Critical Coldcard flaw: what happened, who is affected, and what to do
stackernews-critical-flaw-guide
- Organisation
- Stacker News
- Evidence role
- Community discussion
- Published
- 2026-08-01
- Source changes
- 0
- Detected differences
- 0
- Unreviewed
- 0
- Copies held
- 1
fanis linking a guide: 'Critical Coldcard flaw: what happened, who is affected, and what to do'. Link post; the value captured is the discussion. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
{ "data": { "item": { "comments": { "comments": [ { "createdAt": "2026-08-01T19:10:33.251Z", "text": "Lost about $12k CAD worth.\n\nI think I'm done guys. AI has made the world around us extremely vulnerable.", "user": { "name": "AngryMulbear" } }, { "createdAt": "2026-08-01T19:11:14.671Z", "text": "Holeeeshit. I think I gathered lots of these pieces from following people like Levin as they discovered the depth of this vulnerability, but it is really bad to see it all written out in one place. It sure does make Bitcoin sound like a bunch of larpers. \n\nThis is a great explanation of the role of randomness in generating a key:\n\n> Your Bitcoin secret key rests entirely on a single number, drawn at random once and for all on the day it is created. That 128 or 256 bit number is encoded as 12 or 24 words, then derived into a full tree of keys and addresses. Nothing protects your bitcoins but the statistical impossibility of guessing that number.\n\nOn Coldcard's lack of documentation around sees generation:\n\n> No written requirement said where seed entropy had to come from, so the implementation had nothing to visibly contradict, and anyone auditing the code had nothing to check it against.\n\nAlthough I read this second Coldcard post, I misses this line that Kevin points out: \n\n> the guard itself, he [the author of the Coldcard security advisories] explains that he set the macro to zero thinking it meant neither implementation would be built, which is not what it does.\n\nI suppose I've used lots of things without really knowing what they do, but god damn, it's kind of like CC had one job here and they didn't even know what the function did? \n\nBut perhaps this actually reveals something deeper in Bitcoin: most of the hardware wallet/security industry is about keeping your coins safe, not setting up your seeds. \n\nI have a very clear memory of the first time someone explained to me that you probably shouldn't just trust a seed generated by a device. You don't really have any way of checking how random it actually is. This isn't something that newbies are told. \n\n> If you generated your seed on a Coldcard and then imported it elsewhere, onto any other hardware wallet of any brand, you are affected in exactly the same way. It is the seed that is at fault, not the device it lives on today.\n\nSeeds are the foundation. All the precautions in the world won't help you if your seed is bad. We probably need to put a lot more emphasis on this. I've also likes that Kevin and the rest of the guys at Wizardsardine usually refer to Coldcards and BitBoxes and such devices as hardware *signer* not hardware wallets. The device exists for helping you compute signatures, not for creating seeds. \n\nAnd then there is all the stuff about how thoroughly CC fucked this up. Wow.\n\n> The clone-to-another-device function is broken too. The mechanism relies on an ephemeral key exchange between the two Coldcards, over the SD card, from which the transfer’s encryption key is derived. Since those ephemeral keys come from the faulty generator, anyone who gets hold of the clone file can recompute them, redo the exchange and decrypt everything, and so recover the seed in the clear. **Even if that seed was generated with dice.**\n\n**Any seed created on a Coldcard since 2021 has to be treated as public. And if the seed is public, so is the entire transaction history that flows from it, retroactively and permanently.**\n\nKevin concludes with this good advice:\n\n**Just make sure no spending path can be satisfied with the keys of a single brand.**", "user": { "name": "Scoresby" } }, { "createdAt": "2026-08-02T01:29:22.254Z", "text": "it is what it is...\n\n\n\n⏪⏫🐥 ⏬⏩\n\n", "user": { "name": "SHA256man" } }, { "createdAt": "2026-08-01T17:00:45.052Z", "text": "Very good read, but read it **very** carefully, all of it, and make sure you understand what is written there **exactly** (or you may make poor choices.)", "user": { "name": "optimism" } }, { "createdAt": "2026-08-02T00:27:38.052Z", "text": "This vulnerability in the Colcard has been exploited by a group of hackers, as the amount of BTC stolen suggests it's the work of more than one person. So far, there have been two waves of attacks. The first, on July 30th, extracted 1082.65 BTC from 1195 addresses in 41 minutes. The second, which began on the morning of July 31st, extracted 76.16 BTC from 1478 addresses over 3 hours and 42 minutes. Many Bitcoin users who have these wallets stored in cold storage haven't even heard about these attacks. How sad to have trusted one of the best wallets and then lose your BTC due to a vulnerability beyond the user's control!\nAnd there's talk of a third attack, we don't know if it's true!! What sad days for Bitcoiners!!!!", "user": { "name": "mkmloom" } },Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.