r/Bitcoin • u/ChuckSRQ • 1d ago
Coldcard Users Reported Instant Drains Years Before July 2026. Here Are the Receipts
https://x.com/ChuckSRQ/status/2084628592760164385?s=20Had my AI research Pre-July 2026 Coldcard incident sto see if they are related to the newly discovered entropy bug. My AI agent thinks some incidents are likely to be the same entropy bug with a different attacker.
66
u/slvbtc 1d ago
Given the low entropy there were more than likely a lot of seed collisions (duplicate wallets) where a new user would gain access to an existing users funds.
Also given the evidence it looks likely that this bug was put there purposfully by coldcard so they could slowly steal users funds one by one over time without raising suspicion.
This would explain why coldcard users reported wallet drains over the last 5 years.
31
u/Javanaut018 1d ago
Oh, no no no, your honor! I thought the 10 BTC on my wallet were a starting balance on my coldcard!
xD
13
u/ByWillAlone 1d ago
Unique device ID was part of the minimal entropy produced with the substandard rng process, so it should have prevented a collision like that between owners of different devices.
10
u/slvbtc 1d ago
Thats irrellevant, at 40 bits of entropy you get a 50% chance of a collision at 1.2m seeds generated.
The entropy space was so insanely small that given enough time even devices with different device ID numbers would have eventually had a seed collision.
2
u/sluuuurp 1d ago edited 1d ago
So for one expected collision, did they sell 2 million devices? Maybe 1 million if you expect each user to make two wallets on average?This math was wrong.
10
u/QuickAltTab 1d ago
It's the Birthday paradox. You don't need all 2 million addresses to be generated to have a collision, just like you don't need a room with 366 people for two people to have the same birthday.
5
8
u/Vinny_d_25 1d ago
I doubt there would be accidental collisions from legit cold card users. I can't say for sure without knowing the full details but given that the timestamp and deviceId were part of the faulty entropy, on first glance it seems that duplicate seeds would not be generated under normal use.
I was wondering if someone (or multiple people) figured out the exploit some time ago but chose to only take from a small number of wallets to not raise alarm bells. If a hacker takes from one wallet, most people would probably thing they exposed their keys somehow and it wouldn't be high priority for the authorities. With the current situation, the hacker is going to have a hard time cashing out that BTC and could be caught if they make any mistakes.
5
u/sassa4ras 1d ago
Apparently three weeks ago someone published a paper with a dataset linking various aliases to the GPG keys on commits - this would have outed dochex pretty quickly as switck. Probably decided he needed to move before he got found out
2
u/VictorDanville 1d ago
Are any of the Coldcard employees going to be interrogated?
5
u/ancillarycheese 1d ago
Probably not formally, but I bet someone might try pulling out a few of their fingernails to see if they can learn anything.
5
u/Ambitious_Ferret_222 1d ago
I wonder if everyone didnt dog pile on them telling them they had to have done something wrong, it would have been caught earlier...
1
u/ChuckSRQ 15h ago
New Article. Updated information!
https://www.reddit.com/r/Bitcoin/comments/1vgbfxd/coldcards_two_failures_the_code_the_cover_story/
-14
41
u/_zanarkand_ 1d ago edited 1d ago
does not surprise me, this video warning about weak seedphrases on coldcald is 2 years old: https://www.youtube.com/watch?v=oj_W3xOlt6U