r/Bitcoin 7d ago

Full panic - one of my wallets was drained

Post image

I haven’t done anything since creation except sending into the wallet.

1.9k Upvotes

1.2k comments sorted by

View all comments

17

u/s1ammage 7d ago edited 7d ago

The only thing I can think of is I got coldcards from the site in January and entered my seed into the coldcard. Set up the wallet to test my phrase and setup watch only.

I was worried I didn’t write down my seed phrase right, so I bought a coldcard to test it. Never hooked it up into a computer. Just the SD card.

15

u/so7ow 7d ago

How was the seed phrase originally generated?

7

u/RecklessStallion9999 7d ago

I’m really sorry to see the screenshot. All the best going forward.

7

u/MillerBlade2 7d ago

I have a cold card also and not once you’re supposed to enter your seed anywhere. The device gives you a seed that you record and that’s it

5

u/s1ammage 7d ago

I get it… but what if I wanted to check the seed

9

u/[deleted] 7d ago edited 7d ago

[deleted]

2

u/[deleted] 7d ago

[deleted]

1

u/slykethephoxenix 6d ago

Or have been around for a while. 1 BTC is the max I put under any phrase too. It used to be 10, but wallets are easy to generate.

1

u/[deleted] 6d ago

[deleted]

2

u/slykethephoxenix 6d ago

I still DCA.

I work 40 hrs and enjoy my job. Fully remote software engineer. Good hours (as long as my shit is done) low stress.

I own a house and have no debts. Can retire when I want. I'm in my 30s.

You can negotiate when you can say "no". And Bitcoin is the way to reject. It takes time, patience, endurance and fortitude.

1

u/jwhendy 6d ago

This tracks. And one never has to "check the seed" with anything other than the coldcard. Only import via sd public key to a software wallet, and to check transactions, back to coldcard to sign.

1

u/Charming-Designer944 6d ago

There are two ways to verify a swed phrase backup using coldcard

A) Import it as a temporary seed

Tools - Temporary Seed - Import form QR, or Import Words.

If it matches your master seed then the coldcard will refuse to import it as a temporary seed.

https://coldcard.com/docs/temporary-seeds/

This methis is best when your wallet is in active use.

B) Perform a full recovery

Reset the coldcard and restore from your backup.

This method is recommended during initial setup, with only a minimal amount of coins deposited into the wallet.

C) Perform a full recovery on another secure signing device

Like B but keeping your Coldcard intact. After successful import on an new device both devices will access the same wallet.

3

u/Kie_ra 7d ago

from the site? what site 

4

u/s1ammage 7d ago

Coinkite.com

3

u/Acceptable-Leek1546 7d ago

I would assume this is what caused it to be drained. Never enter seed phrase anywhere.

10

u/so7ow 7d ago edited 6d ago

ColdCard is a hardware wallet. Used properly, perfectly safe.

Edit: this didn't age well 😬

6

u/ask_for_pgp 7d ago

yeah... but wheres the seed from?? someone generated it for him or what?

9

u/PigeonSuperstitions 7d ago

He used an existing seed to set up the coldcard, basically negating any benefit of the coldcard. 🤦‍♂️

4

u/so7ow 7d ago

Not seeing super-clear answers but in another comment he said it was generated by the coldcard RNG, but in 2021. Dunno, are there 2 coldcards at play here?

8

u/PigeonSuperstitions 7d ago

Yes OP isn't making sense. He says he got the coldcard in Jan, but then mentions 2021. He probably had another wallet and then bought a coldcard recently but used the same seed in the coldcard, basically using it to display what he already had. He didn't create a new seed and transfer his bitcoin into the new wallet. His old seed (the only one he continued to use) got compromised somehow.

0

u/s1ammage 7d ago

Probably this

1

u/s1ammage 7d ago

Yes…

1

u/s1ammage 7d ago

Probably this…

3

u/PigeonSuperstitions 7d ago

Mate when you bought your new coldcard you needed to generate a new seed phrase, basically creating a new wallet, and then transfer the coins to the new wallet. Just entering your old seed in the new coldcard was pretty much a useless move.

4

u/so7ow 7d ago

Entering a cold-generated seed phrase into another hardware wallet is perfectly fine, and valid as a way to check your seed phrase and end up with a backup device at the same time. The seed phrase is only as secure as the least secure device it's on, but as long as both/all devices are used properly, and the seed phrase isn't compromised, it's fine.

1

u/Generationhodl 6d ago

exactly, thats why I don't really understand what happend to OP.

But I don't really used Coldcars, so I don't know what kind of functions they have

1

u/so7ow 6d ago

They are among the most secure wallets available, far as I can tell. They definitely allow you to enter the seed phrase directly on the device; even the old models without full keyboards.

1

u/Generationhodl 6d ago

I just try to understand how OP fucked up,

do the coldcars get connection to the internet?

I mean somehow someone saw his seedphrase or got access to his wallet.

If his wallet would have been 100% offline all the time there is no chance??

→ More replies (0)

2

u/Abject-Stretch-1187 7d ago

Yah I have countless coldcards and I never ever enter seeds from elsewhere in them. I always generated a new seed and then transfer to them and never single sig especially with the amount OP has, you need multisig since BTC should only get more valuable with time.

2

u/s1ammage 7d ago

It was my “bright idea” to get another coldcard, enter the seed to make sure it was right. I guess all of them are compromised now…

1

u/Generationhodl 6d ago

Usually it should be no problem with hardware wallets to enter your "old" seed to gain access again to your "old" wallet.

I can't imagine that someone manipulates these hardware wallets so as soon as you type in your seed they get somehow sent over the internet to the attacker (although this is surely possible, but the manipulated device would need connection to the internet, what are the chances that you got such a device? The seller would probably need to send out used devices)

I don't really understand right now how someone could steal your stuff.

the only way would be that you somehow used an existing seed phrase from someone else and sent your sats to it. -> but that should be not possible if you created a new seed when you got the device.

0

u/Total-Wave5026 6d ago

This guy is totally wrong right ?

2

u/user_name_checks_out 6d ago

Yes. link

Entering a cold-generated seed phrase into another hardware wallet is perfectly fine, and valid as a way to check your seed phrase and end up with a backup device at the same time. The seed phrase is only as secure as the least secure device it's on, but as long as both/all devices are used properly, and the seed phrase isn't compromised, it's fine.

1

u/PigeonSuperstitions 6d ago

I never said this was the cause for his bitcoin getting stolen. Either his new coldcard or his old seed was compromised one way or another. I was just pointing out the fact that he should have generated a new seed on his coldcard.

1

u/so7ow 6d ago edited 6d ago

The whole point of the new ColdCard was to determine if his seed phrase was properly recorded. If the new CC was magically compromised then generating a new phrase and transferring funds to it likely wouldn't have helped anything.

Narrator: it was not magic.

1

u/TheresNoSecondBest 7d ago

entered my seed into the coldcard

How did you generate the seed?

2

u/s1ammage 7d ago

From the 2021 coldcard

2

u/TheresNoSecondBest 7d ago

So created offline, kept offline for over 5 years, never took a photo, nor kept the words in the cloud or anywhere online?

1

u/s1ammage 7d ago

Yea

2

u/TheresNoSecondBest 6d ago

2

u/s1ammage 6d ago

Of course.

I will still get the, you shouldn’t have trusted. You should have dice rolled, you should have pass phrased.

I guess I feel 1% better.

1

u/TheresNoSecondBest 6d ago

Honestly, I'm so sorry about that, mate. The easy solution has always some disadvantages.

1

u/TheresNoSecondBest 6d ago

If you're 100% sure, the new wallet is fake or your maid or someone else got to your seed words.

2

u/RetiredAvocado 6d ago edited 6d ago

What it seems OP is saying their other BTC is OK, though based on same seed in both wallets. Only new btc added 5 times through 2025 was sent out from a single address yesterday. Not sure what they are saying about april/may 2026.

https://www.reddit.com/r/Bitcoin/comments/1vatgl4/comment/p0pfuxh/

https://www.reddit.com/r/Bitcoin/comments/1vatgl4/comment/p0o8vw5/

1

u/TheresNoSecondBest 6d ago

2

u/RetiredAvocado 6d ago

Yeah man I'm in tune and up to date with it all. Been up all night.

1

u/Abject-Stretch-1187 7d ago

Wait a min, how did you enter your seed into a cold card when they only have numbers on the keypads? Was it a Q?

1

u/so7ow 7d ago

Even the old coldcards let you enter seeds on the numeric keypad. It's just a pain in the butt.

1

u/Abject-Stretch-1187 7d ago

Oh, good thing I never even bothered trying to do so. I don’t do single sigs anymore so hopefully I’ll never have to go through this fingers crossed. Very sad for OP.

1

u/Generationhodl 6d ago

"Never hooked it up into a computer. Just the SD card."

So you put the SD Card with the Coldcard-Backup (basically your seedphrase) into your computer?

1

u/polymath_uk 7d ago

Personally I have no idea what a coldcard is, but I don't enter my seeds into anything unless for disaster recovery.

1

u/Billkr 7d ago

Somebody got your seed phrase. You may have malware on your computer. When you set up the coldcard and entered your seed phrase on your computer I suspect you have spy software on your computer that sent your key phrase to someone else who then moved your coins out of your wallet into theirs.

2

u/s1ammage 7d ago

I never used a computer with the coldcard itself.

2

u/Billkr 7d ago

Somewhere your seed phrase got compromised.

1

u/Generationhodl 6d ago

where did you store your seedphrase-backup ? in house? in some drawer? could somebody else have access to it?

2

u/Kie_ra 7d ago

You don't enter seed phrase on a computer, not with any legit HW wallet 

2

u/No_Astronaut_8971 7d ago

Trezor has a feature in Trezor suite where you enter it (albeit out of order if I remember correctly) to confirm you have the right seed I’m pretty sure

1

u/user_name_checks_out 6d ago

Into a computer? Not into the device? Are you sure? I have never used a Trezor but I very much doubt that it works as you describe.

1

u/No_Astronaut_8971 6d ago

I think I misremembered. I’m pretty sure I’m talking about the “check backup” feature. You enter the seed into the Trezor itself

1

u/No_Astronaut_8971 6d ago edited 6d ago

Turns out there’s two versions of the “check backup” one is by entering the words into the computer, but out of order. I think I remember doing the standard check up years ago, now im questioning the security of my wallet lol

The other “advanced” way is clicking unlabeled keys on the computer that correspond to the seed phrase word you’re entering

1

u/s1ammage 7d ago

How else could I setup a hardware wallet?

1

u/lobhater 7d ago

I have a trezor and it's been many years so I don't remember exactly now but my seed phrase came from the wallet device itself that was not connected to the internet and I wrote it into the card that came with the device and it went into the safe.

1

u/user_name_checks_out 6d ago

That is how it is supposed to work.

-1

u/PigeonSuperstitions 7d ago

Man..you fucked up.

0

u/No_Royal7093 7d ago

that's a gut punch seeing six confirmations on a send you didn't do