COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: why the COLDCARD attacker's execution drew suspicion

reddit-attacker-execution-critique

https://www.reddit.com/r/Bitcoin/comments/1vh47pj/why_were_coldcard_hackers_so_stupid/

Latest reviewed change

source content difference between and

The Reddit thread gained a new reply from unstopablex15 saying the stolen coins will go through several mixers.

seen +8 -0 full history below
 body:
 Looks like the thieves are not very Bitcoin-sophisticated, they just found this exploit and used the most "obvious" approach to execute the plan. It didn't even occur to them to download the blockchain to search it in the privacy of their own hard drive. Instead, they apparently used a public access outfit to query the addresses live. This is stupidly slow and risks exposure. All of the above suggests it's not a government like North Korea or something, they would likely be much more sophisticated than that.
 
+comment: p393mom
+parent: t3_1vh47pj
+author: unstopablex15
+created_utc: 1786546521
+edited: false

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
10
Detected differences
10
Unreviewed
0
Copies held
11

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +8 -0

    The Reddit thread gained a new reply from unstopablex15 saying the stolen coins will go through several mixers.

    seen · Captured here 99,836 chars
    What changed from the previous capture 8 lines
     body:
     Looks like the thieves are not very Bitcoin-sophisticated, they just found this exploit and used the most "obvious" approach to execute the plan. It didn't even occur to them to download the blockchain to search it in the privacy of their own hard drive. Instead, they apparently used a public access outfit to query the addresses live. This is stupidly slow and risks exposure. All of the above suggests it's not a government like North Korea or something, they would likely be much more sophisticated than that.
     
    +comment: p393mom
    +parent: t3_1vh47pj
    +author: unstopablex15
    +created_utc: 1786546521
    +edited: false
    +body:
    +I'm sure it'll go thru several mixers
    +
     more-stub: parent t1_p2btlqk count <live-count>
     
     more-stub: parent t1_p23f9pw count <live-count>
    
    Extracted text as captured
    post: 1vh47pj
    author: ineedanamegenerator
    created_utc: 1786022747
    title: Why were Coldcard hackers so stupid?
    body:
    I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious.
    
    If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety.
    
    Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do.
    
    Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion.
    
    How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me.
    
    comment: p222a2f
    parent: t3_1vh47pj
    author: ledav3
    created_utc: 1786022974
    edited: false
    body:
    maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them
    
    comment: p222boh
    parent: t3_1vh47pj
    author: bryanchicken
    created_utc: 1786022987
    edited: false
    body:
    I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds?
    
    comment: p222nb5
    parent: t3_1vh47pj
    author: Emergency-Warthog-56
    created_utc: 1786023078
    edited: false
    body:
    Were any cash outs attempted? From what I understand, there are no attempts.
    
    comment: p222nsl

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +25 -0

    The thread gained comments comparing the bug to an early Android wallet RNG flaw and arguing that the thieves' operational mistakes suggest a non-state actor.

    seen · Captured here 99,695 chars
    What changed from the previous capture 25 lines
     body:
     My favorite line to get the woman hot and heavy
     
    +comment: p2zf0hd
    +parent: t1_p25xqk4
    +author: SatisfactionFeisty58
    +created_utc: 1786426946
    +edited: false
    +body:
    +Ok Ahmad 
    +
    +
    +comment: p316tds
    +parent: t3_1vh47pj
    +author: Ok-Mango5075
    +created_utc: 1786454293
    +edited: false
    +body:
    +Very early software wallets about 13 years ago relied on androids built in random number generator to make a seed. This generator was faulty as well. This was patched out in subsequent android releases. Not long afterwards hardware devices were brought onto the market. I never found a compelling reason to trust them.  I was a very active bitcoin user back then.  First with Multibit on PC and then I was searching for an android self custody wallet. The first one arrived called Mycelium. Now this seemed a more sensible combination. An audited self custody wallet running on a mass market Android cell phone. Where are the back doors? Well as time has now shown...Not many.
    +
    +comment: p31i2wv
    +parent: t3_1vh47pj
    +author: Ok-Courage-5115
    +created_utc: 1786457455
    +edited: false
    +body:
    +Looks like the thieves are not very Bitcoin-sophisticated, they just found this exploit and used the most "obvious" approach to execute the plan. It didn't even occur to them to download the blockchain to search it in the privacy of their own hard drive. Instead, they apparently used a public access outfit to query the addresses live. This is stupidly slow and risks exposure. All of the above suggests it's not a government like North Korea or something, they would likely be much more sophisticated than that.
    +
     more-stub: parent t1_p2btlqk count <live-count>
     
     more-stub: parent t1_p23f9pw count <live-count>
    
    Extracted text as captured
    post: 1vh47pj
    author: ineedanamegenerator
    created_utc: 1786022747
    title: Why were Coldcard hackers so stupid?
    body:
    I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious.
    
    If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety.
    
    Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do.
    
    Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion.
    
    How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me.
    
    comment: p222a2f
    parent: t3_1vh47pj
    author: ledav3
    created_utc: 1786022974
    edited: false
    body:
    maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them
    
    comment: p222boh
    parent: t3_1vh47pj
    author: bryanchicken
    created_utc: 1786022987
    edited: false
    body:
    I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds?
    
    comment: p222nb5
    parent: t3_1vh47pj
    author: Emergency-Warthog-56
    created_utc: 1786023078
    edited: false
    body:
    Were any cash outs attempted? From what I understand, there are no attempts.
    
    comment: p222nsl

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +8 -0

    The thread gained an off-topic comment.

    seen · Captured here 98,176 chars
    What changed from the previous capture 8 lines
     body:
     He will never get caught cause it was an inside man. *ahem* I'm looking at you, mr CEO.
     
    +comment: p2qasfg
    +parent: t1_p23bsei
    +author: bluecollarx
    +created_utc: 1786315173
    +edited: false
    +body:
    +My favorite line to get the woman hot and heavy
    +
     more-stub: parent t1_p2btlqk count <live-count>
     
     more-stub: parent t1_p23f9pw count <live-count>
    
    Extracted text as captured
    post: 1vh47pj
    author: ineedanamegenerator
    created_utc: 1786022747
    title: Why were Coldcard hackers so stupid?
    body:
    I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious.
    
    If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety.
    
    Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do.
    
    Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion.
    
    How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me.
    
    comment: p222a2f
    parent: t3_1vh47pj
    author: ledav3
    created_utc: 1786022974
    edited: false
    body:
    maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them
    
    comment: p222boh
    parent: t3_1vh47pj
    author: bryanchicken
    created_utc: 1786022987
    edited: false
    body:
    I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds?
    
    comment: p222nb5
    parent: t3_1vh47pj
    author: Emergency-Warthog-56
    created_utc: 1786023078
    edited: false
    body:
    Were any cash outs attempted? From what I understand, there are no attempts.
    
    comment: p222nsl

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +18 -4

    A comment arguing that stolen funds could not be safely spent was removed by Reddit, and two new comments were added: one about building a white hat agent and another alleging an inside job by the CEO.

    seen · Captured here 98,027 chars
    What changed from the previous capture 22 lines
     
     comment: p22y5se
     parent: t1_p226efp
    -author: fastgriz
    +author: [deleted]
     created_utc: 1786031365
     edited: false
     body:
    -This right here.   Some stolen funds would be reported and watched.   The thief would have no way of knowing which stolen BTC was unreported and safe to spend.   
    -
    -Even if none were currently reported stolen and watched, that could always be done in the future, so even the currently unwatched wallets couldn't be safely used.
    +[deleted]
     
     comment: p22yp5g
     parent: t1_p22x7uv
     body:
     Yeah, ai securing code is the way hardly anything gets hacked in the future. Most hackers will be out of a job in a while tbh.
     
    +comment: p2jqj1v
    +parent: t1_p22uj4k
    +author: Sea_Woodpecker9469
    +created_utc: 1786230420
    +edited: false
    +body:
    +I have been building a white hat agent for this purpose 
    +
    +comment: p2n8uko
    +parent: t3_1vh47pj
    +author: DaturaSpirit
    +created_utc: 1786283216
    +edited: false
    +body:
    +He will never get caught cause it was an inside man. *ahem* I'm looking at you, mr CEO.
    +
     more-stub: parent t1_p2btlqk count <live-count>
     
     more-stub: parent t1_p23f9pw count <live-count>
    
    Extracted text as captured
    post: 1vh47pj
    author: ineedanamegenerator
    created_utc: 1786022747
    title: Why were Coldcard hackers so stupid?
    body:
    I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious.
    
    If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety.
    
    Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do.
    
    Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion.
    
    How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me.
    
    comment: p222a2f
    parent: t3_1vh47pj
    author: ledav3
    created_utc: 1786022974
    edited: false
    body:
    maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them
    
    comment: p222boh
    parent: t3_1vh47pj
    author: bryanchicken
    created_utc: 1786022987
    edited: false
    body:
    I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds?
    
    comment: p222nb5
    parent: t3_1vh47pj
    author: Emergency-Warthog-56
    created_utc: 1786023078
    edited: false
    body:
    Were any cash outs attempted? From what I understand, there are no attempts.
    
    comment: p222nsl

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +4 -2

    A comment's author and body were replaced with [deleted], removing the original text from the thread.

    seen · Captured here 97,988 chars
    What changed from the previous capture 6 lines
     
     comment: p22iyj4
     parent: t1_p22i6k6
    -author: riseandride69
    +author: [deleted]
     created_utc: 1786027470
     edited: false
     body:
    -It is. You would be surprised, but many people started using artificial intelligence without having a grip on their own intelligence first.
    +[deleted]
     
     comment: p22j4vg
     parent: t1_p22i087
     body:
     Yeah, ai securing code is the way hardly anything gets hacked in the future. Most hackers will be out of a job in a while tbh.
     
    +more-stub: parent t1_p2btlqk count <live-count>
    +
     more-stub: parent t1_p23f9pw count <live-count>
    
    Extracted text as captured
    post: 1vh47pj
    author: ineedanamegenerator
    created_utc: 1786022747
    title: Why were Coldcard hackers so stupid?
    body:
    I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious.
    
    If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety.
    
    Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do.
    
    Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion.
    
    How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me.
    
    comment: p222a2f
    parent: t3_1vh47pj
    author: ledav3
    created_utc: 1786022974
    edited: false
    body:
    maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them
    
    comment: p222boh
    parent: t3_1vh47pj
    author: bryanchicken
    created_utc: 1786022987
    edited: false
    body:
    I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds?
    
    comment: p222nb5
    parent: t3_1vh47pj
    author: Emergency-Warthog-56
    created_utc: 1786023078
    edited: false
    body:
    Were any cash outs attempted? From what I understand, there are no attempts.
    
    comment: p222nsl

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +9 -9

    A comment speculating about an inside job was removed, and a new reply was added claiming AI-secured code will reduce future hacks.

    seen · Captured here 98,084 chars
    What changed from the previous capture 18 lines
     edited: false
     body:
     Yes, but why taint them if you could just as easily not have tainted them.
    -
    -comment: p22hskn
    -parent: t3_1vh47pj
    -author: Puzzleheaded_Put3281
    -created_utc: 1786027160
    -edited: false
    -body:
    -theyre not stupid...... but maybe it was a inside job ;) i dont know what to believe anymore.
     
     comment: p22hvs4
     parent: t1_p22h3he
     created_utc: 1786039468
     edited: false
     body:
    -Wish I was bitcoin hacking stupid 
    +[removed]
     
     comment: p23vf91
     parent: t1_p22ythb
     body:
     My account in Kraken was, 2018. Police was laughing. Kraken was laughing. A few BTC was gone.
     
    +comment: p2gu1c3
    +parent: t1_p24j7yx
    +author: OldWitchOfCuba
    +created_utc: 1786199602
    +edited: false
    +body:
    +Yeah, ai securing code is the way hardly anything gets hacked in the future. Most hackers will be out of a job in a while tbh.
    +
     more-stub: parent t1_p23f9pw count <live-count>
    
    Extracted text as captured
    post: 1vh47pj
    author: ineedanamegenerator
    created_utc: 1786022747
    title: Why were Coldcard hackers so stupid?
    body:
    I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious.
    
    If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety.
    
    Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do.
    
    Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion.
    
    How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me.
    
    comment: p222a2f
    parent: t3_1vh47pj
    author: ledav3
    created_utc: 1786022974
    edited: false
    body:
    maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them
    
    comment: p222boh
    parent: t3_1vh47pj
    author: bryanchicken
    created_utc: 1786022987
    edited: false
    body:
    I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds?
    
    comment: p222nb5
    parent: t3_1vh47pj
    author: Emergency-Warthog-56
    created_utc: 1786023078
    edited: false
    body:
    Were any cash outs attempted? From what I understand, there are no attempts.
    
    comment: p222nsl

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +33 -1

    One participant comment was deleted and replaced with a [deleted] marker, while several new comments were added including one asking about a Kraken hack and the original poster replying 'Relevance?'.

    seen · Captured here 98,082 chars
    What changed from the previous capture 34 lines
     
     comment: p23v33d
     parent: t3_1vh47pj
    -author: RevolutionaryQuit487
    +author: [deleted]
     created_utc: 1786039468
     edited: false
     body:
     body:
     how do we know his is using a public node and not a local node to broadcast the transactions behind Tor?
     
    +comment: p2e9vt2
    +parent: t3_1vh47pj
    +author: OrangePillar
    +created_utc: 1786159909
    +edited: false
    +body:
    +Not a bitcoiner 
    +
    +comment: p2eqo6a
    +parent: t1_p28flwi
    +author: ZascandileandoAndo
    +created_utc: 1786166897
    +edited: false
    +body:
    +Kraken was hacked?
    +
    +comment: p2ew5bv
    +parent: t1_p2e9vt2
    +author: ineedanamegenerator
    +created_utc: 1786169489
    +edited: false
    +body:
    +Relevance?
    +
    +comment: p2f48lc
    +parent: t1_p2eqo6a
    +author: Arphinator
    +created_utc: 1786173476
    +edited: false
    +body:
    +My account in Kraken was, 2018. Police was laughing. Kraken was laughing. A few BTC was gone.
    +
     more-stub: parent t1_p23f9pw count <live-count>
    
    Extracted text as captured
    post: 1vh47pj
    author: ineedanamegenerator
    created_utc: 1786022747
    title: Why were Coldcard hackers so stupid?
    body:
    I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious.
    
    If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety.
    
    Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do.
    
    Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion.
    
    How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me.
    
    comment: p222a2f
    parent: t3_1vh47pj
    author: ledav3
    created_utc: 1786022974
    edited: false
    body:
    maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them
    
    comment: p222boh
    parent: t3_1vh47pj
    author: bryanchicken
    created_utc: 1786022987
    edited: false
    body:
    I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds?
    
    comment: p222nb5
    parent: t3_1vh47pj
    author: Emergency-Warthog-56
    created_utc: 1786023078
    edited: false
    body:
    Were any cash outs attempted? From what I understand, there are no attempts.
    
    comment: p222nsl

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. source content difference between and source content +41 -0

    The Reddit thread gained several new participant comments debating proof of ownership, criticizing armchair analysis and asking about the attacker's node setup.

    seen · Captured here 97,533 chars
    What changed from the previous capture 41 lines
     
     Well, in this case mixing is the only option. I see the point of your post, op, but gradual withdrawal to multiple wallets wouldn’t solve much. It’s good in theory, but still extremely risky. Every wallet will be considered stolen until proved otherwise. 
     
    +comment: p2btlqk
    +parent: t1_p2bpu38
    +author: ineedanamegenerator
    +created_utc: 1786131629
    +edited: false
    +body:
    +Proven to who?
    +I find it hard to believe. Bitcoin is about anonymity, about freedom and all of a sudden people would have to prove they are the rightful owners of their own coins? The only reasonable outcome is to give these individual wallets the benefit of the doubt. Anything else would betray everything Bitcoin stands for.
    +
    +comment: p2cbuap
    +parent: t3_1vh47pj
    +author: fittes7
    +created_utc: 1786136583
    +edited: false
    +body:
    +I so love it when a random forum npc calls someone who hacked 120m $ in btc "stupid", reminds me of the fat guy in the stadium seat who are calling out professional athletes because they didn't move the way the clueless fat guy wanted them to. 
    +
    +comment: p2ccclc
    +parent: t1_p2cbuap
    +author: ineedanamegenerator
    +created_utc: 1786136727
    +edited: false
    +body:
    +Glad you're entertained.
    +
    +comment: p2dgyov
    +parent: t1_p24nyy4
    +author: FunWithSkooma
    +created_utc: 1786149590
    +edited: false
    +body:
    +Brazil
    +
    +comment: p2di5gl
    +parent: t1_p2326ud
    +author: FunWithSkooma
    +created_utc: 1786149999
    +edited: false
    +body:
    +how do we know his is using a public node and not a local node to broadcast the transactions behind Tor?
    +
     more-stub: parent t1_p23f9pw count <live-count>
    
    Extracted text as captured
    post: 1vh47pj
    author: ineedanamegenerator
    created_utc: 1786022747
    title: Why were Coldcard hackers so stupid?
    body:
    I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious.
    
    If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety.
    
    Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do.
    
    Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion.
    
    How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me.
    
    comment: p222a2f
    parent: t3_1vh47pj
    author: ledav3
    created_utc: 1786022974
    edited: false
    body:
    maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them
    
    comment: p222boh
    parent: t3_1vh47pj
    author: bryanchicken
    created_utc: 1786022987
    edited: false
    body:
    I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds?
    
    comment: p222nb5
    parent: t3_1vh47pj
    author: Emergency-Warthog-56
    created_utc: 1786023078
    edited: false
    body:
    Were any cash outs attempted? From what I understand, there are no attempts.
    
    comment: p222nsl

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  9. source content difference between and source content +71 -11

    The thread gained new comments debating whether the bug was deliberately implemented, the relationship between private and public keys, and whether mixing could hide stolen coins.

    seen · Captured here 96,302 chars
    What changed from the previous capture 82 lines
     I don’t think the multiple wallet strategies really buys you anything, you still need a foolproof way to mix the coins.
     
     I would assume at some point people who were impacted would get together and compare notes. If even one could be tracked back to the hacker they all might come after you. 
    -
    -comment: p22x5j1
    -parent: t3_1vh47pj
    -author: BitcoinCitadel
    -created_utc: 1786031112
    -edited: false
    -body:
    -It's ai that went rogue
     
     comment: p22x6yv
     parent: t1_p22mu5i
     parent: t1_p25nnre
     author: circuit_breaker
     created_utc: 1786056954
    -edited: false
    -body:
    -I'm not going to argue with you on how stupid it is to not use the library provided for a piece of hardware. It's as simple as seeing which function you're calling. 
    +edited: 1786118804
    +body:
    +I'm not going to argue with you on how stupid it is to not use the library provided for a piece of hardware. It's as simple as seeing which function you're calling. If you were to perform a legitimate audit, you would check the code path..
     
     comment: p25ov84
     parent: t1_p22spkk
     body:
     seriously, are you connected to the hack or what is with the massive downplay here?
     
    +comment: p289wrb
    +parent: t1_p22xuad
    +author: ineedanamegenerator
    +created_utc: 1786093020
    +edited: false
    +body:
    +Can you precisely tell me what the issue was? Because I'm pretty sure you can't.
    +
    +I'm not excluding it's an inside job, I even said very early on that I'm quite sure they were aware and that suspicion has only gone up.
    +
    +https://www.reddit.com/r/Bitcoin/s/ZA2Oi6znDc
    +
    +But I'm also 99% sure this issue was originally not deliberately implemented.
    +
     comment: p28aqo1
     parent: t1_p287ftz
     author: ineedanamegenerator
     body:
     I work in the industry. Prompt engineer was something companies thought they will need 2 years ago. Not anymore. Like it or not.
     
    +comment: p2a6wpz
    +parent: t3_1vh47pj
    +author: Ok-Mango5075
    +created_utc: 1786116481
    +edited: false
    +body:
    +Those funds are gone. Also if someone paid me with some of those coins. Too bad they are mine now. You think you can get them back or stop me spending them. Ha ha dreamer. This is the bitcoin network. Good or bad  unstoppable money.
    +
    +comment: p2ad4n7
    +parent: t1_p22i6k6
    +author: NoInterraction
    +created_utc: 1786118083
    +edited: false
    +body:
    +I mean come on are you really going to discard a whole new field of engineering called prompt engineering? There are certificates and maybe soon even bachelor programs with diplomas and all
    +
    +comment: p2asojc
    +parent: t1_p24ovlj
    +author: The_Realist02
    +created_utc: 1786122066
    +edited: false
    +body:
    +Boooooo!!! BOO THIS MAN!
    +
    +comment: p2blag6
    +parent: t1_p2381zm
    +author: lohmatij
    +created_utc: 1786129423
    +edited: false
    +body:
    +So you say not only the private key had lower entropy, but the public key too?
    +
    +Hmm, after second thought it makes total sense. 
    +
    +comment: p2bmnee
    +parent: t1_p2blag6
    +author: ineedanamegenerator
    +created_utc: 1786129782
    +edited: false
    +body:
    +The public key is derived from the private key. They are tied together. Once you have the private key, you have the public key too.
    +
    +What they did was calculate all possible private keys the MK3 could generate. Then calculate the wallet address that belonged to each private key. Then scan the UTXO to see which wallets existed. The rest is history.
    +
    +comment: p2bpu38
    +parent: t1_p2bmnee
    +author: lohmatij
    +created_utc: 1786130624
    +edited: false
    +body:
    +Yep, as I said after second thought it makes total sense now. 
    +
    +Well, in this case mixing is the only option. I see the point of your post, op, but gradual withdrawal to multiple wallets wouldn’t solve much. It’s good in theory, but still extremely risky. Every wallet will be considered stolen until proved otherwise. 
    +
     more-stub: parent t1_p23f9pw count <live-count>
    
    Extracted text as captured
    post: 1vh47pj
    author: ineedanamegenerator
    created_utc: 1786022747
    title: Why were Coldcard hackers so stupid?
    body:
    I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious.
    
    If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety.
    
    Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do.
    
    Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion.
    
    How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me.
    
    comment: p222a2f
    parent: t3_1vh47pj
    author: ledav3
    created_utc: 1786022974
    edited: false
    body:
    maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them
    
    comment: p222boh
    parent: t3_1vh47pj
    author: bryanchicken
    created_utc: 1786022987
    edited: false
    body:
    I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds?
    
    comment: p222nb5
    parent: t3_1vh47pj
    author: Emergency-Warthog-56
    created_utc: 1786023078
    edited: false
    body:
    Were any cash outs attempted? From what I understand, there are no attempts.
    
    comment: p222nsl

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  10. source content difference between and source content +8 -10

    One comment by Independent_Wear5840 (questioning the point of the post) was removed, and one new comment by bfr_ says prompt engineering is no longer a role companies want.

    seen · Captured here 94,036 chars
    What changed from the previous capture 18 lines
     At least you are worried about transaction fees for them.
     People like you is why the public thinks bitcoin holders are all idiots
     
    -comment: p250kf1
    -parent: t1_p22kqd0
    -author: Independent_Wear5840
    -created_utc: 1786050141
    -edited: false
    -body:
    -Does this post make you feel better/smarter?
    -
    -Because to me taking the time to put energy into this is more of a waste than what the hackers did.
    -
     comment: p253x7d
     parent: t1_p24ovlj
     author: Ferdo306
     
     prompt engineering is a thing, whether you like it or not.
     
    +comment: p28m25s
    +parent: t1_p28j7dx
    +author: bfr_
    +created_utc: 1786098686
    +edited: false
    +body:
    +I work in the industry. Prompt engineer was something companies thought they will need 2 years ago. Not anymore. Like it or not.
    +
     more-stub: parent t1_p23f9pw count <live-count>
    
    Extracted text as captured
    post: 1vh47pj
    author: ineedanamegenerator
    created_utc: 1786022747
    title: Why were Coldcard hackers so stupid?
    body:
    I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious.
    
    If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety.
    
    Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do.
    
    Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion.
    
    How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me.
    
    comment: p222a2f
    parent: t3_1vh47pj
    author: ledav3
    created_utc: 1786022974
    edited: false
    body:
    maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them
    
    comment: p222boh
    parent: t3_1vh47pj
    author: bryanchicken
    created_utc: 1786022987
    edited: false
    body:
    I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds?
    
    comment: p222nb5
    parent: t3_1vh47pj
    author: Emergency-Warthog-56
    created_utc: 1786023078
    edited: false
    body:
    Were any cash outs attempted? From what I understand, there are no attempts.
    
    comment: p222nsl

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  11. Earliest copy held
    seen · Captured here 94,069 chars
    Extracted text as captured
    post: 1vh47pj
    author: ineedanamegenerator
    created_utc: 1786022747
    title: Why were Coldcard hackers so stupid?
    body:
    I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious.
    
    If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety.
    
    Second, the high transaction fees paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase the fees. Exactly what people saving their coins would do.
    
    Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion.
    
    How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me.
    
    comment: p222a2f
    parent: t3_1vh47pj
    author: ledav3
    created_utc: 1786022974
    edited: false
    body:
    maybe when you will steal a few thousand btc you will handle it better smartass😌 they will mix it, don't worry about them
    
    comment: p222boh
    parent: t3_1vh47pj
    author: bryanchicken
    created_utc: 1786022987
    edited: false
    body:
    I know the answer is “greed” but they could also have just stolen part of the funds in each address. Who is gonna believe someone would just partially drain your funds?
    
    comment: p222nb5
    parent: t3_1vh47pj
    author: Emergency-Warthog-56
    created_utc: 1786023078
    edited: false
    body:
    Were any cash outs attempted? From what I understand, there are no attempts.
    
    comment: p222nsl

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.