r/Bitcoin: claim that destroying hardware stock points to a possible second exploit
reddit-coldcards-next-exploit
https://www.reddit.com/r/Bitcoin/comments/1vn78qh/coldcards_next_exploit/
Latest reviewed change
source content difference between and
A reply by Oxymorix was added arguing that destroying affected inventory is more practical than reflashing because returning devices to factory-first-boot state may not be feasible.
edited: false
body:
Not really.
+
+comment: p3tjfec
+parent: t1_p3rdv4h
+author: Oxymorix
+created_utc: 1786791727
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 2
- Detected differences
- 2
- Unreviewed
- 0
- Copies held
- 3
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
A reply by Oxymorix was added arguing that destroying affected inventory is more practical than reflashing because returning devices to factory-first-boot state may not be feasible.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 12 lines
edited: false body: Not really. + +comment: p3tjfec +parent: t1_p3rdv4h +author: Oxymorix +created_utc: 1786791727 +edited: false +body: +Yes. It’s easier, faster, and cheaper to destroy a large number of devices with vulnerable firmware—in the case of COLDCARDs—than to open the old packaging, reflash each device, test it, and then repackage it. + +The issue is not just the firmware update itself. Each device would also have to go through the necessary testing and hardware checks. Beyond that, there is another complication: returning the device to the same factory-fresh state it was in when first powered on, where it displays the bag number and other initial setup information. + +Once Coinkite powers those devices on again for reflashing and testing, they may not be able to return them to that exact first-boot state, or at least not easily. For that reason, destroying the affected inventory may simply make more practical and economic sense.Extracted text as captured
post: 1vn78qh author: Ok-Photograph-3585 created_utc: 1786617945 title: Coldcard's Next Exploit body: People here have been discussing the software bug that triggered the whole Coldcard debacle. that led many people to lose their Bitcoins savings. But what many didn't notice is that Coinkite decided to destroy their stock, instead of upgrading them. Had the bug been software-only, there would be no point in destroying the hardware. After speaking with many colleagues of mine, we have come to the conclusion that a hardware bug might be present, and this could trigger a second exploit. This is a textbook example of a "**Degenerate** **bug**". I believe a full audit of the software (latest version) and the hardware itself is warranted. A complete hardware check is difficult to carry out though because of the way it was designed. Please provide your thoughts and advice on how to proceed, as this could save many people from being victims of a second wave of bitcoin loses. At this point an inside job can also not be ruled out regrettably. comment: p3f3elp parent: t3_1vn78qh author: Laukess created_utc: 1786618109 edited: false body: They destroyed their stock because it’s not feasible to update the firmware before shipping. It must be because they’re hiding something something even more nefarious comment: p3f3l0x parent: t1_p3f3elp author: Ok-Photograph-3585 created_utc: 1786618183 edited: false body: Regrettably, a degenerate attack can not be ruled out. These people are not being transparent and many things don't add up. comment: p3f4d1q parent: t3_1vn78qh author: Main-Massive created_utc: 1786618501 edited: false body: They are degenerates indeed. u/nvk has retreated into his cave, gone hiding,and is probably cashing out the btc in Tel-Aviv, if you know what I mean. comment: p3f4fzo parent: t1_p3f3elp author: SolutionOk1306 created_utc: 1786618534 edited: false body: Destroying stock over a firmware update sounds extreme but honestly in hardware manufacturing it's sometimes cheaper to scrap and start fresh than to pay people to unbox, flash, repackage, and re-certify every single unit. The logistics are a nightmare. If there's a deeper hardware flaw though that's a whole different level of bad and the lack of a full teardown audit just feeds the paranoia. comment: p3f4lboExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained an exchange of short replies between grraarr and ItsAlwaysThemBooBoo disputing the original hardware-bug speculation.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 40 lines
edited: false body: Is it tho? Wouldn't you just pay 1 guy overtime to flash the cold cards and then feed that stock into the packaging phase of production? + +comment: p3rnh8p +parent: t1_p3fh1c7 +author: grraarr +created_utc: 1786760057 +edited: false +body: +Please go the fuck away. + +comment: p3rnj5p +parent: t1_p3f9s8l +author: grraarr +created_utc: 1786760077 +edited: false +body: +You lot are pathetic. + +comment: p3rs2r1 +parent: t1_p3rnh8p +author: ItsAlwaysThemBooBoo +created_utc: 1786761799 +edited: false +body: +nah. + +comment: p3rs6k8 +parent: t1_p3rnj5p +author: ItsAlwaysThemBooBoo +created_utc: 1786761840 +edited: false +body: +nah, we’re just adept at pattern recognition. + +comment: p3rv8hr +parent: t1_p3rs6k8 +author: grraarr +created_utc: 1786763031 +edited: false +body: +Not really.Extracted text as captured
post: 1vn78qh author: Ok-Photograph-3585 created_utc: 1786617945 title: Coldcard's Next Exploit body: People here have been discussing the software bug that triggered the whole Coldcard debacle. that led many people to lose their Bitcoins savings. But what many didn't notice is that Coinkite decided to destroy their stock, instead of upgrading them. Had the bug been software-only, there would be no point in destroying the hardware. After speaking with many colleagues of mine, we have come to the conclusion that a hardware bug might be present, and this could trigger a second exploit. This is a textbook example of a "**Degenerate** **bug**". I believe a full audit of the software (latest version) and the hardware itself is warranted. A complete hardware check is difficult to carry out though because of the way it was designed. Please provide your thoughts and advice on how to proceed, as this could save many people from being victims of a second wave of bitcoin loses. At this point an inside job can also not be ruled out regrettably. comment: p3f3elp parent: t3_1vn78qh author: Laukess created_utc: 1786618109 edited: false body: They destroyed their stock because it’s not feasible to update the firmware before shipping. It must be because they’re hiding something something even more nefarious comment: p3f3l0x parent: t1_p3f3elp author: Ok-Photograph-3585 created_utc: 1786618183 edited: false body: Regrettably, a degenerate attack can not be ruled out. These people are not being transparent and many things don't add up. comment: p3f4d1q parent: t3_1vn78qh author: Main-Massive created_utc: 1786618501 edited: false body: They are degenerates indeed. u/nvk has retreated into his cave, gone hiding,and is probably cashing out the btc in Tel-Aviv, if you know what I mean. comment: p3f4fzo parent: t1_p3f3elp author: SolutionOk1306 created_utc: 1786618534 edited: false body: Destroying stock over a firmware update sounds extreme but honestly in hardware manufacturing it's sometimes cheaper to scrap and start fresh than to pay people to unbox, flash, repackage, and re-certify every single unit. The logistics are a nightmare. If there's a deeper hardware flaw though that's a whole different level of bad and the lack of a full teardown audit just feeds the paranoia. comment: p3f4lboExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vn78qh author: Ok-Photograph-3585 created_utc: 1786617945 title: Coldcard's Next Exploit body: People here have been discussing the software bug that triggered the whole Coldcard debacle. that led many people to lose their Bitcoins savings. But what many didn't notice is that Coinkite decided to destroy their stock, instead of upgrading them. Had the bug been software-only, there would be no point in destroying the hardware. After speaking with many colleagues of mine, we have come to the conclusion that a hardware bug might be present, and this could trigger a second exploit. This is a textbook example of a "**Degenerate** **bug**". I believe a full audit of the software (latest version) and the hardware itself is warranted. A complete hardware check is difficult to carry out though because of the way it was designed. Please provide your thoughts and advice on how to proceed, as this could save many people from being victims of a second wave of bitcoin loses. At this point an inside job can also not be ruled out regrettably. comment: p3f3elp parent: t3_1vn78qh author: Laukess created_utc: 1786618109 edited: false body: They destroyed their stock because it’s not feasible to update the firmware before shipping. It must be because they’re hiding something something even more nefarious comment: p3f3l0x parent: t1_p3f3elp author: Ok-Photograph-3585 created_utc: 1786618183 edited: false body: Regrettably, a degenerate attack can not be ruled out. These people are not being transparent and many things don't add up. comment: p3f4d1q parent: t3_1vn78qh author: Main-Massive created_utc: 1786618501 edited: false body: They are degenerates indeed. u/nvk has retreated into his cave, gone hiding,and is probably cashing out the btc in Tel-Aviv, if you know what I mean. comment: p3f4fzo parent: t1_p3f3elp author: SolutionOk1306 created_utc: 1786618534 edited: false body: Destroying stock over a firmware update sounds extreme but honestly in hardware manufacturing it's sometimes cheaper to scrap and start fresh than to pay people to unbox, flash, repackage, and re-certify every single unit. The logistics are a nightmare. If there's a deeper hardware flaw though that's a whole different level of bad and the lack of a full teardown audit just feeds the paranoia. comment: p3f4lboExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.