r/Bitcoin: report that white-hat drains of unpatched COLDCARDs are underway
reddit-white-hat-drains-relay
https://www.reddit.com/r/Bitcoin/comments/1veo0yh/white_hats_are_emptying_weak_keys_generated_by/
Latest reviewed change
source content difference between and
The thread gained a skeptical comment casting doubt on the white-hat drain claim.
body:
Supposedly, I’ve not even seen anything concrete, only rumors.
+comment: p2q5ppw
+parent: t1_p1il3lu
+author: BigDik6355
+created_utc: 1786313557
+edited: false
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 10
- Detected differences
- 10
- Unreviewed
- 0
- Copies held
- 11
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The thread gained a skeptical comment casting doubt on the white-hat drain claim.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: Supposedly, I’ve not even seen anything concrete, only rumors. +comment: p2q5ppw +parent: t1_p1il3lu +author: BigDik6355 +created_utc: 1786313557 +edited: false +body: +The only white heads i know for sure are for real are on my ass. And they still hurt despite being white. Wouldn’t trust this one bit. + more-stub: parent t1_p1j79qs count <live-count>Extracted text as captured
post: 1veo0yh author: RetiredAvocado created_utc: 1785786814 title: White hats are emptying weak keys generated by broken RNG in unpatched coldcards body: WHITE HAT DRAINS OF COLDCARD WALLETS BEGIN The white hat wallet drains of exploitable COLDCARD wallets are now underway, according to @coinjoined If your COLDCARD was compromised, do not destroy the device. It could be needed if a recovery process is established. If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records. Users without a way to verify ownership could face a much harder path to recovery. comment: p1iihxv parent: t3_1veo0yh author: qwertyuiop121314321 created_utc: 1785787273 edited: false body: Why would anyone ever destroy their cold card, if they verified that they still had money on it after the attack? comment: p1ijqck parent: t1_p1iihxv author: dasmonty created_utc: 1785787601 edited: false body: *Murphy's Law* comment: p1ik891 parent: t1_p1iihxv author: Laukess created_utc: 1785787732 edited: false body: He's asking people who's been affected by the exploit to not destroy their CC's. A white hat hacker would still steal your coins, with the intent to give it back if you if you can prove ownership.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Four comments by IllllIIlIllIllllIlll were deleted (author now [deleted], bodies [deleted]) and a new comment says only rumors, nothing concrete, have been seen about the white hat.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 42 lines
body: Device ID of the physical device. That's why they are telling people to not destroy their device. -comment: p1iqrx2 -parent: t1_p1il4yb -author: IllllIIlIllIllllIlll -created_utc: 1785789452 -edited: false -body: -Lol maybe *you* should read again. It's not so hard to understand. - comment: p1ir29g parent: t3_1veo0yh author: Slow-Childhood-5671 comment: p1iro8r parent: t1_p1ippvk -author: IllllIIlIllIllllIlll +author: [deleted] created_utc: 1785789689 -edited: false -body: -That doesn't really answer the question, there is nothing tying an address to a specific device id no? A black hat could just give the device id their own cold card and claim that they are the person who had 18 BTC on it when in reality they had 0.01 +edited: 1786027693 +body: +[deleted] comment: p1is3d8 parent: t1_p1iihxv comment: p1iut2w parent: t1_p1isqlx -author: IllllIIlIllIllllIlll +author: [deleted] created_utc: 1785790519 -edited: false -body: -If the black hat was able to drain the wallet, it means that he is able to correctly derive addresses from the seed already, which means he already has all the info needed. If the attacker was able to brute force the seed, it means that he can also brute force a valid device id that generates this seed (I assume, maybe not) - -Like isn't the whole vulnerability stemming from the fact that the attacker could brute force the device ID? +edited: 1786027681 +body: +[deleted] comment: p1iv56s parent: t1_p1iut2w comment: p1iwhhq parent: t1_p1iv56s -author: IllllIIlIllIllllIlll +author: [deleted] created_utc: 1785790972 -edited: false -body: -Why does it matter? Or will the recovery imply physically shipping your device to the white hat? +edited: 1786027669 +body: +[deleted] comment: p1iwktp parent: t1_p1invwp A single transaction wouldn't be enough, but if multiple derived addresses got transactions from your exchange account, that's pretty strong evidence. +comment: p21z557 +parent: t1_p1kezat +author: Personal-Time-9993 +created_utc: 1786022082 +edited: false +body: +Supposedly, I’ve not even seen anything concrete, only rumors. + more-stub: parent t1_p1j79qs count <live-count>Extracted text as captured
post: 1veo0yh author: RetiredAvocado created_utc: 1785786814 title: White hats are emptying weak keys generated by broken RNG in unpatched coldcards body: WHITE HAT DRAINS OF COLDCARD WALLETS BEGIN The white hat wallet drains of exploitable COLDCARD wallets are now underway, according to @coinjoined If your COLDCARD was compromised, do not destroy the device. It could be needed if a recovery process is established. If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records. Users without a way to verify ownership could face a much harder path to recovery. comment: p1iihxv parent: t3_1veo0yh author: qwertyuiop121314321 created_utc: 1785787273 edited: false body: Why would anyone ever destroy their cold card, if they verified that they still had money on it after the attack? comment: p1ijqck parent: t1_p1iihxv author: dasmonty created_utc: 1785787601 edited: false body: *Murphy's Law* comment: p1ik891 parent: t1_p1iihxv author: Laukess created_utc: 1785787732 edited: false body: He's asking people who's been affected by the exploit to not destroy their CC's. A white hat hacker would still steal your coins, with the intent to give it back if you if you can prove ownership.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit added a comment suggesting exchange withdrawal histories across derived addresses as evidence of wallet ownership.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 10 lines
body: What are you on about? Anyone can see those transactions on chain. +comment: p1xjy91 +parent: t1_p1sx38c +author: generateduser29128 +created_utc: 1785962793 +edited: false +body: +Rather than showing ownership of the receiving address (which got compromised), you can show the history of your exchange account sending to your wallet address. + +A single transaction wouldn't be enough, but if multiple derived addresses got transactions from your exchange account, that's pretty strong evidence. + more-stub: parent t1_p1j79qs count <live-count>Extracted text as captured
post: 1veo0yh author: RetiredAvocado created_utc: 1785786814 title: White hats are emptying weak keys generated by broken RNG in unpatched coldcards body: WHITE HAT DRAINS OF COLDCARD WALLETS BEGIN The white hat wallet drains of exploitable COLDCARD wallets are now underway, according to @coinjoined If your COLDCARD was compromised, do not destroy the device. It could be needed if a recovery process is established. If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records. Users without a way to verify ownership could face a much harder path to recovery. comment: p1iihxv parent: t3_1veo0yh author: qwertyuiop121314321 created_utc: 1785787273 edited: false body: Why would anyone ever destroy their cold card, if they verified that they still had money on it after the attack? comment: p1ijqck parent: t1_p1iihxv author: dasmonty created_utc: 1785787601 edited: false body: *Murphy's Law* comment: p1ik891 parent: t1_p1iihxv author: Laukess created_utc: 1785787732 edited: false body: He's asking people who's been affected by the exploit to not destroy their CC's. A white hat hacker would still steal your coins, with the intent to give it back if you if you can prove ownership.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained a reply saying the cited transactions are publicly visible on-chain.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: Source of funds is easiest. Show control over the address that funded the wallet +comment: p1sx38c +parent: t1_p1m1rw9 +author: striata +created_utc: 1785910167 +edited: false +body: +What are you on about? Anyone can see those transactions on chain. + more-stub: parent t1_p1j79qs count <live-count>Extracted text as captured
post: 1veo0yh author: RetiredAvocado created_utc: 1785786814 title: White hats are emptying weak keys generated by broken RNG in unpatched coldcards body: WHITE HAT DRAINS OF COLDCARD WALLETS BEGIN The white hat wallet drains of exploitable COLDCARD wallets are now underway, according to @coinjoined If your COLDCARD was compromised, do not destroy the device. It could be needed if a recovery process is established. If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records. Users without a way to verify ownership could face a much harder path to recovery. comment: p1iihxv parent: t3_1veo0yh author: qwertyuiop121314321 created_utc: 1785787273 edited: false body: Why would anyone ever destroy their cold card, if they verified that they still had money on it after the attack? comment: p1ijqck parent: t1_p1iihxv author: dasmonty created_utc: 1785787601 edited: false body: *Murphy's Law* comment: p1ik891 parent: t1_p1iihxv author: Laukess created_utc: 1785787732 edited: false body: He's asking people who's been affected by the exploit to not destroy their CC's. A white hat hacker would still steal your coins, with the intent to give it back if you if you can prove ownership.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained a comment disputing the white-hat characterization of the drains.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: Yeah but since the keys are compromised, how would you prove you are the original owner and not the hacker? +comment: p1oc0ft +parent: t3_1veo0yh +author: 00-SilverShot +created_utc: 1785859947 +edited: false +body: +I call bullshit. Whitehat my ass. These hackers are breaking into someones wallet and draining funds. That's theft, through and through. Imagine if I broke into my neighbors house and removed all their gold from their safe, then the police caught me. Would the police let me go because I was "trying to prevent someone else from stealing it from them". It's so insanely stupid to think that's somehow not theft. Handcuffs and jail time for you thief! + comment: p1pjfbm parent: t3_1veo0yh author: locotxExtracted text as captured
post: 1veo0yh author: RetiredAvocado created_utc: 1785786814 title: White hats are emptying weak keys generated by broken RNG in unpatched coldcards body: WHITE HAT DRAINS OF COLDCARD WALLETS BEGIN The white hat wallet drains of exploitable COLDCARD wallets are now underway, according to @coinjoined If your COLDCARD was compromised, do not destroy the device. It could be needed if a recovery process is established. If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records. Users without a way to verify ownership could face a much harder path to recovery. comment: p1iihxv parent: t3_1veo0yh author: qwertyuiop121314321 created_utc: 1785787273 edited: false body: Why would anyone ever destroy their cold card, if they verified that they still had money on it after the attack? comment: p1ijqck parent: t1_p1iihxv author: dasmonty created_utc: 1785787601 edited: false body: *Murphy's Law* comment: p1ik891 parent: t1_p1iihxv author: Laukess created_utc: 1785787732 edited: false body: He's asking people who's been affected by the exploit to not destroy their CC's. A white hat hacker would still steal your coins, with the intent to give it back if you if you can prove ownership.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained a suggestion to prove ownership through control of the funding address.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: You know the Original Godfather wore a white hat. He gave you protection . . . . for a cost. +comment: p1qqpjp +parent: t1_p1j0whh +author: TotalRepost +created_utc: 1785882490 +edited: false +body: +Source of funds is easiest. Show control over the address that funded the wallet + more-stub: parent t1_p1j79qs count 0Extracted text as captured
post: 1veo0yh author: RetiredAvocado created_utc: 1785786814 title: White hats are emptying weak keys generated by broken RNG in unpatched coldcards body: WHITE HAT DRAINS OF COLDCARD WALLETS BEGIN The white hat wallet drains of exploitable COLDCARD wallets are now underway, according to @coinjoined If your COLDCARD was compromised, do not destroy the device. It could be needed if a recovery process is established. If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records. Users without a way to verify ownership could face a much harder path to recovery. comment: p1iihxv parent: t3_1veo0yh author: qwertyuiop121314321 created_utc: 1785787273 edited: false body: Why would anyone ever destroy their cold card, if they verified that they still had money on it after the attack? comment: p1ijqck parent: t1_p1iihxv author: dasmonty created_utc: 1785787601 edited: false body: *Murphy's Law* comment: p1ik891 parent: t1_p1iihxv author: Laukess created_utc: 1785787732 edited: false body: He's asking people who's been affected by the exploit to not destroy their CC's. A white hat hacker would still steal your coins, with the intent to give it back if you if you can prove ownership.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: Yeah but since the keys are compromised, how would you prove you are the original owner and not the hacker? +comment: p1pjfbm +parent: t3_1veo0yh +author: locotx +created_utc: 1785870767 +edited: false +body: +You know the Original Godfather wore a white hat. He gave you protection . . . . for a cost. + more-stub: parent t1_p1j79qs count 0Extracted text as captured
post: 1veo0yh author: RetiredAvocado created_utc: 1785786814 title: White hats are emptying weak keys generated by broken RNG in unpatched coldcards body: WHITE HAT DRAINS OF COLDCARD WALLETS BEGIN The white hat wallet drains of exploitable COLDCARD wallets are now underway, according to @coinjoined If your COLDCARD was compromised, do not destroy the device. It could be needed if a recovery process is established. If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records. Users without a way to verify ownership could face a much harder path to recovery. comment: p1iihxv parent: t3_1veo0yh author: qwertyuiop121314321 created_utc: 1785787273 edited: false body: Why would anyone ever destroy their cold card, if they verified that they still had money on it after the attack? comment: p1ijqck parent: t1_p1iihxv author: dasmonty created_utc: 1785787601 edited: false body: *Murphy's Law* comment: p1ik891 parent: t1_p1iihxv author: Laukess created_utc: 1785787732 edited: false body: He's asking people who's been affected by the exploit to not destroy their CC's. A white hat hacker would still steal your coins, with the intent to give it back if you if you can prove ownership.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, including IndependenceTop6501.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: …verify your money and pay Taxes +comment: p1npqx7 +parent: t3_1veo0yh +author: IndependenceTop6501 +created_utc: 1785854192 +edited: false +body: +Yeah but since the keys are compromised, how would you prove you are the original owner and not the hacker? + more-stub: parent t1_p1j79qs count 0Extracted text as captured
post: 1veo0yh author: RetiredAvocado created_utc: 1785786814 title: White hats are emptying weak keys generated by broken RNG in unpatched coldcards body: WHITE HAT DRAINS OF COLDCARD WALLETS BEGIN The white hat wallet drains of exploitable COLDCARD wallets are now underway, according to @coinjoined If your COLDCARD was compromised, do not destroy the device. It could be needed if a recovery process is established. If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records. Users without a way to verify ownership could face a much harder path to recovery. comment: p1iihxv parent: t3_1veo0yh author: qwertyuiop121314321 created_utc: 1785787273 edited: false body: Why would anyone ever destroy their cold card, if they verified that they still had money on it after the attack? comment: p1ijqck parent: t1_p1iihxv author: dasmonty created_utc: 1785787601 edited: false body: *Murphy's Law* comment: p1ik891 parent: t1_p1iihxv author: Laukess created_utc: 1785787732 edited: false body: He's asking people who's been affected by the exploit to not destroy their CC's. A white hat hacker would still steal your coins, with the intent to give it back if you if you can prove ownership.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
3 new Reddit comments were posted, including Available-Distance81,LexxM3,Fat-Finger-8906.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 26 lines
body: Even if an amazon package on someone's front porch is accessible to you, it's not legal to just take it. +comment: p1ne1ca +parent: t1_p1ixhk0 +author: Available-Distance81 +created_utc: 1785851012 +edited: false +body: +National Treasure logic, Nick Cage is going to steal the Declaration of Independence to prevent someone else from stealing it. + +comment: p1nfo5k +parent: t1_p1l3d8h +author: LexxM3 +created_utc: 1785851466 +edited: false +body: +Actually, pretty much by definition, if they use the funds in any way, they are a thief; if they hold forever they remain a white hat. It’s not “up to them” at all if they want to claim to remain a white hat. It’s a really bright line. + +And it’s not “any better” to the individual that lost their funds either way. To them it is theft either way. + +comment: p1nh4mo +parent: t3_1veo0yh +author: Fat-Finger-8906 +created_utc: 1785851867 +edited: false +body: +…verify your money and pay Taxes + more-stub: parent t1_p1j79qs count 0Extracted text as captured
post: 1veo0yh author: RetiredAvocado created_utc: 1785786814 title: White hats are emptying weak keys generated by broken RNG in unpatched coldcards body: WHITE HAT DRAINS OF COLDCARD WALLETS BEGIN The white hat wallet drains of exploitable COLDCARD wallets are now underway, according to @coinjoined If your COLDCARD was compromised, do not destroy the device. It could be needed if a recovery process is established. If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records. Users without a way to verify ownership could face a much harder path to recovery. comment: p1iihxv parent: t3_1veo0yh author: qwertyuiop121314321 created_utc: 1785787273 edited: false body: Why would anyone ever destroy their cold card, if they verified that they still had money on it after the attack? comment: p1ijqck parent: t1_p1iihxv author: dasmonty created_utc: 1785787601 edited: false body: *Murphy's Law* comment: p1ik891 parent: t1_p1iihxv author: Laukess created_utc: 1785787732 edited: false body: He's asking people who's been affected by the exploit to not destroy their CC's. A white hat hacker would still steal your coins, with the intent to give it back if you if you can prove ownership.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
3 new Reddit comments were posted, including PiDigitsOfPi,MiaTaude589,Available-Distance81.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 28 lines
body: You can also show the incoming transactions, eg, the history from your exchange account to cold wallet. +comment: p1mmj1y +parent: t1_p1kvc92 +author: PiDigitsOfPi +created_utc: 1785842080 +edited: false +body: +That doesn't make sense. Why would a scammer not take $50k per coin just because it used to be $100k per coin? + +That's still a lot. + + + +comment: p1mxn0r +parent: t3_1veo0yh +author: MiaTaude589 +created_utc: 1785846059 +edited: false +body: +honestly this is such a liability nightmare. you're asking people to trust some random held their coins, and proving ownership afterwards when the keys were already exposed? that's just legal hell waiting to happen + +comment: p1nco1w +parent: t1_p1iwktp +author: Available-Distance81 +created_utc: 1785850627 +edited: false +body: +Even if an amazon package on someone's front porch is accessible to you, it's not legal to just take it. + more-stub: parent t1_p1j79qs count 0Extracted text as captured
post: 1veo0yh author: RetiredAvocado created_utc: 1785786814 title: White hats are emptying weak keys generated by broken RNG in unpatched coldcards body: WHITE HAT DRAINS OF COLDCARD WALLETS BEGIN The white hat wallet drains of exploitable COLDCARD wallets are now underway, according to @coinjoined If your COLDCARD was compromised, do not destroy the device. It could be needed if a recovery process is established. If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records. Users without a way to verify ownership could face a much harder path to recovery. comment: p1iihxv parent: t3_1veo0yh author: qwertyuiop121314321 created_utc: 1785787273 edited: false body: Why would anyone ever destroy their cold card, if they verified that they still had money on it after the attack? comment: p1ijqck parent: t1_p1iihxv author: dasmonty created_utc: 1785787601 edited: false body: *Murphy's Law* comment: p1ik891 parent: t1_p1iihxv author: Laukess created_utc: 1785787732 edited: false body: He's asking people who's been affected by the exploit to not destroy their CC's. A white hat hacker would still steal your coins, with the intent to give it back if you if you can prove ownership.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1veo0yh author: RetiredAvocado created_utc: 1785786814 title: White hats are emptying weak keys generated by broken RNG in unpatched coldcards body: WHITE HAT DRAINS OF COLDCARD WALLETS BEGIN The white hat wallet drains of exploitable COLDCARD wallets are now underway, according to @coinjoined If your COLDCARD was compromised, do not destroy the device. It could be needed if a recovery process is established. If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records. Users without a way to verify ownership could face a much harder path to recovery. comment: p1iihxv parent: t3_1veo0yh author: qwertyuiop121314321 created_utc: 1785787273 edited: false body: Why would anyone ever destroy their cold card, if they verified that they still had money on it after the attack? comment: p1ijqck parent: t1_p1iihxv author: dasmonty created_utc: 1785787601 edited: false body: *Murphy's Law* comment: p1ik891 parent: t1_p1iihxv author: Laukess created_utc: 1785787732 edited: false body: He's asking people who's been affected by the exploit to not destroy their CC's. A white hat hacker would still steal your coins, with the intent to give it back if you if you can prove ownership.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.