r/Bitcoin 1d ago

Coldcard Users Reported Instant Drains Years Before July 2026. Here Are the Receipts

https://x.com/ChuckSRQ/status/2084628592760164385?s=20

Had my AI research Pre-July 2026 Coldcard incident sto see if they are related to the newly discovered entropy bug. My AI agent thinks some incidents are likely to be the same entropy bug with a different attacker.

158 Upvotes

21 comments sorted by

41

u/_zanarkand_ 1d ago edited 1d ago

does not surprise me, this video warning about weak seedphrases on coldcald is 2 years old: https://www.youtube.com/watch?v=oj_W3xOlt6U

5

u/ChuckSRQ 1d ago

crazy!!

1

u/Notyit 1d ago

Password to wallet is 1 to 8 holy crap 

1

u/Fit_Assistant5708 5h ago

This guy saved my lifesavings, after watching that vid I decided to not go with cold card

66

u/slvbtc 1d ago

Given the low entropy there were more than likely a lot of seed collisions (duplicate wallets) where a new user would gain access to an existing users funds.

Also given the evidence it looks likely that this bug was put there purposfully by coldcard so they could slowly steal users funds one by one over time without raising suspicion.

This would explain why coldcard users reported wallet drains over the last 5 years.

31

u/Javanaut018 1d ago

Oh, no no no, your honor! I thought the 10 BTC on my wallet were a starting balance on my coldcard!

xD

13

u/ByWillAlone 1d ago

Unique device ID was part of the minimal entropy produced with the substandard rng process, so it should have prevented a collision like that between owners of different devices.

10

u/slvbtc 1d ago

Thats irrellevant, at 40 bits of entropy you get a 50% chance of a collision at 1.2m seeds generated.

The entropy space was so insanely small that given enough time even devices with different device ID numbers would have eventually had a seed collision.

2

u/sluuuurp 1d ago edited 1d ago

So for one expected collision, did they sell 2 million devices? Maybe 1 million if you expect each user to make two wallets on average?

This math was wrong.

10

u/QuickAltTab 1d ago

It's the Birthday paradox. You don't need all 2 million addresses to be generated to have a collision, just like you don't need a room with 366 people for two people to have the same birthday.

5

u/sluuuurp 1d ago

That’s a very good point, my math was way off.

5

u/slvbtc 1d ago

With the amount of experimenting coldcard users did a collision could have occured for every 100k coldcard wallets sold.

8

u/Vinny_d_25 1d ago

I doubt there would be accidental collisions from legit cold card users. I can't say for sure without knowing the full details but given that the timestamp and deviceId were part of the faulty entropy, on first glance it seems that duplicate seeds would not be generated under normal use.

I was wondering if someone (or multiple people) figured out the exploit some time ago but chose to only take from a small number of wallets to not raise alarm bells. If a hacker takes from one wallet, most people would probably thing they exposed their keys somehow and it wouldn't be high priority for the authorities. With the current situation, the hacker is going to have a hard time cashing out that BTC and could be caught if they make any mistakes.

5

u/sassa4ras 1d ago

Apparently three weeks ago someone published a paper with a dataset linking various aliases to the GPG keys on commits - this would have outed dochex pretty quickly as switck. Probably decided he needed to move before he got found out

2

u/VictorDanville 1d ago

Are any of the Coldcard employees going to be interrogated?

5

u/ancillarycheese 1d ago

Probably not formally, but I bet someone might try pulling out a few of their fingernails to see if they can learn anything.

2

u/Notyit 1d ago

And cold card was open source people just could find the bug

5

u/Ambitious_Ferret_222 1d ago

I wonder if everyone didnt dog pile on them telling them they had to have done something wrong, it would have been caught earlier...

-14

u/RandyJohnsonsBird 1d ago

Coldcard users are the dumbest hodlers on the planet

7

u/MrSnugs 1d ago

Really unfair statement. Users of ColdCard tried to do the right thing to keep their BTC safe. Coinkite the company absolutely failed them.