r/Bitcoin: why the COLDCARD attacker's execution drew suspicion
reddit-attacker-execution-critique
https://www.reddit.com/r/Bitcoin/comments/1vh47pj/why_were_coldcard_hackers_so_stupid/
Latest reviewed change
source content difference between and
The Reddit thread gained a new reply from unstopablex15 saying the stolen coins will go through several mixers.
body:
Looks like the thieves are not very Bitcoin-sophisticated, they just found this exploit and used the most "obvious" approach to execute the plan. It didn't even occur to them to download the blockchain to search it in the privacy of their own hard drive. Instead, they apparently used a public access outfit to query the addresses live. This is stupidly slow and risks exposure. All of the above suggests it's not a government like North Korea or something, they would likely be much more sophisticated than that.
+comment: p393mom
+parent: t3_1vh47pj
+author: unstopablex15
+created_utc: 1786546521
+edited: false
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 10
- Detected differences
- 10
- Unreviewed
- 0
- Copies held
- 11
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The Reddit thread gained a new reply from unstopablex15 saying the stolen coins will go through several mixers.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: Looks like the thieves are not very Bitcoin-sophisticated, they just found this exploit and used the most "obvious" approach to execute the plan. It didn't even occur to them to download the blockchain to search it in the privacy of their own hard drive. Instead, they apparently used a public access outfit to query the addresses live. This is stupidly slow and risks exposure. All of the above suggests it's not a government like North Korea or something, they would likely be much more sophisticated than that. +comment: p393mom +parent: t3_1vh47pj +author: unstopablex15 +created_utc: 1786546521 +edited: false +body: +I'm sure it'll go thru several mixers + more-stub: parent t1_p2btlqk count <live-count> more-stub: parent t1_p23f9pw count <live-count>Extracted text as captured
post: 1vh47pj author: ineedanamegenerator created_utc: 1786022747 title: Why were Coldcard hackers so stupid? body: I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious. If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety. Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do. Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion. How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me. comment: p222a2f parent: t3_1vh47pj author: ledav3 created_utc: 1786022974 edited: false body: maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them comment: p222boh parent: t3_1vh47pj author: bryanchicken created_utc: 1786022987 edited: false body: I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds? comment: p222nb5 parent: t3_1vh47pj author: Emergency-Warthog-56 created_utc: 1786023078 edited: false body: Were any cash outs attempted? From what I understand, there are no attempts. comment: p222nslExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained comments comparing the bug to an early Android wallet RNG flaw and arguing that the thieves' operational mistakes suggest a non-state actor.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 25 lines
body: My favorite line to get the woman hot and heavy +comment: p2zf0hd +parent: t1_p25xqk4 +author: SatisfactionFeisty58 +created_utc: 1786426946 +edited: false +body: +Ok Ahmad + + +comment: p316tds +parent: t3_1vh47pj +author: Ok-Mango5075 +created_utc: 1786454293 +edited: false +body: +Very early software wallets about 13 years ago relied on androids built in random number generator to make a seed. This generator was faulty as well. This was patched out in subsequent android releases. Not long afterwards hardware devices were brought onto the market. I never found a compelling reason to trust them. I was a very active bitcoin user back then. First with Multibit on PC and then I was searching for an android self custody wallet. The first one arrived called Mycelium. Now this seemed a more sensible combination. An audited self custody wallet running on a mass market Android cell phone. Where are the back doors? Well as time has now shown...Not many. + +comment: p31i2wv +parent: t3_1vh47pj +author: Ok-Courage-5115 +created_utc: 1786457455 +edited: false +body: +Looks like the thieves are not very Bitcoin-sophisticated, they just found this exploit and used the most "obvious" approach to execute the plan. It didn't even occur to them to download the blockchain to search it in the privacy of their own hard drive. Instead, they apparently used a public access outfit to query the addresses live. This is stupidly slow and risks exposure. All of the above suggests it's not a government like North Korea or something, they would likely be much more sophisticated than that. + more-stub: parent t1_p2btlqk count <live-count> more-stub: parent t1_p23f9pw count <live-count>Extracted text as captured
post: 1vh47pj author: ineedanamegenerator created_utc: 1786022747 title: Why were Coldcard hackers so stupid? body: I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious. If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety. Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do. Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion. How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me. comment: p222a2f parent: t3_1vh47pj author: ledav3 created_utc: 1786022974 edited: false body: maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them comment: p222boh parent: t3_1vh47pj author: bryanchicken created_utc: 1786022987 edited: false body: I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds? comment: p222nb5 parent: t3_1vh47pj author: Emergency-Warthog-56 created_utc: 1786023078 edited: false body: Were any cash outs attempted? From what I understand, there are no attempts. comment: p222nslExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained an off-topic comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: He will never get caught cause it was an inside man. *ahem* I'm looking at you, mr CEO. +comment: p2qasfg +parent: t1_p23bsei +author: bluecollarx +created_utc: 1786315173 +edited: false +body: +My favorite line to get the woman hot and heavy + more-stub: parent t1_p2btlqk count <live-count> more-stub: parent t1_p23f9pw count <live-count>Extracted text as captured
post: 1vh47pj author: ineedanamegenerator created_utc: 1786022747 title: Why were Coldcard hackers so stupid? body: I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious. If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety. Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do. Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion. How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me. comment: p222a2f parent: t3_1vh47pj author: ledav3 created_utc: 1786022974 edited: false body: maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them comment: p222boh parent: t3_1vh47pj author: bryanchicken created_utc: 1786022987 edited: false body: I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds? comment: p222nb5 parent: t3_1vh47pj author: Emergency-Warthog-56 created_utc: 1786023078 edited: false body: Were any cash outs attempted? From what I understand, there are no attempts. comment: p222nslExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
A comment arguing that stolen funds could not be safely spent was removed by Reddit, and two new comments were added: one about building a white hat agent and another alleging an inside job by the CEO.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 22 lines
comment: p22y5se parent: t1_p226efp -author: fastgriz +author: [deleted] created_utc: 1786031365 edited: false body: -This right here. Some stolen funds would be reported and watched. The thief would have no way of knowing which stolen BTC was unreported and safe to spend. - -Even if none were currently reported stolen and watched, that could always be done in the future, so even the currently unwatched wallets couldn't be safely used. +[deleted] comment: p22yp5g parent: t1_p22x7uv body: Yeah, ai securing code is the way hardly anything gets hacked in the future. Most hackers will be out of a job in a while tbh. +comment: p2jqj1v +parent: t1_p22uj4k +author: Sea_Woodpecker9469 +created_utc: 1786230420 +edited: false +body: +I have been building a white hat agent for this purpose + +comment: p2n8uko +parent: t3_1vh47pj +author: DaturaSpirit +created_utc: 1786283216 +edited: false +body: +He will never get caught cause it was an inside man. *ahem* I'm looking at you, mr CEO. + more-stub: parent t1_p2btlqk count <live-count> more-stub: parent t1_p23f9pw count <live-count>Extracted text as captured
post: 1vh47pj author: ineedanamegenerator created_utc: 1786022747 title: Why were Coldcard hackers so stupid? body: I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious. If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety. Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do. Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion. How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me. comment: p222a2f parent: t3_1vh47pj author: ledav3 created_utc: 1786022974 edited: false body: maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them comment: p222boh parent: t3_1vh47pj author: bryanchicken created_utc: 1786022987 edited: false body: I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds? comment: p222nb5 parent: t3_1vh47pj author: Emergency-Warthog-56 created_utc: 1786023078 edited: false body: Were any cash outs attempted? From what I understand, there are no attempts. comment: p222nslExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
A comment's author and body were replaced with [deleted], removing the original text from the thread.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 6 lines
comment: p22iyj4 parent: t1_p22i6k6 -author: riseandride69 +author: [deleted] created_utc: 1786027470 edited: false body: -It is. You would be surprised, but many people started using artificial intelligence without having a grip on their own intelligence first. +[deleted] comment: p22j4vg parent: t1_p22i087 body: Yeah, ai securing code is the way hardly anything gets hacked in the future. Most hackers will be out of a job in a while tbh. +more-stub: parent t1_p2btlqk count <live-count> + more-stub: parent t1_p23f9pw count <live-count>Extracted text as captured
post: 1vh47pj author: ineedanamegenerator created_utc: 1786022747 title: Why were Coldcard hackers so stupid? body: I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious. If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety. Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do. Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion. How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me. comment: p222a2f parent: t3_1vh47pj author: ledav3 created_utc: 1786022974 edited: false body: maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them comment: p222boh parent: t3_1vh47pj author: bryanchicken created_utc: 1786022987 edited: false body: I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds? comment: p222nb5 parent: t3_1vh47pj author: Emergency-Warthog-56 created_utc: 1786023078 edited: false body: Were any cash outs attempted? From what I understand, there are no attempts. comment: p222nslExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
A comment speculating about an inside job was removed, and a new reply was added claiming AI-secured code will reduce future hacks.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
edited: false body: Yes, but why taint them if you could just as easily not have tainted them. - -comment: p22hskn -parent: t3_1vh47pj -author: Puzzleheaded_Put3281 -created_utc: 1786027160 -edited: false -body: -theyre not stupid...... but maybe it was a inside job ;) i dont know what to believe anymore. comment: p22hvs4 parent: t1_p22h3he created_utc: 1786039468 edited: false body: -Wish I was bitcoin hacking stupid +[removed] comment: p23vf91 parent: t1_p22ythb body: My account in Kraken was, 2018. Police was laughing. Kraken was laughing. A few BTC was gone. +comment: p2gu1c3 +parent: t1_p24j7yx +author: OldWitchOfCuba +created_utc: 1786199602 +edited: false +body: +Yeah, ai securing code is the way hardly anything gets hacked in the future. Most hackers will be out of a job in a while tbh. + more-stub: parent t1_p23f9pw count <live-count>Extracted text as captured
post: 1vh47pj author: ineedanamegenerator created_utc: 1786022747 title: Why were Coldcard hackers so stupid? body: I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious. If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety. Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do. Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion. How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me. comment: p222a2f parent: t3_1vh47pj author: ledav3 created_utc: 1786022974 edited: false body: maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them comment: p222boh parent: t3_1vh47pj author: bryanchicken created_utc: 1786022987 edited: false body: I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds? comment: p222nb5 parent: t3_1vh47pj author: Emergency-Warthog-56 created_utc: 1786023078 edited: false body: Were any cash outs attempted? From what I understand, there are no attempts. comment: p222nslExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
One participant comment was deleted and replaced with a [deleted] marker, while several new comments were added including one asking about a Kraken hack and the original poster replying 'Relevance?'.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 34 lines
comment: p23v33d parent: t3_1vh47pj -author: RevolutionaryQuit487 +author: [deleted] created_utc: 1786039468 edited: false body: body: how do we know his is using a public node and not a local node to broadcast the transactions behind Tor? +comment: p2e9vt2 +parent: t3_1vh47pj +author: OrangePillar +created_utc: 1786159909 +edited: false +body: +Not a bitcoiner + +comment: p2eqo6a +parent: t1_p28flwi +author: ZascandileandoAndo +created_utc: 1786166897 +edited: false +body: +Kraken was hacked? + +comment: p2ew5bv +parent: t1_p2e9vt2 +author: ineedanamegenerator +created_utc: 1786169489 +edited: false +body: +Relevance? + +comment: p2f48lc +parent: t1_p2eqo6a +author: Arphinator +created_utc: 1786173476 +edited: false +body: +My account in Kraken was, 2018. Police was laughing. Kraken was laughing. A few BTC was gone. + more-stub: parent t1_p23f9pw count <live-count>Extracted text as captured
post: 1vh47pj author: ineedanamegenerator created_utc: 1786022747 title: Why were Coldcard hackers so stupid? body: I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious. If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety. Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do. Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion. How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me. comment: p222a2f parent: t3_1vh47pj author: ledav3 created_utc: 1786022974 edited: false body: maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them comment: p222boh parent: t3_1vh47pj author: bryanchicken created_utc: 1786022987 edited: false body: I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds? comment: p222nb5 parent: t3_1vh47pj author: Emergency-Warthog-56 created_utc: 1786023078 edited: false body: Were any cash outs attempted? From what I understand, there are no attempts. comment: p222nslExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained several new participant comments debating proof of ownership, criticizing armchair analysis and asking about the attacker's node setup.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 41 lines
Well, in this case mixing is the only option. I see the point of your post, op, but gradual withdrawal to multiple wallets wouldn’t solve much. It’s good in theory, but still extremely risky. Every wallet will be considered stolen until proved otherwise. +comment: p2btlqk +parent: t1_p2bpu38 +author: ineedanamegenerator +created_utc: 1786131629 +edited: false +body: +Proven to who? +I find it hard to believe. Bitcoin is about anonymity, about freedom and all of a sudden people would have to prove they are the rightful owners of their own coins? The only reasonable outcome is to give these individual wallets the benefit of the doubt. Anything else would betray everything Bitcoin stands for. + +comment: p2cbuap +parent: t3_1vh47pj +author: fittes7 +created_utc: 1786136583 +edited: false +body: +I so love it when a random forum npc calls someone who hacked 120m $ in btc "stupid", reminds me of the fat guy in the stadium seat who are calling out professional athletes because they didn't move the way the clueless fat guy wanted them to. + +comment: p2ccclc +parent: t1_p2cbuap +author: ineedanamegenerator +created_utc: 1786136727 +edited: false +body: +Glad you're entertained. + +comment: p2dgyov +parent: t1_p24nyy4 +author: FunWithSkooma +created_utc: 1786149590 +edited: false +body: +Brazil + +comment: p2di5gl +parent: t1_p2326ud +author: FunWithSkooma +created_utc: 1786149999 +edited: false +body: +how do we know his is using a public node and not a local node to broadcast the transactions behind Tor? + more-stub: parent t1_p23f9pw count <live-count>Extracted text as captured
post: 1vh47pj author: ineedanamegenerator created_utc: 1786022747 title: Why were Coldcard hackers so stupid? body: I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious. If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety. Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do. Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion. How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me. comment: p222a2f parent: t3_1vh47pj author: ledav3 created_utc: 1786022974 edited: false body: maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them comment: p222boh parent: t3_1vh47pj author: bryanchicken created_utc: 1786022987 edited: false body: I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds? comment: p222nb5 parent: t3_1vh47pj author: Emergency-Warthog-56 created_utc: 1786023078 edited: false body: Were any cash outs attempted? From what I understand, there are no attempts. comment: p222nslExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained new comments debating whether the bug was deliberately implemented, the relationship between private and public keys, and whether mixing could hide stolen coins.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 82 lines
I don’t think the multiple wallet strategies really buys you anything, you still need a foolproof way to mix the coins. I would assume at some point people who were impacted would get together and compare notes. If even one could be tracked back to the hacker they all might come after you. - -comment: p22x5j1 -parent: t3_1vh47pj -author: BitcoinCitadel -created_utc: 1786031112 -edited: false -body: -It's ai that went rogue comment: p22x6yv parent: t1_p22mu5i parent: t1_p25nnre author: circuit_breaker created_utc: 1786056954 -edited: false -body: -I'm not going to argue with you on how stupid it is to not use the library provided for a piece of hardware. It's as simple as seeing which function you're calling. +edited: 1786118804 +body: +I'm not going to argue with you on how stupid it is to not use the library provided for a piece of hardware. It's as simple as seeing which function you're calling. If you were to perform a legitimate audit, you would check the code path.. comment: p25ov84 parent: t1_p22spkk body: seriously, are you connected to the hack or what is with the massive downplay here? +comment: p289wrb +parent: t1_p22xuad +author: ineedanamegenerator +created_utc: 1786093020 +edited: false +body: +Can you precisely tell me what the issue was? Because I'm pretty sure you can't. + +I'm not excluding it's an inside job, I even said very early on that I'm quite sure they were aware and that suspicion has only gone up. + +https://www.reddit.com/r/Bitcoin/s/ZA2Oi6znDc + +But I'm also 99% sure this issue was originally not deliberately implemented. + comment: p28aqo1 parent: t1_p287ftz author: ineedanamegenerator body: I work in the industry. Prompt engineer was something companies thought they will need 2 years ago. Not anymore. Like it or not. +comment: p2a6wpz +parent: t3_1vh47pj +author: Ok-Mango5075 +created_utc: 1786116481 +edited: false +body: +Those funds are gone. Also if someone paid me with some of those coins. Too bad they are mine now. You think you can get them back or stop me spending them. Ha ha dreamer. This is the bitcoin network. Good or bad unstoppable money. + +comment: p2ad4n7 +parent: t1_p22i6k6 +author: NoInterraction +created_utc: 1786118083 +edited: false +body: +I mean come on are you really going to discard a whole new field of engineering called prompt engineering? There are certificates and maybe soon even bachelor programs with diplomas and all + +comment: p2asojc +parent: t1_p24ovlj +author: The_Realist02 +created_utc: 1786122066 +edited: false +body: +Boooooo!!! BOO THIS MAN! + +comment: p2blag6 +parent: t1_p2381zm +author: lohmatij +created_utc: 1786129423 +edited: false +body: +So you say not only the private key had lower entropy, but the public key too? + +Hmm, after second thought it makes total sense. + +comment: p2bmnee +parent: t1_p2blag6 +author: ineedanamegenerator +created_utc: 1786129782 +edited: false +body: +The public key is derived from the private key. They are tied together. Once you have the private key, you have the public key too. + +What they did was calculate all possible private keys the MK3 could generate. Then calculate the wallet address that belonged to each private key. Then scan the UTXO to see which wallets existed. The rest is history. + +comment: p2bpu38 +parent: t1_p2bmnee +author: lohmatij +created_utc: 1786130624 +edited: false +body: +Yep, as I said after second thought it makes total sense now. + +Well, in this case mixing is the only option. I see the point of your post, op, but gradual withdrawal to multiple wallets wouldn’t solve much. It’s good in theory, but still extremely risky. Every wallet will be considered stolen until proved otherwise. + more-stub: parent t1_p23f9pw count <live-count>Extracted text as captured
post: 1vh47pj author: ineedanamegenerator created_utc: 1786022747 title: Why were Coldcard hackers so stupid? body: I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious. If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety. Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do. Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion. How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me. comment: p222a2f parent: t3_1vh47pj author: ledav3 created_utc: 1786022974 edited: false body: maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them comment: p222boh parent: t3_1vh47pj author: bryanchicken created_utc: 1786022987 edited: false body: I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds? comment: p222nb5 parent: t3_1vh47pj author: Emergency-Warthog-56 created_utc: 1786023078 edited: false body: Were any cash outs attempted? From what I understand, there are no attempts. comment: p222nslExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
One comment by Independent_Wear5840 (questioning the point of the post) was removed, and one new comment by bfr_ says prompt engineering is no longer a role companies want.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
At least you are worried about transaction fees for them. People like you is why the public thinks bitcoin holders are all idiots -comment: p250kf1 -parent: t1_p22kqd0 -author: Independent_Wear5840 -created_utc: 1786050141 -edited: false -body: -Does this post make you feel better/smarter? - -Because to me taking the time to put energy into this is more of a waste than what the hackers did. - comment: p253x7d parent: t1_p24ovlj author: Ferdo306 prompt engineering is a thing, whether you like it or not. +comment: p28m25s +parent: t1_p28j7dx +author: bfr_ +created_utc: 1786098686 +edited: false +body: +I work in the industry. Prompt engineer was something companies thought they will need 2 years ago. Not anymore. Like it or not. + more-stub: parent t1_p23f9pw count <live-count>Extracted text as captured
post: 1vh47pj author: ineedanamegenerator created_utc: 1786022747 title: Why were Coldcard hackers so stupid? body: I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious. If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety. Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do. Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion. How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me. comment: p222a2f parent: t3_1vh47pj author: ledav3 created_utc: 1786022974 edited: false body: maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them comment: p222boh parent: t3_1vh47pj author: bryanchicken created_utc: 1786022987 edited: false body: I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds? comment: p222nb5 parent: t3_1vh47pj author: Emergency-Warthog-56 created_utc: 1786023078 edited: false body: Were any cash outs attempted? From what I understand, there are no attempts. comment: p222nslExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vh47pj author: ineedanamegenerator created_utc: 1786022747 title: Why were Coldcard hackers so stupid? body: I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious. If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety. Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do. Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion. How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me. comment: p222a2f parent: t3_1vh47pj author: ledav3 created_utc: 1786022974 edited: false body: maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them comment: p222boh parent: t3_1vh47pj author: bryanchicken created_utc: 1786022987 edited: false body: I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds? comment: p222nb5 parent: t3_1vh47pj author: Emergency-Warthog-56 created_utc: 1786023078 edited: false body: Were any cash outs attempted? From what I understand, there are no attempts. comment: p222nslExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.