Wallet drained timeline
reddit-drained-timeline
https://www.reddit.com/r/Bitcoin/comments/1vb6teq/wallet_drained_timeline/
Latest reviewed change
source content difference between and
A participant's account was deleted, replacing several of its comments with deleted placeholders. The removed comments discussed the RNG issue, proposed seed-handling approaches and broader hardware-wallet custody risks.
body:
What? Wait if this is an issue with rng, would this affect other HW wallets like Blockstream Jade plus?
-comment: p0scpz0
-parent: t1_p0s1vkb
-author: OldHamburger7923
-created_utc: 1785460841
-edited: false
First lines only. The complete diff is in the timeline below.
- Organisation
- r/Bitcoin
- Evidence role
- First-hand account
- Published
- 2026-07-31
- Source changes
- 2
- Detected differences
- 2
- Unreviewed
- 0
- Copies held
- 3
A first-hand account posted while the sweep was still being worked out, before the cause was publicly identified. A rendered capture from 1 Aug 2026 holds the original post and 25 comments locally. Public snapshot and diff text are withheld because the account contains identifying and wallet-specific details.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
A participant's account was deleted, replacing several of its comments with deleted placeholders. The removed comments discussed the RNG issue, proposed seed-handling approaches and broader hardware-wallet custody risks.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 111 lines
body: What? Wait if this is an issue with rng, would this affect other HW wallets like Blockstream Jade plus? -comment: p0scpz0 -parent: t1_p0s1vkb -author: OldHamburger7923 -created_utc: 1785460841 -edited: false -body: -he'll have as much btc as a baby - comment: p0sdrir parent: t1_p0rv18a -author: OldHamburger7923 +author: [deleted] created_utc: 1785461187 edited: 1785474844 body: -So, its what I mentioned on my reply to you yesterday. The RND issue. Your takeaway in your OP was always wrong, you can and should restore your seed on your HW wallet in order to verify your funds are reachable in case you messed up writing down the seed and to test the device restore capabilities. The issue is your original HW RNG, and ironically your new device could have fixed your issue if you generated a new wallet with it and did the transfer - which would be super easy with two devices. - -What I did when I moved from an older device to a new one was to create a new account. I was however lazy, so I didn't make a completely new account. I scrambled the existing words around, and then randomly picked a few words to replace, plus added a lengthy passphrase. You can get from ChatGPT the required amount of entropy needed to secure it to a reasonable expectation if someone knew your prior seed. But the non lazy way is just make a new seed. Or do what I did above, to a newly generated seed. +[deleted] comment: p0sduf0 parent: t3_1vb6teq body: I’m so sorry for this bullshit OP. -comment: p0sfaf4 -parent: t1_p0rjnj8 -author: OldHamburger7923 -created_utc: 1785461692 -edited: 1785463008 -body: -Look at the mk3 security advisory. It's about specific firmware. The RNG code isn't as random as it could be. Knowing that, an attacker can take their time (even over years) to run code to check potential addresses till they made a list large enough to sweep. - -**edit:** - -A flawed fallback RNG apparently derived randomness from a small or predictable device state, including a timer. - -* The researchers narrowed that state to about 80,000 possibilities. - -* They recreated the wallet’s RNG process for each possibility. - -* Each possibility produced a candidate 24-word phrase. - -* They compared each candidate’s resulting public wallet identifier, the xpub, against the known xpub. -One candidate matched, revealing the private key and recovery phrase. - -* 80,000-state timer range appears to come from a controlled reproduction where timing and device behavior were constrained. It does not prove that every affected wallet has exactly 80,000 possibilities. - comment: p0sfkvu parent: t3_1vb6teq author: dkayt edited: false body: Ledger... Not gonna go making that mistake again - -comment: p0sghla -parent: t1_p0r6s63 -author: OldHamburger7923 -created_utc: 1785462088 -edited: false -body: -Which makes perfect sense. If the RNG is flawed, it takes time to randomly generate potential addresses and to log the ones found with btc in it. Over time you build up a list knowing that people aren't likely to move funds often. One you generated enough wallets to hack, you sweep in one go. - -The nice thing for people who haven't been hacked yet, who had a coldcard on the bad firmware version, you now have advance notice your wallet is going to be fucked if you don't move it. - -Start moving it now. Generate a seed on a device without the bad firmware, then scramble the words around so its not what the RNG used, replace some words, add a passphrase. You won't have this issue even if they find a new RNG issue. Or just roll dice (or flip a coin) to generate your own seed by scratch. - -The 24th word is a checksum. You get one out of 7 potentials for your 23 words. On ledger and trezor devices (years ago) I don't recall seeing the ability for the device to give you the available checksum word, but on my new jade, it does. Which helps because you don't need to go off device to figure that out. Maybe there is an offline easy way to calculate it (I haven't looked) comment: p0sgnj8 parent: t1_p0s1fl1 comment: p0sgoad parent: t1_p0s1zok -author: OldHamburger7923 +author: [deleted] created_utc: 1785462151 edited: false body: -I read the prospectus on FBTC and IBIT and both said you are fucked if they get hacked. - -So its a matter if you trust fidelity or blackrock (coinbase custody) more than you trust yourself. The other consideration is that fidelity and coinbase have a larger target on their back because of the size of the assets they hold. your personal wallet isn't going to be large enough for anyone to focus on. +[deleted] comment: p0si12n parent: t1_p0rim2d edited: false body: Probably should consider to re-key that multisig. If other vendor hardware involved you're safer of course... but now one quorum member has a published exploit. - -comment: p0slxff -parent: t1_p0sk3m9 -author: OldHamburger7923 -created_utc: 1785463937 -edited: false -body: -Crazy. I really wanted to get a coldcard with keyboard too. But I didn't want to spend that much on a wallet. comment: p0smbi1 parent: t1_p0sl8zh And you won't hear it enough to make it any better, but I'm sorry this happened to you. I can't even imagine. -comment: p0t937v -parent: t1_p0s60k6 -author: OldHamburger7923 -created_utc: 1785472502 -edited: false -body: -The point is, no matter what device you get, if they later find an exploit with the RNG, you are exposed. You could do a mixture of the two, use the HW wallet seed, but restore it with the words reordered, and replace at least 4 of the words with random other words. Make sure the 24th checksum word matches the 23. Some wallets do this automatically (Jade), which makes it easier. - comment: p0t9drk parent: t1_p0s60k6 author: newMoneyStyle It’s always a extremely small fraction -comment: p0teh5y -parent: t1_p0s5joi -author: OldHamburger7923 -created_utc: 1785474781 -edited: false -body: -only on some versions of the firmware. But at this point anyone with a coldcard or any other hw wallet should consider generating their own seed and then migrating assets to it. And add a passphrase. - -comment: p0ter32 -parent: t1_p0s6775 -author: OldHamburger7923 -created_utc: 1785474902 -edited: false -body: -i wouldn't assume that. a normal guy from last season low could have put their savings into btc. we'd need to check when they put the funds into the wallet to even guess. - comment: p0teyf3 parent: t1_p0sbi27 -author: OldHamburger7923 +author: [deleted] created_utc: 1785474993 edited: false body: -You are shitting on coldcard with some justification, but keep in mind your trezor, ledger, etc, could also have a RND exploit in the future. And I bet people have been and continue looking for it. Best to generate your own seed so you aren't part of a bulk exploit. - -The coldcard with keyboard looks super nice still. +[deleted] comment: p0tfqe3 parent: t1_p0skel1 comment: p0tjaux parent: t1_p0tj1dl -author: OldHamburger7923 +author: [deleted] created_utc: 1785476944 edited: false body: -Why would you get drained if you make your own wallet seed? As I said, any company can have an exploitable seed generator. This one took many years to be exploited. Next one could be yours. +[deleted] comment: p0tkdxl parent: t1_p0teyf3 comment: p0tutrw parent: t1_p0tumiz -author: OldHamburger7923 +author: [deleted] created_utc: 1785482243 edited: false body: -It's just a matter of any small edge. With enough time the computational requirements isn't prohibitive. And the more users using the algorithm the more odds of hitting someone's wallet. +[deleted] comment: p0tuze4 parent: t1_p0svd3o body: [deleted] -comment: p0tzi55 -parent: t1_p0tybaq -author: OldHamburger7923 -created_utc: 1785484513 -edited: false -body: -As I said it depends on the explot. You can't say anything with any certainly what current rnd code will be exploitable. Especially as computational power increases - comment: p0u0vub parent: t1_p0traw6 author: downtherabbitExtracted text as captured
post: 1vb6teq author: s1ammage created_utc: 1785446774 title: Wallet Drained Timeline body: This is me… [https://www.reddit.com/r/Bitcoin/s/UeSfLoeyS4](https://www.reddit.com/r/Bitcoin/s/UeSfLoeyS4) I’m in a better state now. It’s not the end of the world, but it’s a lot of fucking money… Little background: The setup was IRA custodian is Solera National Bank, exchange at Swan Bitcoin was used as an Investment Trust, purchase a dedicated hardware wallets: coldcard mk3 from [https://store.coinkite.com](https://store.coinkite.com/) May 2021 for this ROTH IRA. Got the wallets, followed all the setup/checks/balances from [https://youtu.be/FAYmE5-40PQ?is=wiYMHaS\_YGKHjNOY](https://youtu.be/FAYmE5-40PQ?is=wiYMHaS_YGKHjNOY) for both wallets, sent a test transaction IRA dedicated hardware wallet (2021). I never setup a 25th Passphrase… REST of the BTC stayed in Swan Exchange. Speaking only on this IRA Wallet: SD card stored with wallet details (paper phrase) in a baggie. Dormant until January 2025. I couldn’t deposit more because of Roth IRA threshold. Come January 2025, been learning more about retirement, BTC, multi-Sig, and heard about a Megaback Door to get more money into a Roth IRA. Was able to get money into Solera, transfer to Swan, and purchase more BTC and withdraw to the same wallet address. No new hardware involved at this point. With newer wallets now, I thought newer tech means more security. Let’s test by buying (3 mk4 - same site. There was still record of my 2021 purchase) new wallets and setup a multi-Sig. (still January 2025) For some reason, when I got the new coldcards, I never did anything with them for all of 2025, I guess I was too lazy/daunting to use the hardware and relearn. Coming to January 2026 now, I decided to use these new cards. I dug out the wallet seed (from 2021) phrase paper. Dusted off one of the mk4, walked into the corner of a room in my house (only myself and partner live in the house), plugged in the cold card into an outlet and typed in the seed written down from 2021 (stored in my dresser). Restored my 2021 onto one of the new wallet 2025. Watched updated BTCSession videos on my phone to set everything up again. I never plugged into a computer, since airgapped was the reason I got the coldcards. I used the same SD Card from 2021 though to export the wallet file from the newly restored coldcard. Import that file into Sparrow (needed to update Sparrow at this point), generated a watch-only wallet QR (to scan for my phone) for Blue Wallet to check frequently. This is where the screenshot is from. Honestly, I haven’t touched the wallet with any transactions/seeds since January 2026. This is definitely the point of failure when I restored the 2021 wallet (now on 2 devices). This was the transaction. [https://mempool.space/tx/2fe075cf0ec799f3529ed6a28e0a08b45fe1fc9bd93c3f33bdbc42d5bff4f736](https://mempool.space/tx/2fe075cf0ec799f3529ed6a28e0a08b45fe1fc9bd93c3f33bdbc42d5bff4f736) My wallet address is (with all transactions, since it’s gone now…): bc1qldkfrrlylk4s9sdyns9jkaajuzugl0dv5m8fxj My key takeaway now never enter the seed phrase into anything. EVER. Even to restore. Always will generate new and use a 25th passphrase. comment: p0r52y2 parent: t3_1vb6teq author: NiagaraBTC created_utc: 1785447216 edited: false body: You're certain you exported a wallet file via SD card and not somehow the private key itself?Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
One new comment was posted: iloverunning11 speculating that victims will collectively sue Coinkite into chapter 11 and recover something like 15 to 20 cents on the dollar.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: Thanks for writing the timeline out. That’s the thing that actually helps people work out whether they’re hit. One bit worth adding: if your seed was generated on an affected version, updating firmware doesn’t fix it. You need a fresh seed. (I work at ELLIPAL.) +comment: p1mrctp +parent: t1_p0s1koh +author: iloverunning11 +created_utc: 1785843884 +edited: false +body: +What I think it more likely is that many victims will collectively sue coinkite and they will go belly up \*chapter 11\* and these victims will get something like 15-20 cents on the $ as they will not be able to afford to compensate them with 100% + more-stub: parent t1_p0t3gqq count 0Extracted text as captured
post: 1vb6teq author: s1ammage created_utc: 1785446774 title: Wallet Drained Timeline body: This is me… [https://www.reddit.com/r/Bitcoin/s/UeSfLoeyS4](https://www.reddit.com/r/Bitcoin/s/UeSfLoeyS4) I’m in a better state now. It’s not the end of the world, but it’s a lot of fucking money… Little background: The setup was IRA custodian is Solera National Bank, exchange at Swan Bitcoin was used as an Investment Trust, purchase a dedicated hardware wallets: coldcard mk3 from [https://store.coinkite.com](https://store.coinkite.com/) May 2021 for this ROTH IRA. Got the wallets, followed all the setup/checks/balances from [https://youtu.be/FAYmE5-40PQ?is=wiYMHaS\_YGKHjNOY](https://youtu.be/FAYmE5-40PQ?is=wiYMHaS_YGKHjNOY) for both wallets, sent a test transaction IRA dedicated hardware wallet (2021). I never setup a 25th Passphrase… REST of the BTC stayed in Swan Exchange. Speaking only on this IRA Wallet: SD card stored with wallet details (paper phrase) in a baggie. Dormant until January 2025. I couldn’t deposit more because of Roth IRA threshold. Come January 2025, been learning more about retirement, BTC, multi-Sig, and heard about a Megaback Door to get more money into a Roth IRA. Was able to get money into Solera, transfer to Swan, and purchase more BTC and withdraw to the same wallet address. No new hardware involved at this point. With newer wallets now, I thought newer tech means more security. Let’s test by buying (3 mk4 - same site. There was still record of my 2021 purchase) new wallets and setup a multi-Sig. (still January 2025) For some reason, when I got the new coldcards, I never did anything with them for all of 2025, I guess I was too lazy/daunting to use the hardware and relearn. Coming to January 2026 now, I decided to use these new cards. I dug out the wallet seed (from 2021) phrase paper. Dusted off one of the mk4, walked into the corner of a room in my house (only myself and partner live in the house), plugged in the cold card into an outlet and typed in the seed written down from 2021 (stored in my dresser). Restored my 2021 onto one of the new wallet 2025. Watched updated BTCSession videos on my phone to set everything up again. I never plugged into a computer, since airgapped was the reason I got the coldcards. I used the same SD Card from 2021 though to export the wallet file from the newly restored coldcard. Import that file into Sparrow (needed to update Sparrow at this point), generated a watch-only wallet QR (to scan for my phone) for Blue Wallet to check frequently. This is where the screenshot is from. Honestly, I haven’t touched the wallet with any transactions/seeds since January 2026. This is definitely the point of failure when I restored the 2021 wallet (now on 2 devices). This was the transaction. [https://mempool.space/tx/2fe075cf0ec799f3529ed6a28e0a08b45fe1fc9bd93c3f33bdbc42d5bff4f736](https://mempool.space/tx/2fe075cf0ec799f3529ed6a28e0a08b45fe1fc9bd93c3f33bdbc42d5bff4f736) My wallet address is (with all transactions, since it’s gone now…): bc1qldkfrrlylk4s9sdyns9jkaajuzugl0dv5m8fxj My key takeaway now never enter the seed phrase into anything. EVER. Even to restore. Always will generate new and use a 25th passphrase. comment: p0r52y2 parent: t3_1vb6teq author: NiagaraBTC created_utc: 1785447216 edited: false body: You're certain you exported a wallet file via SD card and not somehow the private key itself?Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vb6teq author: s1ammage created_utc: 1785446774 title: Wallet Drained Timeline body: This is me… [https://www.reddit.com/r/Bitcoin/s/UeSfLoeyS4](https://www.reddit.com/r/Bitcoin/s/UeSfLoeyS4) I’m in a better state now. It’s not the end of the world, but it’s a lot of fucking money… Little background: The setup was IRA custodian is Solera National Bank, exchange at Swan Bitcoin was used as an Investment Trust, purchase a dedicated hardware wallets: coldcard mk3 from [https://store.coinkite.com](https://store.coinkite.com/) May 2021 for this ROTH IRA. Got the wallets, followed all the setup/checks/balances from [https://youtu.be/FAYmE5-40PQ?is=wiYMHaS\_YGKHjNOY](https://youtu.be/FAYmE5-40PQ?is=wiYMHaS_YGKHjNOY) for both wallets, sent a test transaction IRA dedicated hardware wallet (2021). I never setup a 25th Passphrase… REST of the BTC stayed in Swan Exchange. Speaking only on this IRA Wallet: SD card stored with wallet details (paper phrase) in a baggie. Dormant until January 2025. I couldn’t deposit more because of Roth IRA threshold. Come January 2025, been learning more about retirement, BTC, multi-Sig, and heard about a Megaback Door to get more money into a Roth IRA. Was able to get money into Solera, transfer to Swan, and purchase more BTC and withdraw to the same wallet address. No new hardware involved at this point. With newer wallets now, I thought newer tech means more security. Let’s test by buying (3 mk4 - same site. There was still record of my 2021 purchase) new wallets and setup a multi-Sig. (still January 2025) For some reason, when I got the new coldcards, I never did anything with them for all of 2025, I guess I was too lazy/daunting to use the hardware and relearn. Coming to January 2026 now, I decided to use these new cards. I dug out the wallet seed (from 2021) phrase paper. Dusted off one of the mk4, walked into the corner of a room in my house (only myself and partner live in the house), plugged in the cold card into an outlet and typed in the seed written down from 2021 (stored in my dresser). Restored my 2021 onto one of the new wallet 2025. Watched updated BTCSession videos on my phone to set everything up again. I never plugged into a computer, since airgapped was the reason I got the coldcards. I used the same SD Card from 2021 though to export the wallet file from the newly restored coldcard. Import that file into Sparrow (needed to update Sparrow at this point), generated a watch-only wallet QR (to scan for my phone) for Blue Wallet to check frequently. This is where the screenshot is from. Honestly, I haven’t touched the wallet with any transactions/seeds since January 2026. This is definitely the point of failure when I restored the 2021 wallet (now on 2 devices). This was the transaction. [https://mempool.space/tx/2fe075cf0ec799f3529ed6a28e0a08b45fe1fc9bd93c3f33bdbc42d5bff4f736](https://mempool.space/tx/2fe075cf0ec799f3529ed6a28e0a08b45fe1fc9bd93c3f33bdbc42d5bff4f736) My wallet address is (with all transactions, since it’s gone now…): bc1qldkfrrlylk4s9sdyns9jkaajuzugl0dv5m8fxj My key takeaway now never enter the seed phrase into anything. EVER. Even to restore. Always will generate new and use a 25th passphrase. comment: p0r52y2 parent: t3_1vb6teq author: NiagaraBTC created_utc: 1785447216 edited: false body: You're certain you exported a wallet file via SD card and not somehow the private key itself?Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.