r/coldcard: first-hand report of an Mk3 wallet drained mid-migration
reddit-wallet-drained-mk3
https://www.reddit.com/r/coldcard/comments/1vbzvf1/wallet_drained/
Latest reviewed change
source content difference between and
Reddit served an additional comment criticising COLDCARD users and recommending a different hardware-wallet brand.
edited: false
body:
I don't, because it isn't necessary for the exploits we've seen so far.
+
+comment: p1trwl6
+parent: t3_1vbzvf1
+author: Omniknight111
+created_utc: 1785924914
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 2
- Detected differences
- 2
- Unreviewed
- 0
- Copies held
- 3
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Reddit served an additional comment criticising COLDCARD users and recommending a different hardware-wallet brand.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: I don't, because it isn't necessary for the exploits we've seen so far. + +comment: p1trwl6 +parent: t3_1vbzvf1 +author: Omniknight111 +created_utc: 1785924914 +edited: false +body: +Only idiots use coldcard. You should have used trezor manExtracted text as captured
post: 1vbzvf1 author: reeferqueefer created_utc: 1785524173 title: Wallet drained body: I had a mk3. Got an email notifying my of a security flaw from coldcard wallets. I made a test transaction (5% or my stack). When I went to make another one, I get an error "not enough funds"... Wallet drained. I'm feeling shattered right now. I don't even know what to do. comment: p0xqjma parent: t3_1vbzvf1 author: Old_Instruction_6004 created_utc: 1785526531 edited: false body: Who sent the email? Coinkite doesn't keep customer info more than 90 days or something. comment: p0xroat parent: t1_p0xqjma author: reeferqueefer created_utc: 1785526836 edited: false body: The email was from a crypto news source, not coinkite. That was how I found out about the vulnerability. I searched online to confirm it. comment: p0xtpct parent: t1_p0xroat author: Old_Instruction_6004 created_utc: 1785527384 edited: false body: Ok, just wanted to make sure you weren't phished. comment: p0xtsel parent: t3_1vbzvf1 author: Old_Instruction_6004 created_utc: 1785527407 edited: false body: Did you use any dice rolls or have a passphrase?Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, including na3than.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Do you think quantum technology was involved to check trillions of combinations in a short time? + +comment: p1n034w +parent: t1_p1m0qw6 +author: na3than +created_utc: 1785846854 +edited: false +body: +I don't, because it isn't necessary for the exploits we've seen so far.Extracted text as captured
post: 1vbzvf1 author: reeferqueefer created_utc: 1785524173 title: Wallet drained body: I had a mk3. Got an email notifying my of a security flaw from coldcard wallets. I made a test transaction (5% or my stack). When I went to make another one, I get an error "not enough funds"... Wallet drained. I'm feeling shattered right now. I don't even know what to do. comment: p0xqjma parent: t3_1vbzvf1 author: Old_Instruction_6004 created_utc: 1785526531 edited: false body: Who sent the email? Coinkite doesn't keep customer info more than 90 days or something. comment: p0xroat parent: t1_p0xqjma author: reeferqueefer created_utc: 1785526836 edited: false body: The email was from a crypto news source, not coinkite. That was how I found out about the vulnerability. I searched online to confirm it. comment: p0xtpct parent: t1_p0xroat author: Old_Instruction_6004 created_utc: 1785527384 edited: false body: Ok, just wanted to make sure you weren't phished. comment: p0xtsel parent: t3_1vbzvf1 author: Old_Instruction_6004 created_utc: 1785527407 edited: false body: Did you use any dice rolls or have a passphrase?Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vbzvf1 author: reeferqueefer created_utc: 1785524173 title: Wallet drained body: I had a mk3. Got an email notifying my of a security flaw from coldcard wallets. I made a test transaction (5% or my stack). When I went to make another one, I get an error "not enough funds"... Wallet drained. I'm feeling shattered right now. I don't even know what to do. comment: p0xqjma parent: t3_1vbzvf1 author: Old_Instruction_6004 created_utc: 1785526531 edited: false body: Who sent the email? Coinkite doesn't keep customer info more than 90 days or something. comment: p0xroat parent: t1_p0xqjma author: reeferqueefer created_utc: 1785526836 edited: false body: The email was from a crypto news source, not coinkite. That was how I found out about the vulnerability. I searched online to confirm it. comment: p0xtpct parent: t1_p0xroat author: Old_Instruction_6004 created_utc: 1785527384 edited: false body: Ok, just wanted to make sure you weren't phished. comment: p0xtsel parent: t3_1vbzvf1 author: Old_Instruction_6004 created_utc: 1785527407 edited: false body: Did you use any dice rolls or have a passphrase?Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.