r/coldcard: owner leaving COLDCARD after the incident
reddit-im-out
Latest reviewed change
source content difference between and
The thread gained a new comment comparing leaving COLDCARD to losing a relationship.
I also moved my funds to Coinbase for now, I think it's much safer. Thank God I used a passphrase and rolled dice to generate my seeds on the Coldcard, but after this event, I completely lost trust in Coinkite. Who can guarantee there aren't other bugs out there?
+
+comment: p2i7983
+parent: t3_1vfbi4w
+author: carothersjoshua
+created_utc: 1786213673
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 20
- Detected differences
- 20
- Unreviewed
- 0
- Copies held
- 21
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The thread gained a new comment comparing leaving COLDCARD to losing a relationship.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
I also moved my funds to Coinbase for now, I think it's much safer. Thank God I used a passphrase and rolled dice to generate my seeds on the Coldcard, but after this event, I completely lost trust in Coinkite. Who can guarantee there aren't other bugs out there? + +comment: p2i7983 +parent: t3_1vfbi4w +author: carothersjoshua +created_utc: 1786213673 +edited: false +body: +It sucks because I really like Coldcard and finally got used to using it and now it’s all over. Like that girlfriend you just can’t get out of your mind.Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Two comments by anotherfroggyevening were replaced with [deleted] and [removed], including one linking to a thread arguing the incident was deliberate rather than incompetent.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 13 lines
comment: p1pfyij parent: t1_p1nlzuy -author: anotherfroggyevening +author: [deleted] created_utc: 1785869873 edited: false body: -Even scarier to think it wasnt incompetente at all. Deliberate, planned way in advance: -https://www.reddit.com/r/CryptoCurrency/s/s5fNgg9k4X +[removed] comment: p1prhh8 parent: t1_p1oy5k1 body: Imagine continuing to trust a CC with your hard earned bitcoin after this, you would deserve to be rugged -comment: p1svl5z -parent: t1_p1rku7g -author: anotherfroggyevening -created_utc: 1785909477 -edited: false -body: -A "bug" imo works much better according to that logic. "It can't be deliberate, because it's a bug." Sure. Seeing the general tone of comments, seems like it was a perfect game plan. - comment: p1t1im3 parent: t1_p1rd237 author: Sammy262Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained a comment saying the poster moved funds to Coinbase and lost trust in Coinkite despite having used a passphrase and dice-generated seeds.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 10 lines
Why would you trust a team of clowns though? They're either complete morons or they're in on it. Maybe they'll accidentally push an update that uploads your private key next, who knows? How anyone can trust these people after this is beyond me. + +comment: p2arswq +parent: t3_1vfbi4w +author: eternal_recurrence12 +created_utc: 1786121841 +edited: false +body: + +I also moved my funds to Coinbase for now, I think it's much safer. Thank God I used a passphrase and rolled dice to generate my seeds on the Coldcard, but after this event, I completely lost trust in Coinkite. Who can guarantee there aren't other bugs out there? +Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained comments proposing limited reuse of a COLDCARD and criticizing Coinkite’s competence, including an inside-job allegation presented as the commenter’s speculation.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 40 lines
edited: false body: Those are valid points. I'm not expecting to rely on any future fixes or support. I am not even installing their emergency patches, so if/when they go under it won't impact my use of the cold card. But...yes, it is likely worth looking into other solutions that will be reliable and eventually take cold card out of the picture entirely. + +comment: p1yao12 +parent: t3_1vfbi4w +author: FerdaStonks +created_utc: 1785970553 +edited: false +body: +Don’t throw away your coldcard, it still works well as an airgapped way to calculate your 24th word if you make a wallet by flipping a coin 256 times. + +Use it to get that word and then use another wallet to actually transact with. I trust it to calculate 1 word and then turn off but wouldn’t trust it to actually enter dice rolls and get a legit seed or to transact with. + +comment: p1yeg9r +parent: t1_p1v78j6 +author: Ok-Information-2428 +created_utc: 1785971750 +edited: false +body: +If the attacker was a highly sophisticated operation it would be more understandable- in this case though it was their own total incompetence and complete lack of concern with the most critical code path in their wallet + +comment: p1yu0bw +parent: t1_p1v78j6 +author: rockorangebear +created_utc: 1785976860 +edited: false +body: +Honestly, any competent senior developer from a top tech company could've done it. A wallet's functionality isn't that large in scope, in fact it's surprisingly simple. + +In terms of security, making sure that a newly generated seed is done so randomly is one of the only critical tasks needed. + +It's not difficult to have automated tests in place. + +comment: p1yv366 +parent: t1_p1pzxcz +author: rockorangebear +created_utc: 1785977215 +edited: false +body: +Why would you trust a team of clowns though? They're either complete morons or they're in on it. + +Maybe they'll accidentally push an update that uploads your private key next, who knows? How anyone can trust these people after this is beyond me.Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained comments questioning Coinkite's staffing and future support, and discussing alternative hardware wallets and continued use after dice-derived seed generation.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 36 lines
edited: false body: Of course, any rational human being should toss any coldcard to the trash bin, I’ve disposed my two mk4s and have incoming parts to build a few seed signers and a jade ordered to make a multisig setup. This has been too close of a call, if I had been drained I don’t know what would have happened to me, I’m scared just to think of it. + +comment: p1v78j6 +parent: t1_p1nlzuy +author: deny_by_default +created_utc: 1785941421 +edited: false +body: +Isn't the "company" only like 5 people? How can keep up with security exploits and audit your code properly with a staff that size? Frankly, I'm amazed it took this long for this disaster to happen. It's a shame too. I really like the Coldcard Q, but I've lost faith in Coinkite. + +comment: p1vb9cu +parent: t1_p1owrme +author: cworxnine +created_utc: 1785942455 +edited: false +body: +I was considering the same, it's just a signing device and I used dice rolls so maybe I can continue using it right? But now their future is unclear, their team and company is very small and unlikely to absorb the loss of future income for years to come. + +It's unlikely they'll double down and reinvest in a dozen more developers, or revamp their broken QA. I doubt there's more than 30 full time employees there. This company doesn't have many business skills except grass roots marketing - which is gone now. How will this affect future firmware and support? + +It's just too risky to keep using their products when other viable solutions are out there who are WAY more funded and can invest more money in support and continued development. + +comment: p1veieb +parent: t1_p1qah2m +author: cworxnine +created_utc: 1785943285 +edited: false +body: +Trezor Safe 7 is actually pretty big. Ledger Flex is also a great device. I agree the CCQ is a sexy device, but I only use mine a few times a year anyways. Just needs to be easy to use and stable. + +comment: p1w3iok +parent: t1_p1vb9cu +author: Stack_Sats_Often +created_utc: 1785949479 +edited: false +body: +Those are valid points. I'm not expecting to rely on any future fixes or support. I am not even installing their emergency patches, so if/when they go under it won't impact my use of the cold card. But...yes, it is likely worth looking into other solutions that will be reliable and eventually take cold card out of the picture entirely.Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained owner accounts of leaving COLDCARD despite dice-derived seeds and passphrases, alongside replies asserting the patch is safe and questioning that assessment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 49 lines
edited: false body: I think Trezor had that happen to them as well or did I misunderstand that? + +comment: p1tiiyg +parent: t3_1vfbi4w +author: Logical_Breadfruit36 +created_utc: 1785920487 +edited: false +body: +Jup, I have the Q and just bought the MK5 last week.. I did dice rolls and a strong passphrase. Im also moving out. Will never use these wallets again. For me the company is done. They wont convince me again. Just bought a new cold wallet. Will make my own seed phrase fully offline now. + +comment: p1tjva5 +parent: t3_1vfbi4w +author: AmericanCryptoAbroad +created_utc: 1785921146 +edited: false +body: +MK4 with > 50 dice rolls is safe to use. If you moved your funds to an exchange or a lower security wallet like a hot wallet, you should move them back. + +comment: p1tkxl8 +parent: t1_p1ns7dv +author: Charming-Designer944 +created_utc: 1785921667 +edited: false +body: +The root cause of the coldcard firmware flaw have been analyzed in detail. There is no doubt that the patch fixes the issue and that seed phrases generated by devices with a corrected firmware are safe. + +Some vendors have a design where the device RNG capability is not blindly trusted and minimize the risk that issues like this causes catastrophic failure. + +The same kind of hacks are possible with closed source firmware as well. But takes a little more effort to find the flaw. + + + +comment: p1to9ju +parent: t1_p1tkxl8 +author: magic-battry-unknown +created_utc: 1785923260 +edited: false +body: +There's an interesting post here. Potentially pretty damning. And does call in question the correctness of the patch (amongst other things) +https://www.reddit.com/r/Bitcoin/s/VMGQZ0Z7bZ + +What I had meant to say earlier (it could happen to any company) is that, there could be similar flaws in other products too. So be careful with any alternative you choose. For example, it may be that I used the dice rolls (around 100) is the reason i still have my BTC. But i moved it anyway, just in case. Frankly, with everything that is being discovered, I'm not sure I'll ever use my new coldcard wallet i newly generated (with dice rolls too) with the updated firmware. + +comment: p1v1k69 +parent: t3_1vfbi4w +author: Uhrenwerker +created_utc: 1785939926 +edited: false +body: +Of course, any rational human being should toss any coldcard to the trash bin, I’ve disposed my two mk4s and have incoming parts to build a few seed signers and a jade ordered to make a multisig setup. This has been too close of a call, if I had been drained I don’t know what would have happened to me, I’m scared just to think of it.Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained criticism of COLDCARD and discussion of alternative wallets, dice-generated entropy, passphrases and speculation about the incident.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 97 lines
edited: false body: I moved my stack off my Coldcard last night and then slept like a baby for the first time since this started. + +comment: p1ruvvl +parent: t1_p1rbsb1 +author: moviemaker2 +created_utc: 1785895263 +edited: false +body: +>I’m just saying that such attacks were used before many times with other wallet providers. + +No, you said: + +>Many YouTube videos from years ago go over this exact situation. + +The claim that you and other know-nothings are making is that this exact exploit was known. That is ridiculous. + +>I don’t think anyone should consider the 100 dice rolls “above and beyond”, regardless of the wallet maker. + +You don't think that **now,** with hindsight, just like every other Monday morning quarterback. You're mistaking your ability to see the now obvious as some sort of insight. + +But the TRNG of the coldcard **WAS** considered sufficient for 256 bit entropy, as was the TRNGs of other leading wallet makers. That was the entire point of these devices. + +comment: p1rx86a +parent: t1_p1pfyij +author: moviemaker2 +created_utc: 1785896043 +edited: false +body: +That is idiotic. + +comment: p1ry5b1 +parent: t1_p1pzxcz +author: moviemaker2 +created_utc: 1785896349 +edited: false +body: +>Is not the device, but the software. + +What a braindead take. + +comment: p1sa64o +parent: t3_1vfbi4w +author: straight-up-digital +created_utc: 1785900538 +edited: false +body: +I’ve got a seedsigner. The project nvk always mocked. How the tables have turned. For me, I’d say either seedsigner of blockstream Jade or Trezor. + +comment: p1seo7d +parent: t3_1vfbi4w +author: Lost-Bowl3269 +created_utc: 1785902243 +edited: false +body: +Você está certo. +Mesmo que o codigo seja arrumado, as pessoas devem boicotar e processar a empresa. +Eles prometeram o cofre mais seguro do mundo e entregaram uma piada. +Merecem e devem falir e seus donos processados por fraude e propaganda enganosa. + +comment: p1sh27q +parent: t3_1vfbi4w +author: bigocreddit +created_utc: 1785903181 +edited: false +body: +You’re safe if you truly did 100 dice rolls plus a 256bit passphrase but I understand it. + +comment: p1sqvb7 +parent: t1_p1ns7dv +author: coinfreekz +created_utc: 1785907326 +edited: false +body: +Remember this is not a free product, cold card costs money and it's expensive. They had one job and failed. + +comment: p1ss6ns +parent: t1_p1pzxcz +author: Only_Assistant9176 +created_utc: 1785907918 +edited: false +body: +Imagine continuing to trust a CC with your hard earned bitcoin after this, you would deserve to be rugged + +comment: p1svl5z +parent: t1_p1rku7g +author: anotherfroggyevening +created_utc: 1785909477 +edited: false +body: +A "bug" imo works much better according to that logic. "It can't be deliberate, because it's a bug." Sure. Seeing the general tone of comments, seems like it was a perfect game plan. + +comment: p1t1im3 +parent: t1_p1rd237 +author: Sammy262 +created_utc: 1785912244 +edited: false +body: +I think Trezor had that happen to them as well or did I misunderstand that?Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained an owner report that they moved their bitcoin off a COLDCARD and felt safer afterward.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
I don’t believe that for a second. If it were intentional, it would be much smarter to simply drain a few high value wallets. There is no way they would drain this much and draw such attention to this bug. I understand how upsetting and infuriating this is, especially for those directly affected. But the majority of reactions I see are pure emotion and not much intellect. + +comment: p1rn9so +parent: t3_1vfbi4w +author: BTCMachineElf +created_utc: 1785892767 +edited: false +body: +I moved my stack off my Coldcard last night and then slept like a baby for the first time since this started.Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained two comments, including one rejecting an intentional-drain theory.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
edited: false body: The only information that was leaked was names, addresses, and emails from a third party hack. If people are foolish enough to fall for scams, that’s their own fault. + +comment: p1rkq8q +parent: t3_1vfbi4w +author: kotb0614 +created_utc: 1785891936 +edited: false +body: +Samesies. I just keep coming back here to try to save/warn other orangepilled bros and broettes + +comment: p1rku7g +parent: t1_p1pfyij +author: SomeGuyInOz +created_utc: 1785891972 +edited: false +body: +I don’t believe that for a second. If it were intentional, it would be much smarter to simply drain a few high value wallets. There is no way they would drain this much and draw such attention to this bug. + +I understand how upsetting and infuriating this is, especially for those directly affected. But the majority of reactions I see are pure emotion and not much intellect.Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained two replies discussing a past customer-data leak and victims of phishing scams.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 16 lines
I’m not saying coldcard is not at fault. Their randomness was not random. It’s definitely a big flaw. I’m just saying that such attacks were used before many times with other wallet providers. I don’t think anyone should consider the 100 dice rolls “above and beyond”, regardless of the wallet maker. + +comment: p1rd237 +parent: t1_p1pxriw +author: adequate_redditor +created_utc: 1785889465 +edited: false +body: +There was a big data leak a few years ago. Not directly related to the device itself, but people lost millions to phishing attempts. + +comment: p1ren0n +parent: t1_p1rd237 +author: Aqua-Barracuda +created_utc: 1785889972 +edited: false +body: +The only information that was leaked was names, addresses, and emails from a third party hack. If people are foolish enough to fall for scams, that’s their own fault.Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained comments questioning the timing of the fix and discussing dice-generated entropy.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 20 lines
edited: false body: The people that dont think like you seem to like getting bent over all day long + +comment: p1r7t0w +parent: t1_p1q0eis +author: moviemaker2 +created_utc: 1785887779 +edited: false +body: +Did all the world's cybercriminals just leave 80 million dollars on the table for 5 years out of their goodness of their hearts? + +Why did Coinkite not patch this easily fixable and company-destroying bug until after the wallets were drained, then patch it in a few hours? + +comment: p1rbsb1 +parent: t1_p1r7t0w +author: adequate_redditor +created_utc: 1785889059 +edited: false +body: +I’m not saying coldcard is not at fault. Their randomness was not random. It’s definitely a big flaw. + +I’m just saying that such attacks were used before many times with other wallet providers. I don’t think anyone should consider the 100 dice rolls “above and beyond”, regardless of the wallet maker.Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained a new participant comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
Being humbled isn't what I would call it. People put trust in a company that should have done things properly but didn't. Now a bunch of people got ripped off because ColdCard messed up. If this taught something to everyone it's DO NOT TRUST anybody or any company and generate your seed with 99 dice roll and make sure you do that right and include a 8 word or more paraphrase on top of it. This was a horrible situation for many people who didn't deserve it. This was some epic BS and Cold Card is 100% to blame for this. + +comment: p1r0li2 +parent: t3_1vfbi4w +author: RandyJohnsonsBird +created_utc: 1785885509 +edited: false +body: +The people that dont think like you seem to like getting bent over all day longExtracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained a comment assigning responsibility for the incident to COLDCARD.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 10 lines
edited: false body: To where did you move? + +comment: p1qoswd +parent: t3_1vfbi4w +author: Tebundo +created_utc: 1785881931 +edited: false +body: +Being humbled isn't what I would call it. People put trust in a company that should have done things properly but didn't. Now a bunch of people got ripped off because ColdCard messed up. If this taught something to everyone it's DO NOT TRUST anybody or any company and generate your seed with 99 dice roll and make sure you do that right and include a 8 word or more paraphrase on top of it. This was a horrible situation for many people who didn't deserve it. + +This was some epic BS and Cold Card is 100% to blame for this.Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment and no longer served an earlier comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 16 lines
body: …. And I am here expecting the company to pay back the $$ I spent to get 2 CCs that I got in 2023 -comment: p1pvrei -parent: t3_1vfbi4w -author: Emotional-Run9144 -created_utc: 1785874006 -edited: false -body: -No form of custody is every 100% safe, not with crypto or real world assets. - comment: p1pwg0u parent: t3_1vfbi4w author: hakunamatata0002 edited: false body: As someone almost buying a coldcard Q, im kinda disappointed. Because from a hardware perspective, it seems amazing. Jade uses a shit camera, q uses a qr reader. Trezor uses a tiny touchscreen. The Q uses a full physical keyboard…like fuck man. Honestly want other companies to just use this hardware for there firmwares. Or diy builtds + +comment: p1qdhay +parent: t3_1vfbi4w +author: JumpProfessional3372 +created_utc: 1785878737 +edited: false +body: +To where did you move?Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 3 new comments.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 24 lines
https://youtu.be/D9j5y3tyMo8 Wallets that don’t offer the dice roll function could be at risk too if similar vulnerabilities are uncovered. + +comment: p1q6krx +parent: t1_p1p4tx9 +author: RyzenNinja +created_utc: 1785876874 +edited: false +body: +I didnt say it wouldn't happen but what was my alternative in a pinch leave it there and let it get stolen. + +comment: p1q6vbe +parent: t1_p1ogj0b +author: RyzenNinja +created_utc: 1785876953 +edited: false +body: +Yes on the ColdCard I didnt erase it. I need to apply the firmware update and generate a new seed then test it out a bit but I'll never trust it to hold a lot. + +comment: p1qah2m +parent: t1_p1ocvfz +author: OddioClay +created_utc: 1785877927 +edited: false +body: +As someone almost buying a coldcard Q, im kinda disappointed. Because from a hardware perspective, it seems amazing. Jade uses a shit camera, q uses a qr reader. Trezor uses a tiny touchscreen. The Q uses a full physical keyboard…like fuck man. Honestly want other companies to just use this hardware for there firmwares. Or diy builtdsExtracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 2 new comments.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 20 lines
edited: false body: Ledger is Number One ☝️ + +comment: p1pzxcz +parent: t3_1vfbi4w +author: StageComprehensive81 +created_utc: 1785875104 +edited: false +body: +Is not the device, but the software. They updated the software. You can make a new seed from it and a strong passphrase no need to throw away the Coldcard. + +comment: p1q0eis +parent: t1_p1oxxr8 +author: adequate_redditor +created_utc: 1785875229 +edited: false +body: +Yes, but there were similar hacks before. Many YouTube videos from years ago go over this exact situation. The hardware is sufficient for entropy, but if it’s flawed in anyway then you get something like the coldcard hack… + +https://youtu.be/D9j5y3tyMo8 + +Wallets that don’t offer the dice roll function could be at risk too if similar vulnerabilities are uncovered.Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 3 new comments.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 24 lines
edited: false body: …. And I am here expecting the company to pay back the $$ I spent to get 2 CCs that I got in 2023 + +comment: p1pvrei +parent: t3_1vfbi4w +author: Emotional-Run9144 +created_utc: 1785874006 +edited: false +body: +No form of custody is every 100% safe, not with crypto or real world assets. + +comment: p1pwg0u +parent: t3_1vfbi4w +author: hakunamatata0002 +created_utc: 1785874187 +edited: false +body: +Bet they'll come out as different name for wallet soon! + +comment: p1pxriw +parent: t3_1vfbi4w +author: Aqua-Barracuda +created_utc: 1785874536 +edited: false +body: +Ledger is Number One ☝️Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: Even scarier to think it wasnt incompetente at all. Deliberate, planned way in advance: https://www.reddit.com/r/CryptoCurrency/s/s5fNgg9k4X + +comment: p1prhh8 +parent: t1_p1oy5k1 +author: ady1583 +created_utc: 1785872875 +edited: false +body: +…. And I am here expecting the company to pay back the $$ I spent to get 2 CCs that I got in 2023Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 9 lines
edited: false body: What makes you think that another hw wallet won't get hacked in a similar way? + +comment: p1pfyij +parent: t1_p1nlzuy +author: anotherfroggyevening +created_utc: 1785869873 +edited: false +body: +Even scarier to think it wasnt incompetente at all. Deliberate, planned way in advance: +https://www.reddit.com/r/CryptoCurrency/s/s5fNgg9k4XExtracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Ive seen people say theyre okay with continuing to use the coldcard with their dice generated seedphrase and passphrase, but fuck that... This company doesnt deserve anyone staying with them. If they missed this bug that was there since 2021 what else have they missed... plus they arent gonna reimburse victims of this disaster. + +comment: p1p4tx9 +parent: t1_p1ocvfz +author: mj +created_utc: 1785867095 +edited: false +body: +What makes you think that another hw wallet won't get hacked in a similar way?Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vfbi4w author: General_Asparagus976 created_utc: 1785852725 title: I'm out body: Moved off of coldcard even with mk4 with dice and a passphrase. This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. comment: p1nlzuy parent: t3_1vfbi4w author: Ok-Information-2428 created_utc: 1785853196 edited: false body: COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late comment: p1nnuzo parent: t3_1vfbi4w author: alixanc created_utc: 1785853690 edited: false body: "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG. comment: p1np0sk parent: t3_1vfbi4w author: Netopr22 created_utc: 1785853999 edited: false body: i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it.. comment: p1nqdxy parent: t3_1vfbi4w author: opossum_cz created_utc: 1785854362 edited: false body: \> people who thought they were doing the safest, most transparent form of self custody Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.