard incident +Post by: yhiaali3 on August 07, 2026, 04:04:12 AM +Yes, this incident taught us many lessons, the most important of which is that there is no complete security in crypto unless you take the highest security and safety standards. The biggest mistake is to think you are safe just because you use a hardware wallet. +The security level should be increased to the highest level by adding a passphrase to the seed, or by using multiple signatures and most importantly, not putting all your eggs in one basket. It is very important to distribute assets across more than one wallet in anticipation of the worst-case scenario. Powered by SMF 1.1.19 | SMF © 2006-2009, Simple MachinesExtracted text as captured
Bitcoin Forum Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM Title: We can all learn one or two from this ColdCard incident Post by: YellowSwap on August 01, 2026, 08:19:47 AM I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator). This should not in anyway makes you look less on hardware wallets still. The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices. If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day. This kind of incidents rarely happens with hardware wallet but it's the case with software wallets. It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids. https://talkimg.com/images/2026/08/01/UomI9C.jpg The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. - let's start considering multisig if possible. - let's start considering the Dice 🎲 rolling method for entropy While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this. Title: Re: We can all learn one or two from this ColdCard incident Post by: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - Title: Re: We can all learn one or two from this ColdCard incident Post by: Crypto Library on August 01, 2026, 10:19:36 AM Quote from: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet. I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there. And this new incident is already what we can see so far, about 1128.47 which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47¤cy=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection. Title: Re: We can all learn one or two from this ColdCard incident Post by: MusaMohamed on August 01, 2026, 10:29:57 AM Quote from: YellowSwap on August 01, 2026, 08:19:47 AM The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets. You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet. Quote - let's start considering multisig if possible. It's right but multisig wallet will cost you more in transaction fees.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Two new posts: Z-tight on airgapped wallets not being newbie-friendly, and I_Anime advising users to write down seed phrases and not rely on hardware wallets being 100 percent safe.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 9 lines
There is a risk of supply chain attack, accidental seed phrase leak, everything. The risk is exactly in the step you called a "pain to do". Setting it up. If you dont know exactly what you are doing, you can expose yourself to those risks When you buy a good hardware wallet (not coldcard), you are theoretically free of all those risks. +Title: Re: We can all learn one or two from this ColdCard incident +Post by: Z-tight on August 06, 2026, 05:14:28 PM +Quote from: X-ray on Today at 03:23:13 AM +To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet. +Setting up a wallet in an airgapped device is not so newbie-friendly, that's why the community recommends hardware wallets to newbies, as it is easier for them to use safely. An airgapped wallet has to be set up in a safe environment and you ought to know what you are doing, so you don't lock yourself out of your funds. +However, if you are using a recommended wallet software, you do not need to constantly verify anything. E.G., if you set up Electrum in an airgapped device, which is a well-reviewed wallet, then you're good if you do everything correctly locally. +Title: Re: We can all learn one or two from this ColdCard incident +Post by: I_Anime on August 06, 2026, 07:34:03 PM +Hardware wallet is the best to store your assets but don�t make it 100% safe there�s nothing like 100% when come to the crypto space. Hardware wallet has its own disadvantages too , like sometimes physical effects can damage it , like fire, water or you lose it (but can be recover if you have your seed phrase well save). And for those that are too lazy to write down their seed phrase and keep to a place safe and accessible, start writing it down now and stop saving it in your device just writing it down will save you a fortune . Powered by SMF 1.1.19 | SMF © 2006-2009, Simple MachinesExtracted text as captured
Bitcoin Forum Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM Title: We can all learn one or two from this ColdCard incident Post by: YellowSwap on August 01, 2026, 08:19:47 AM I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator). This should not in anyway makes you look less on hardware wallets still. The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices. If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day. This kind of incidents rarely happens with hardware wallet but it's the case with software wallets. It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids. https://talkimg.com/images/2026/08/01/UomI9C.jpg The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. - let's start considering multisig if possible. - let's start considering the Dice 🎲 rolling method for entropy While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this. Title: Re: We can all learn one or two from this ColdCard incident Post by: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - Title: Re: We can all learn one or two from this ColdCard incident Post by: Crypto Library on August 01, 2026, 10:19:36 AM Quote from: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet. I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there. And this new incident is already what we can see so far, about 1128.47 which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47¤cy=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection. Title: Re: We can all learn one or two from this ColdCard incident Post by: MusaMohamed on August 01, 2026, 10:29:57 AM Quote from: YellowSwap on August 01, 2026, 08:19:47 AM The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets. You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet. Quote - let's start considering multisig if possible. It's right but multisig wallet will cost you more in transaction fees.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
One new post by bitmover arguing the risk of airgapped setups lies in the setup step itself, and that a good hardware wallet ("not coldcard") is theoretically free of those risks.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 15 lines
Quote from: X-ray on Today at 03:23:13 AM To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet. I do not see any difficulty in setting up a wallet on an airgapped device, it was simple for me to do. Another thing is that if you are also not updated with exploit updates and knowing how to avoid hackers, hardware wallet can not save your coins from the hackers. Hackers also target hardware wallet users specifically. +Title: Re: We can all learn one or two from this ColdCard incident +Post by: bitmover on August 06, 2026, 10:12:18 AM +Quote from: X-ray on Today at 03:23:13 AM +Quote from: PostQuantumBTC on August 02, 2026, 12:36:35 AM +Quote from: bitmover on August 01, 2026, 04:59:06 PM +Airgapped computers are risky to setup and use. +How is it risky? +Airgapped computers means you are not sending anything out of the wallet in a way that you can be affected. If you have airgapped wallet, you are safe so far it stayed airgapped but stay away from crypto clipper. +But I will likely if you correct me because my understanding about the cold airgapped device may be limited. +I've used airgapped computers for my wallet for quite sometime, I don't find it any more riskier than hardware wallet. You installed latest OS to an airgapped computer, you never connect it to the Internet and the wallet stays on the computer. +No supply chain attack which hardware wallet could be infected from, no accidental seed phrase leak because the internet isn't there in the first place, your wallet stay safe until the day you decided to withdraw it. I think it's robust enough solution for me, but it's just my opinion. +To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet. +There is a risk of supply chain attack, accidental seed phrase leak, everything. +The risk is exactly in the step you called a "pain to do". Setting it up. If you dont know exactly what you are doing, you can expose yourself to those risks +When you buy a good hardware wallet (not coldcard), you are theoretically free of all those risks. Powered by SMF 1.1.19 | SMF © 2006-2009, Simple MachinesExtracted text as captured
Bitcoin Forum Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM Title: We can all learn one or two from this ColdCard incident Post by: YellowSwap on August 01, 2026, 08:19:47 AM I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator). This should not in anyway makes you look less on hardware wallets still. The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices. If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day. This kind of incidents rarely happens with hardware wallet but it's the case with software wallets. It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids. https://talkimg.com/images/2026/08/01/UomI9C.jpg The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. - let's start considering multisig if possible. - let's start considering the Dice 🎲 rolling method for entropy While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this. Title: Re: We can all learn one or two from this ColdCard incident Post by: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - Title: Re: We can all learn one or two from this ColdCard incident Post by: Crypto Library on August 01, 2026, 10:19:36 AM Quote from: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet. I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there. And this new incident is already what we can see so far, about 1128.47 which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47¤cy=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection. Title: Re: We can all learn one or two from this ColdCard incident Post by: MusaMohamed on August 01, 2026, 10:29:57 AM Quote from: YellowSwap on August 01, 2026, 08:19:47 AM The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets. You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet. Quote - let's start considering multisig if possible. It's right but multisig wallet will cost you more in transaction fees.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Two new posts: Outhue on airgapped-computer setups not suiting people who do not live alone, and PostQuantumBTC saying airgapped setup is simple and hardware wallet users are specifically targeted.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 19 lines
I've used airgapped computers for my wallet for quite sometime, I don't find it any more riskier than hardware wallet. You installed latest OS to an airgapped computer, you never connect it to the Internet and the wallet stays on the computer. No supply chain attack which hardware wallet could be infected from, no accidental seed phrase leak because the internet isn't there in the first place, your wallet stay safe until the day you decided to withdraw it. I think it's robust enough solution for me, but it's just my opinion. To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet. +Title: Re: We can all learn one or two from this ColdCard incident +Post by: Outhue on August 06, 2026, 07:35:59 AM +Quote from: X-ray on Today at 03:23:13 AM +Quote from: PostQuantumBTC on August 02, 2026, 12:36:35 AM +Quote from: bitmover on August 01, 2026, 04:59:06 PM +Airgapped computers are risky to setup and use. +How is it risky? +Airgapped computers means you are not sending anything out of the wallet in a way that you can be affected. If you have airgapped wallet, you are safe so far it stayed airgapped but stay away from crypto clipper. +But I will likely if you correct me because my understanding about the cold airgapped device may be limited. +I've used airgapped computers for my wallet for quite sometime, I don't find it any more riskier than hardware wallet. You installed latest OS to an airgapped computer, you never connect it to the Internet and the wallet stays on the computer. +No supply chain attack which hardware wallet could be infected from, no accidental seed phrase leak because the internet isn't there in the first place, your wallet stay safe until the day you decided to withdraw it. I think it's robust enough solution for me, but it's just my opinion. +To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet. +Let's say that you can handle this perfectly, I am not new to Bitcoin but I can't do this same thing that you are doing, because of few reasons like I am not living alone, my computer isn't private and others, you can go out and someone startup your computer and connect it to the internet, unless you live alone all by yourself. +Also airgapped devices comes with extra security, if anyone tries to tamper with em they can self wiped themselves, talking for Keystone wallet though, I don't know about the rest, but if someone wants to tampered with that PC or Laptop behind your back they would successfully do it, but like I've just said, if you can handle it right then no problem, only that it's not for everyone. +Title: Re: We can all learn one or two from this ColdCard incident +Post by: PostQuantumBTC on August 06, 2026, 09:13:25 AM +Quote from: X-ray on Today at 03:23:13 AM +To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet. +I do not see any difficulty in setting up a wallet on an airgapped device, it was simple for me to do. Another thing is that if you are also not updated with exploit updates and knowing how to avoid hackers, hardware wallet can not save your coins from the hackers. Hackers also target hardware wallet users specifically. Powered by SMF 1.1.19 | SMF © 2006-2009, Simple MachinesExtracted text as captured
Bitcoin Forum Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM Title: We can all learn one or two from this ColdCard incident Post by: YellowSwap on August 01, 2026, 08:19:47 AM I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator). This should not in anyway makes you look less on hardware wallets still. The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices. If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day. This kind of incidents rarely happens with hardware wallet but it's the case with software wallets. It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids. https://talkimg.com/images/2026/08/01/UomI9C.jpg The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. - let's start considering multisig if possible. - let's start considering the Dice 🎲 rolling method for entropy While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this. Title: Re: We can all learn one or two from this ColdCard incident Post by: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - Title: Re: We can all learn one or two from this ColdCard incident Post by: Crypto Library on August 01, 2026, 10:19:36 AM Quote from: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet. I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there. And this new incident is already what we can see so far, about 1128.47 which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47¤cy=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection. Title: Re: We can all learn one or two from this ColdCard incident Post by: MusaMohamed on August 01, 2026, 10:29:57 AM Quote from: YellowSwap on August 01, 2026, 08:19:47 AM The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets. You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet. Quote - let's start considering multisig if possible. It's right but multisig wallet will cost you more in transaction fees.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
A participant added a discussion of using an air-gapped computer, describing its perceived benefits and setup burden.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 11 lines
It is just to be better equipped with better security knowledge than to try to play it safe and still have loopholes that can be manipulated anytime. We have learnt a great deal from this coldcard incident and I must say I may try on my own to explore safer options that includes security features and diversity strategies Incase a similar or new kind of coldcard issue arises again. You are correct to point this out but I don't think it is reasonable to expect normal users to know these kinds of things. Maybe when we were promoting hardware wallets as the best solutions to the general public we have together made a mistake by not sharing the issues that could happen with it. I have had these wallets for years, and I consider myself a bit more security conscious than the average person but nothing special. I have never considered that my wallet could be hacked this way even if it was a very obvious possibility, I have considered all kinds of offline hacks, attacks by the vendor or through the internet but not a complete failure in the random generation where you are defenseless if you have set up the wallet the right way. I also don't think the regular advice was ever that you should in all cases add a passphrase to a hardware wallet, it was suggested only in some specific cases to deal with some sort of attacks or to add more protection. I think one lesson from this would be that adding passphrases to wallets should be a regular thing, and it does not even have to be extremely long but it would provide you enough time to survive the first wave attacks and get your keys out before some kind of brute force attack is successful against it. +Title: Re: We can all learn one or two from this ColdCard incident +Post by: X-ray on August 06, 2026, 03:23:13 AM +Quote from: PostQuantumBTC on August 02, 2026, 12:36:35 AM +Quote from: bitmover on August 01, 2026, 04:59:06 PM +Airgapped computers are risky to setup and use. +How is it risky? +Airgapped computers means you are not sending anything out of the wallet in a way that you can be affected. If you have airgapped wallet, you are safe so far it stayed airgapped but stay away from crypto clipper. +But I will likely if you correct me because my understanding about the cold airgapped device may be limited. +I've used airgapped computers for my wallet for quite sometime, I don't find it any more riskier than hardware wallet. You installed latest OS to an airgapped computer, you never connect it to the Internet and the wallet stays on the computer. +No supply chain attack which hardware wallet could be infected from, no accidental seed phrase leak because the internet isn't there in the first place, your wallet stay safe until the day you decided to withdraw it. I think it's robust enough solution for me, but it's just my opinion. +To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet. Powered by SMF 1.1.19 | SMF © 2006-2009, Simple MachinesExtracted text as captured
Bitcoin Forum Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM Title: We can all learn one or two from this ColdCard incident Post by: YellowSwap on August 01, 2026, 08:19:47 AM I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator). This should not in anyway makes you look less on hardware wallets still. The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices. If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day. This kind of incidents rarely happens with hardware wallet but it's the case with software wallets. It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids. https://talkimg.com/images/2026/08/01/UomI9C.jpg The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. - let's start considering multisig if possible. - let's start considering the Dice 🎲 rolling method for entropy While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this. Title: Re: We can all learn one or two from this ColdCard incident Post by: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - Title: Re: We can all learn one or two from this ColdCard incident Post by: Crypto Library on August 01, 2026, 10:19:36 AM Quote from: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet. I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there. And this new incident is already what we can see so far, about 1128.47 which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47¤cy=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection. Title: Re: We can all learn one or two from this ColdCard incident Post by: MusaMohamed on August 01, 2026, 10:29:57 AM Quote from: YellowSwap on August 01, 2026, 08:19:47 AM The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets. You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet. Quote - let's start considering multisig if possible. It's right but multisig wallet will cost you more in transaction fees.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The BitcoinTalk thread gained a post arguing ordinary users cannot reasonably be expected to anticipate this attack class.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 6 lines
Post by: dansus021 on August 04, 2026, 09:19:52 AM Hardware wallets are still vastly superior to keeping funds on internet-connected phones or computers, but the ColdCard RNG issue proves that relying on a single device, vendor, or internal generator leaves a single point of failure. In my opinion the best takeaway for anyone serious about security is to take entropy into your own hands by rolling physical dice, adding a strong BIP-39 passphrase, and moving toward a multi-vendor multisig setup so a single software or firmware bug never puts your entire stack at risk. Combine keys from two or three different hardware manufacturers Even if one hardware manufacturer ships flawed firmware or a compromised RNG, an attacker holding a single compromised key cannot spend your funds without a second signature from an unaffected device made by a completely different team. +Title: Re: We can all learn one or two from this ColdCard incident +Post by: Dogedegen on August 04, 2026, 07:22:08 PM +Quote from: Cryptomultiplier on August 03, 2026, 09:25:09 PM +It is just to be better equipped with better security knowledge than to try to play it safe and still have loopholes that can be manipulated anytime. +We have learnt a great deal from this coldcard incident and I must say I may try on my own to explore safer options that includes security features and diversity strategies Incase a similar or new kind of coldcard issue arises again. +You are correct to point this out but I don't think it is reasonable to expect normal users to know these kinds of things. Maybe when we were promoting hardware wallets as the best solutions to the general public we have together made a mistake by not sharing the issues that could happen with it. I have had these wallets for years, and I consider myself a bit more security conscious than the average person but nothing special. I have never considered that my wallet could be hacked this way even if it was a very obvious possibility, I have considered all kinds of offline hacks, attacks by the vendor or through the internet but not a complete failure in the random generation where you are defenseless if you have set up the wallet the right way. I also don't think the regular advice was ever that you should in all cases add a passphrase to a hardware wallet, it was suggested only in some specific cases to deal with some sort of attacks or to add more protection. I think one lesson from this would be that adding passphrases to wallets should be a regular thing, and it does not even have to be extremely long but it would provide you enough time to survive the first wave attacks and get your keys out before some kind of brute force attack is successful against it. Powered by SMF 1.1.19 | SMF © 2006-2009, Simple MachinesExtracted text as captured
Bitcoin Forum Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM Title: We can all learn one or two from this ColdCard incident Post by: YellowSwap on August 01, 2026, 08:19:47 AM I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator). This should not in anyway makes you look less on hardware wallets still. The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices. If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day. This kind of incidents rarely happens with hardware wallet but it's the case with software wallets. It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids. https://talkimg.com/images/2026/08/01/UomI9C.jpg The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. - let's start considering multisig if possible. - let's start considering the Dice 🎲 rolling method for entropy While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this. Title: Re: We can all learn one or two from this ColdCard incident Post by: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - Title: Re: We can all learn one or two from this ColdCard incident Post by: Crypto Library on August 01, 2026, 10:19:36 AM Quote from: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet. I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there. And this new incident is already what we can see so far, about 1128.47 which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47¤cy=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection. Title: Re: We can all learn one or two from this ColdCard incident Post by: MusaMohamed on August 01, 2026, 10:29:57 AM Quote from: YellowSwap on August 01, 2026, 08:19:47 AM The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets. You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet. Quote - let's start considering multisig if possible. It's right but multisig wallet will cost you more in transaction fees.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
Bitcoin Forum Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM Title: We can all learn one or two from this ColdCard incident Post by: YellowSwap on August 01, 2026, 08:19:47 AM I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator). This should not in anyway makes you look less on hardware wallets still. The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices. If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day. This kind of incidents rarely happens with hardware wallet but it's the case with software wallets. It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids. https://talkimg.com/images/2026/08/01/UomI9C.jpg The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. - let's start considering multisig if possible. - let's start considering the Dice 🎲 rolling method for entropy While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this. Title: Re: We can all learn one or two from this ColdCard incident Post by: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - Title: Re: We can all learn one or two from this ColdCard incident Post by: Crypto Library on August 01, 2026, 10:19:36 AM Quote from: un_rank on August 01, 2026, 09:21:12 AM If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet. What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years. - Jay - I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet. I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there. And this new incident is already what we can see so far, about 1128.47 which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47¤cy=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection. Title: Re: We can all learn one or two from this ColdCard incident Post by: MusaMohamed on August 01, 2026, 10:29:57 AM Quote from: YellowSwap on August 01, 2026, 08:19:47 AM The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets. - let's start considering passphrase with recovery seeds. It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets. You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet. Quote - let's start considering multisig if possible. It's right but multisig wallet will cost you more in transaction fees.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
1 presentation-noise difference. Sidebar, ticker and other page chrome churn that our review classified as not being a change to what the source says.
- +4 -4 Only Bitcointalk's relative quote dates rolled from Today to absolute dates.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.