r/Bitcoin: speculation on why the attacker struck when they did
reddit-attack-timing-speculation
https://www.reddit.com/r/Bitcoin/comments/1vetc6x/the_timing_of_it_all/
Latest reviewed change
source content difference between and
Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.
edited: false
body:
A basic pre-AI code scan should have detected the badly implemented flag. A normal warning should have made this visible.
+
+comment: p1zzeaq
+parent: t1_p1ludcg
+author: CBpegasus
+created_utc: 1785991523
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 10
- Detected differences
- 10
- Unreviewed
- 0
- Copies held
- 11
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 14 lines
edited: false body: A basic pre-AI code scan should have detected the badly implemented flag. A normal warning should have made this visible. + +comment: p1zzeaq +parent: t1_p1ludcg +author: CBpegasus +created_utc: 1785991523 +edited: false +body: +No evidence they "knew about the vuln". James O'Beirne claims he warned them of a potential risk in 2025, that they did shrug off. If he's telling the truth, that's far from the best way to act as a security-based company. But getting warning of a potential risk is far from "knowing about the vuln". + +Shrugging off potential risk can be simple incompetence (and belief in their own competence - kind of Dunning-Kruger maybe). Shrugging off a known vuln is maliciousness. + +It might change as more info is uncovered, but I still tend to think the whole thing can (and therefore should, by Hanlon's Razor) be attributed to incompetence rather than maliciousness. There are a lot of weird points in the story if we assume maliciousness IMO. The bug itself is almost too simple as a backdoor, and since it was on the public code anyone else could have found it. One might say it's for "plausible deniability" but I think that's more risk than a malicious actor is likely to take for that. + +Assuming incompetence does require multiple points of failures and arrogance on the part of CoinKite - but it's similar to things I've seen as a former security researcher. It can and does happen.Extracted text as captured
post: 1vetc6x author: corporate-citizen created_utc: 1785799180 title: The timing of it all body: *The Coldcard RNG/low entropy issue has been known about by the stealer since a few weeks to months after the code was released in Nov 2021.* *They waited years so that as many people as possible would generate seeds on that faulty firmware and send bitcoin to addresses derived from those private keys.* *Something caused them to strike and take it all now. Bottom of bear market. BIP-110. Clarity Act. Something triggered them to steal and cause the FUD right now.* Source: [https://x.com/hodlonaut/status/2084217381165940812?s=46](https://x.com/hodlonaut/status/2084217381165940812?s=46) comment: p1jtsnc parent: t3_1vetc6x author: Optionbulls created_utc: 1785800816 edited: false body: Could be comment: p1jutqv parent: t3_1vetc6x author: Left_Entrepreneur918 created_utc: 1785801149 edited: false body: Get Rich and burn their old employer to the ground? Hmmmm comment: p1jx8y2 parent: t3_1vetc6x author: Doritos707 created_utc: 1785801942 edited: false body: Either that or somebody used ai and caught wind before patching became available comment: p1jxh39 parent: t3_1vetc6xExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
That way you could target way more wallets. The day they wants to execute the transfer, they already got a list of private keys. I also find it hard to believe someone finding this bug would wait 5 years. + +comment: p1tz1ui +parent: t1_p1k6e9c +author: Archophob +created_utc: 1785927902 +edited: false +body: +>I don’t think a criminal act like this would need AI. + +no, but AI makes it easy for any script kiddy out there to find the same bug and move the coins before you do. + +comment: p1utsu1 +parent: t1_p1k3ybm +author: Javanaut018 +created_utc: 1785937844 +edited: false +body: +A basic pre-AI code scan should have detected the badly implemented flag. A normal warning should have made this visible.Extracted text as captured
post: 1vetc6x author: corporate-citizen created_utc: 1785799180 title: The timing of it all body: *The Coldcard RNG/low entropy issue has been known about by the stealer since a few weeks to months after the code was released in Nov 2021.* *They waited years so that as many people as possible would generate seeds on that faulty firmware and send bitcoin to addresses derived from those private keys.* *Something caused them to strike and take it all now. Bottom of bear market. BIP-110. Clarity Act. Something triggered them to steal and cause the FUD right now.* Source: [https://x.com/hodlonaut/status/2084217381165940812?s=46](https://x.com/hodlonaut/status/2084217381165940812?s=46) comment: p1jtsnc parent: t3_1vetc6x author: Optionbulls created_utc: 1785800816 edited: false body: Could be comment: p1jutqv parent: t3_1vetc6x author: Left_Entrepreneur918 created_utc: 1785801149 edited: false body: Get Rich and burn their old employer to the ground? Hmmmm comment: p1jx8y2 parent: t3_1vetc6x author: Doritos707 created_utc: 1785801942 edited: false body: Either that or somebody used ai and caught wind before patching became available comment: p1jxh39 parent: t3_1vetc6xExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 19 lines
edited: false body: I think the thing people are missing is - what does fixing the vulnerability even look like? So they fix the code and have to announce to everyone “hey if you generated a key with the old code you have to move all your coins now!” Just alerting bad actors. That is better than doing nothing (they still would have been raked through the coals), I don’t see any world where this ended nicely. In all honesty if they knew about it after selling thousands of cold cards with that version of firmware they probably would have quietly dismantled the company before it blew up in their faces. + +comment: p1suw17 +parent: t3_1vetc6x +author: Crcex86 +created_utc: 1785909153 +edited: false +body: +If that's true, they were extremely patient and cool, because the exploit could have been resolved easily at any time. + +comment: p1t82tj +parent: t3_1vetc6x +author: Laukess +created_utc: 1785915393 +edited: false +body: +If you had known about this bug for 5 years, why not use the time to find exposed keys? +That way you could target way more wallets. +The day they wants to execute the transfer, they already got a list of private keys. +I also find it hard to believe someone finding this bug would wait 5 years.Extracted text as captured
post: 1vetc6x author: corporate-citizen created_utc: 1785799180 title: The timing of it all body: *The Coldcard RNG/low entropy issue has been known about by the stealer since a few weeks to months after the code was released in Nov 2021.* *They waited years so that as many people as possible would generate seeds on that faulty firmware and send bitcoin to addresses derived from those private keys.* *Something caused them to strike and take it all now. Bottom of bear market. BIP-110. Clarity Act. Something triggered them to steal and cause the FUD right now.* Source: [https://x.com/hodlonaut/status/2084217381165940812?s=46](https://x.com/hodlonaut/status/2084217381165940812?s=46) comment: p1jtsnc parent: t3_1vetc6x author: Optionbulls created_utc: 1785800816 edited: false body: Could be comment: p1jutqv parent: t3_1vetc6x author: Left_Entrepreneur918 created_utc: 1785801149 edited: false body: Get Rich and burn their old employer to the ground? Hmmmm comment: p1jx8y2 parent: t3_1vetc6x author: Doritos707 created_utc: 1785801942 edited: false body: Either that or somebody used ai and caught wind before patching became available comment: p1jxh39 parent: t3_1vetc6xExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment about the difficulty of disclosing and fixing the vulnerability.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Disgruntled ex-employee probably did this then. Burn baby burn! + +comment: p1qceb6 +parent: t1_p1lng0b +author: Sproutlee_Dev +created_utc: 1785878445 +edited: false +body: +I think the thing people are missing is - what does fixing the vulnerability even look like? So they fix the code and have to announce to everyone “hey if you generated a key with the old code you have to move all your coins now!” Just alerting bad actors. That is better than doing nothing (they still would have been raked through the coals), I don’t see any world where this ended nicely. In all honesty if they knew about it after selling thousands of cold cards with that version of firmware they probably would have quietly dismantled the company before it blew up in their faces.Extracted text as captured
post: 1vetc6x author: corporate-citizen created_utc: 1785799180 title: The timing of it all body: *The Coldcard RNG/low entropy issue has been known about by the stealer since a few weeks to months after the code was released in Nov 2021.* *They waited years so that as many people as possible would generate seeds on that faulty firmware and send bitcoin to addresses derived from those private keys.* *Something caused them to strike and take it all now. Bottom of bear market. BIP-110. Clarity Act. Something triggered them to steal and cause the FUD right now.* Source: [https://x.com/hodlonaut/status/2084217381165940812?s=46](https://x.com/hodlonaut/status/2084217381165940812?s=46) comment: p1jtsnc parent: t3_1vetc6x author: Optionbulls created_utc: 1785800816 edited: false body: Could be comment: p1jutqv parent: t3_1vetc6x author: Left_Entrepreneur918 created_utc: 1785801149 edited: false body: Get Rich and burn their old employer to the ground? Hmmmm comment: p1jx8y2 parent: t3_1vetc6x author: Doritos707 created_utc: 1785801942 edited: false body: Either that or somebody used ai and caught wind before patching became available comment: p1jxh39 parent: t3_1vetc6xExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, by VeryThicknLong, speculating about a disgruntled former employee.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Indeed I did. I had just read about a theory that the timing was due to recent advancements in AI. + +comment: p1o75hj +parent: t3_1vetc6x +author: VeryThicknLong +created_utc: 1785858716 +edited: false +body: +Disgruntled ex-employee probably did this then. Burn baby burn!Extracted text as captured
post: 1vetc6x author: corporate-citizen created_utc: 1785799180 title: The timing of it all body: *The Coldcard RNG/low entropy issue has been known about by the stealer since a few weeks to months after the code was released in Nov 2021.* *They waited years so that as many people as possible would generate seeds on that faulty firmware and send bitcoin to addresses derived from those private keys.* *Something caused them to strike and take it all now. Bottom of bear market. BIP-110. Clarity Act. Something triggered them to steal and cause the FUD right now.* Source: [https://x.com/hodlonaut/status/2084217381165940812?s=46](https://x.com/hodlonaut/status/2084217381165940812?s=46) comment: p1jtsnc parent: t3_1vetc6x author: Optionbulls created_utc: 1785800816 edited: false body: Could be comment: p1jutqv parent: t3_1vetc6x author: Left_Entrepreneur918 created_utc: 1785801149 edited: false body: Get Rich and burn their old employer to the ground? Hmmmm comment: p1jx8y2 parent: t3_1vetc6x author: Doritos707 created_utc: 1785801942 edited: false body: Either that or somebody used ai and caught wind before patching became available comment: p1jxh39 parent: t3_1vetc6xExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, by corporate-citizen, linking timing speculation to recent AI advances.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Ya, fair point. I wasn’t saying to trust them, only sharing what I’ve heard them say. + +comment: p1nyeaq +parent: t1_p1k73a6 +author: corporate-citizen +created_utc: 1785856467 +edited: false +body: +Indeed I did. I had just read about a theory that the timing was due to recent advancements in AI.Extracted text as captured
post: 1vetc6x author: corporate-citizen created_utc: 1785799180 title: The timing of it all body: *The Coldcard RNG/low entropy issue has been known about by the stealer since a few weeks to months after the code was released in Nov 2021.* *They waited years so that as many people as possible would generate seeds on that faulty firmware and send bitcoin to addresses derived from those private keys.* *Something caused them to strike and take it all now. Bottom of bear market. BIP-110. Clarity Act. Something triggered them to steal and cause the FUD right now.* Source: [https://x.com/hodlonaut/status/2084217381165940812?s=46](https://x.com/hodlonaut/status/2084217381165940812?s=46) comment: p1jtsnc parent: t3_1vetc6x author: Optionbulls created_utc: 1785800816 edited: false body: Could be comment: p1jutqv parent: t3_1vetc6x author: Left_Entrepreneur918 created_utc: 1785801149 edited: false body: Get Rich and burn their old employer to the ground? Hmmmm comment: p1jx8y2 parent: t3_1vetc6x author: Doritos707 created_utc: 1785801942 edited: false body: Either that or somebody used ai and caught wind before patching became available comment: p1jxh39 parent: t3_1vetc6xExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, including blackblastie.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: An accident. Life is weird sometimes. Another theory is that it was an anti-BIP-110 attack but this seems far-fetched to me (didn't accomplish anything if true anyway). + +comment: p1nijq4 +parent: t1_p1l4i0c +author: blackblastie +created_utc: 1785852260 +edited: false +body: +Ya, fair point. I wasn’t saying to trust them, only sharing what I’ve heard them say.Extracted text as captured
post: 1vetc6x author: corporate-citizen created_utc: 1785799180 title: The timing of it all body: *The Coldcard RNG/low entropy issue has been known about by the stealer since a few weeks to months after the code was released in Nov 2021.* *They waited years so that as many people as possible would generate seeds on that faulty firmware and send bitcoin to addresses derived from those private keys.* *Something caused them to strike and take it all now. Bottom of bear market. BIP-110. Clarity Act. Something triggered them to steal and cause the FUD right now.* Source: [https://x.com/hodlonaut/status/2084217381165940812?s=46](https://x.com/hodlonaut/status/2084217381165940812?s=46) comment: p1jtsnc parent: t3_1vetc6x author: Optionbulls created_utc: 1785800816 edited: false body: Could be comment: p1jutqv parent: t3_1vetc6x author: Left_Entrepreneur918 created_utc: 1785801149 edited: false body: Get Rich and burn their old employer to the ground? Hmmmm comment: p1jx8y2 parent: t3_1vetc6x author: Doritos707 created_utc: 1785801942 edited: false body: Either that or somebody used ai and caught wind before patching became available comment: p1jxh39 parent: t3_1vetc6xExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, including JanPB.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: I highly doubt this was left with awareness, anybody could have found it. Hell I could have found it. + +comment: p1n8cpu +parent: t3_1vetc6x +author: JanPB +created_utc: 1785849384 +edited: false +body: +An accident. Life is weird sometimes. Another theory is that it was an anti-BIP-110 attack but this seems far-fetched to me (didn't accomplish anything if true anyway).Extracted text as captured
post: 1vetc6x author: corporate-citizen created_utc: 1785799180 title: The timing of it all body: *The Coldcard RNG/low entropy issue has been known about by the stealer since a few weeks to months after the code was released in Nov 2021.* *They waited years so that as many people as possible would generate seeds on that faulty firmware and send bitcoin to addresses derived from those private keys.* *Something caused them to strike and take it all now. Bottom of bear market. BIP-110. Clarity Act. Something triggered them to steal and cause the FUD right now.* Source: [https://x.com/hodlonaut/status/2084217381165940812?s=46](https://x.com/hodlonaut/status/2084217381165940812?s=46) comment: p1jtsnc parent: t3_1vetc6x author: Optionbulls created_utc: 1785800816 edited: false body: Could be comment: p1jutqv parent: t3_1vetc6x author: Left_Entrepreneur918 created_utc: 1785801149 edited: false body: Get Rich and burn their old employer to the ground? Hmmmm comment: p1jx8y2 parent: t3_1vetc6x author: Doritos707 created_utc: 1785801942 edited: false body: Either that or somebody used ai and caught wind before patching became available comment: p1jxh39 parent: t3_1vetc6xExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
One new comment was posted: circuit_breaker, doubting the bug was left in deliberately and saying anyone could have found it.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: makes most sense + +comment: p1n1rt0 +parent: t3_1vetc6x +author: circuit_breaker +created_utc: 1785847390 +edited: false +body: +I highly doubt this was left with awareness, anybody could have found it. Hell I could have found it.Extracted text as captured
post: 1vetc6x author: corporate-citizen created_utc: 1785799180 title: The timing of it all body: *The Coldcard RNG/low entropy issue has been known about by the stealer since a few weeks to months after the code was released in Nov 2021.* *They waited years so that as many people as possible would generate seeds on that faulty firmware and send bitcoin to addresses derived from those private keys.* *Something caused them to strike and take it all now. Bottom of bear market. BIP-110. Clarity Act. Something triggered them to steal and cause the FUD right now.* Source: [https://x.com/hodlonaut/status/2084217381165940812?s=46](https://x.com/hodlonaut/status/2084217381165940812?s=46) comment: p1jtsnc parent: t3_1vetc6x author: Optionbulls created_utc: 1785800816 edited: false body: Could be comment: p1jutqv parent: t3_1vetc6x author: Left_Entrepreneur918 created_utc: 1785801149 edited: false body: Get Rich and burn their old employer to the ground? Hmmmm comment: p1jx8y2 parent: t3_1vetc6x author: Doritos707 created_utc: 1785801942 edited: false body: Either that or somebody used ai and caught wind before patching became available comment: p1jxh39 parent: t3_1vetc6xExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Two new comments were posted: CiaranCarroll ('Interesting...') and anonuemus ('makes most sense').
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 16 lines
Since the code is public (and has been for a long time) it seems risky for the attacker to wait and risk losing the hack to someone else. More likely that someone just discovered the issue (could even have automated scanning a bunch of repos for vulnerabilities with claude or whatever) and immediately launched a scan then an attack the moment it was discovered. + +comment: p1mi7ac +parent: t3_1vetc6x +author: CiaranCarroll +created_utc: 1785840332 +edited: false +body: +Interesting... + +comment: p1miz85 +parent: t1_p1jxh39 +author: anonuemus +created_utc: 1785840652 +edited: false +body: +makes most senseExtracted text as captured
post: 1vetc6x author: corporate-citizen created_utc: 1785799180 title: The timing of it all body: *The Coldcard RNG/low entropy issue has been known about by the stealer since a few weeks to months after the code was released in Nov 2021.* *They waited years so that as many people as possible would generate seeds on that faulty firmware and send bitcoin to addresses derived from those private keys.* *Something caused them to strike and take it all now. Bottom of bear market. BIP-110. Clarity Act. Something triggered them to steal and cause the FUD right now.* Source: [https://x.com/hodlonaut/status/2084217381165940812?s=46](https://x.com/hodlonaut/status/2084217381165940812?s=46) comment: p1jtsnc parent: t3_1vetc6x author: Optionbulls created_utc: 1785800816 edited: false body: Could be comment: p1jutqv parent: t3_1vetc6x author: Left_Entrepreneur918 created_utc: 1785801149 edited: false body: Get Rich and burn their old employer to the ground? Hmmmm comment: p1jx8y2 parent: t3_1vetc6x author: Doritos707 created_utc: 1785801942 edited: false body: Either that or somebody used ai and caught wind before patching became available comment: p1jxh39 parent: t3_1vetc6xExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vetc6x author: corporate-citizen created_utc: 1785799180 title: The timing of it all body: *The Coldcard RNG/low entropy issue has been known about by the stealer since a few weeks to months after the code was released in Nov 2021.* *They waited years so that as many people as possible would generate seeds on that faulty firmware and send bitcoin to addresses derived from those private keys.* *Something caused them to strike and take it all now. Bottom of bear market. BIP-110. Clarity Act. Something triggered them to steal and cause the FUD right now.* Source: [https://x.com/hodlonaut/status/2084217381165940812?s=46](https://x.com/hodlonaut/status/2084217381165940812?s=46) comment: p1jtsnc parent: t3_1vetc6x author: Optionbulls created_utc: 1785800816 edited: false body: Could be comment: p1jutqv parent: t3_1vetc6x author: Left_Entrepreneur918 created_utc: 1785801149 edited: false body: Get Rich and burn their old employer to the ground? Hmmmm comment: p1jx8y2 parent: t3_1vetc6x author: Doritos707 created_utc: 1785801942 edited: false body: Either that or somebody used ai and caught wind before patching became available comment: p1jxh39 parent: t3_1vetc6xExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.