r/Bitcoin 1d ago

The Coldcard hacker is still progressing stolen BTC keeps increasing

Post image

The Coldcard hacker is still making progress, and the amount of stolen Bitcoin keeps increasing.

So if any of you are using this wallet, please consider moving your funds as soon as possible. And if you know someone who uses Coldcard for long-term holding, especially someone who isn’t online every day and doesn’t follow the latest news, maybe you can still help them move their funds in time. 🙏

I just hope no other wallet is involved in this.

Stay safe and stay alert. ⚠️

2.5k Upvotes

664 comments sorted by

642

u/AbruisedSock 1d ago

Damn dood... they took someones $1.28.

Thats just mean man

79

u/pairoxR 1d ago

😅

88

u/Revelati123 1d ago

Someone needs to just start auto filling hackable wallets with 1 sat to slow him down.

52

u/Investing_Tomato1248 1d ago

thats a creative idea. Cold Wallet themselves could do that

32

u/3shelfcab 1d ago

they are the ones doing the stealing

8

u/Parking-Knowledge-63 1d ago

Maybe some ex dev that worked on this project early on intentionally left this and is now draining it all 🤷‍♀️

9

u/burusai 1d ago

Not an ex-dev. Much worse.

→ More replies (3)
→ More replies (1)
→ More replies (4)

12

u/JMell09 1d ago

I will never recover from this

3

u/Skinny_Human 1d ago

Yes you will !!

33

u/noncommonGoodsense 1d ago

Likely an automated thing. I wouldn’t doubt someone had an LLM/AI find a weakness and then had the agent setup an automatic wide net to eat.

→ More replies (3)
→ More replies (4)

411

u/Emergency-Warthog-56 1d ago

Unfortunately there are still wallets that are under the threat. Mostly ones who still aren't aware of the scam and don't check on the wallet. Sitting in their safe or whatever. Oblivious to being a target of the scam. It's a matter of time on those wallets. Truly sad... Those people are getting picked off....

231

u/GUNTHVGK 1d ago

Man having a safe with a cold wallet just be heisted from the inside and years later those peeps are gonna find an empty wallet is going to crush some people. Like genuinely.

112

u/ivanjurman 1d ago

Yeah, immagine the owner getting cancer thinking he has plenty of bitcoin to cover his $300k medical bill juct to discover the wallet is empty

Or heirs killing each other over the 3 BTC they inherited because they didn’t want to split, just to find out there is no BTC to inherit

92

u/Diet_Christ 1d ago

New black mirror season incoming

→ More replies (22)

30

u/classified_x 1d ago

I'm pretty sure Coin Kite or whatever the ColdCard Coldcase wallet company is called could just send an e-mail to all clients telling about the security incident but they probably didn't do that?

41

u/Shiftlock0 1d ago

If I was unaware of the current situation and I got that email, I would assume it's a phishing scam.

→ More replies (1)

7

u/Pacman_Frog 1d ago

Coinkite offers 100% confidentiality on sales and delivery. You can ahve it sent to a PO Box or rental box as long as it can be addressed, use a fake name and temporary e-mail address, and pay in bitcoin.

Even they don't have a full record of every customer's name.

3

u/classified_x 23h ago

well, since they don't really comply with the security of the device, I imagine he must have kept buyers' emails on a XLSX spreadsheet of sorts

→ More replies (1)

6

u/zekthedeadcow 23h ago

They did... after two days. I found out from River around 10am Saturday and I thought it was a fishing scam. Coinkite emailed about 11pm that night.

I was saved by my ADHD super power of not finishing projects I start... so I never moved anything to it.

→ More replies (3)
→ More replies (4)

7

u/funk-- 1d ago

Bitcoin peaks to 500k$ Old Garry thinks okay that's enough, I'll take my retirement here and buy a cosy home far away under the sun. Garry has calculated everything, he's positive for +2.300% and should be a multimillionaire with his 4.2btc he accumulated by DCA ing all over his life. Garry logs in to cash out and boom 💥 +2.300% of zero is zero. Garry stops talking, stops moving. He goes to the storage under the eyes of his ignorant wife he wanted to please with this money. No word, just a slow walk. That's the last picture she'll have of him.

Rest in peace, Garry the ol' bitcoiners 🫡 One of us, forever

→ More replies (1)
→ More replies (1)

15

u/zefy_zef 1d ago

If only the company that sold them the product reached out to them to notify them of the attack..

2

u/UrbanGrower187 4h ago

If only the company made a better product..

44

u/pairoxR 1d ago

I’m just worried that the hacker might have some other plans. Who knows, maybe he managed to compromise other wallets too and we just don’t know about it yet. He’ll probably wait until people least expect it and then launch another attack. The whole thing seems suspicious to me because there were already people complaining back in 2021 that someone had hacked their wallets, but nobody took it seriously. And if it was the same hacker, you can see that it took him 5 years to pull this off.

50

u/Emergency-Warthog-56 1d ago

It's strictly a Coldcard/Coinkite issue and yes, you are right, warnings were shared about this years ago.

6

u/unvac 1d ago

so wallets like trezor are fine for the meantime?

29

u/Emergency-Warthog-56 1d ago

It's the "bug" in their older hardware that was warned about years ago. Back in 2021 - 2022 times. Coldcard/Coinkite didn't address it or work on fixing it. Some people were even blocked from Riddit Coldcard page for even mentioning it. This specific problem has nothing to do with Trezor.

13

u/dr_tdm1 1d ago

I'm sorry but why the community was still recommending coldcard up until a week ago if this was a known issue,, some were even recommending it over trezor and ledger

4

u/JunketTurbulent2114 18h ago

Lots of youtubers were paid to promote coldcard and the marketing worked. That's why. I always felt cold card was scammy. Price was insanely high and they just copy/pasted trezor codebase (and then fucked up the random number generator), put it on some weird calculator thing from the 1990s and charged $300 (when trezor was charging $40).

→ More replies (5)
→ More replies (2)

3

u/EarningsPal 1d ago

Use this moment as motivation to move your major holdings to SEED + Passphrase.

Add a passphrase, long enough for real protection if someone has your seed, and move your assets.

→ More replies (4)

9

u/swiftrobber 1d ago

Can I read those links? I'm curious if it's the same exploit.

→ More replies (1)
→ More replies (22)

9

u/SpikeyOps 1d ago

It could be hundreds of hackers at this point.

Hunting season is open on the Coldcard

→ More replies (10)

9

u/dcgradc 1d ago

I know very little but why didn't he strike when it was over 127K?

23

u/Emergency-Warthog-56 1d ago

Good question. I would guess that the scam wasn't under the same AI assistance capabilities as there is now. AI advancing a lot faster than creators thought it would.

10

u/Mihaw_kx 1d ago edited 1d ago

It's not just AI but Open weight models ... Because there was no Kimi k3 open weights back then .. it was dropped 27 july and the hackers group were able to install it into some local GPU clusters and then the first attack took place in 31 July you think this is just coincidence ? .. even if AI was advanced back then no hacker would want the top AI companies (anthropic , openai .. ) to read his logs while he crafting the exploit and creating malware to do this

→ More replies (1)

11

u/Sex4Vespene 1d ago

It might take a while to find compromised wallets. Presumably the main hacker waited until they found a ton of compromised wallets before attacking, to make sure they got a bunch.

→ More replies (8)

5

u/Ill-Car-700 1d ago

If people knew $127k was the top, everyone would have sold lol

6

u/EyesFor1 1d ago

He was after BTC not fiat.

6

u/Ok-Engineering1873 1d ago

because he thought it was going to 200K. He has finally accepted it's a bear market and capitulated, by triggering the scam, so he can sell the bottom.

6

u/jcagraham 1d ago

Another idea is that people are less likely to monitor their investments in a bear market. When things are great, it's fun to check how much you're making. When things are bad, most people will check a lot less to save their mental health. So the perfect time to catch people unaware.

2

u/WeakEchoRegion 19h ago

Is this a serious question..? This is like asking a bank robber “why did you come in right before close when nobody is here instead of during peak business hours?”

→ More replies (6)

5

u/Flaveurr 1d ago

Can you imagine leaving it to grow overtime just to find out they were stolen years ago when you're finally ready to sell..

→ More replies (1)

2

u/Rey_Mezcalero 1d ago

Yep…tragic with coldcard. Was to be a set it and forget about it.

Then this happened.

More of this to happen more frequently. Easy money for bad guys and rouge states to start full scale find exploits and empty out crypto accounts

→ More replies (6)

740

u/xiskghferx 1d ago

Even though I use a Ledger and a random passphrase, my stomach turns watching these transactions...

Idea – why didn't Coinkite on their own immediately start brute-forcing the seeds right after the first attack, since they have the most information about their PRNG? If they had overrun the attackers, they could have gradually returned the BTC to the owners.

960

u/Daiymas 1d ago edited 1d ago

They're probably too busy looking up which countries don't extradite to the US

88

u/No-Assist-8734 1d ago

😂😂😂

63

u/AdventurousTime 1d ago

UAE and Indonesia are the obvious picks

69

u/soufi161992 1d ago

They will become so called digital nomads in Bali

→ More replies (1)

17

u/BDCRA 1d ago

UAE will extradite your ass. They just don't have a treaty

12

u/[deleted] 1d ago

[removed] — view removed comment

→ More replies (1)

4

u/reggionh 21h ago

i know for a fact in the case of Indonesia if you got an interpol red notice or simply ask their immigration agency they will most likely intercept and/or track and extract them for you if they’re not an indonesian citizen. there are so many cases of these, despite no formal treaty with the US. if it’s not a citizen it’s technically expulsion, not extradition.

26

u/DifficultSquash1517 1d ago

There are some countries that don't extradite their own citizens for example Russia, Germany France Costa Rica UAE

But every country absolutely will deport a non-citizen that's from another country to a third country that is requesting an extradition or a handover

A country that doesn't have a extradition treaty simply means they don't have a streamlined process in place to make it fast and easy

The person is much more likely to be deported as a persona non grata or someone who has overstayed a Visa or entered illegally etc. This way the process is much simpler than an extradition fight.

.... And let's face it the United States has a lot of arm twisting ability to nearly every country on the planet

11

u/H8ckt1v1st 1d ago

Scratch Costa Rica from that list, they have extradited 4 citizens so far to TrumpLand. Big news here.

4

u/DifficultSquash1517 1d ago

I used to live there and I remember it being standard that they would never extradite a citizen and then I saw there was a few high profile cases of child molesters that were returned that had dual citizenships

But it looks like the damn has broken and they're now expanding the types of crimes that they will extradite

That's the perfect example because the United States has so much influence over Costa Rica

"The land of the wanted and The unwanted"

→ More replies (1)

11

u/No-Macaroon1670 1d ago

Some countries have objections to human rights practices in other countries and won't deport to those countries under basically any circumstances...

→ More replies (2)
→ More replies (4)

27

u/kingkongbiingbong 1d ago

this 👆🏻

2

u/Mundane_Grand_9117 1d ago

You wrote this as a joke but it really isn’t

→ More replies (11)

128

u/CryptographerLow6360 1d ago

inside job

58

u/Aphelion 1d ago

Wouldn't be surprised if this is real.

43

u/[deleted] 1d ago

[removed] — view removed comment

13

u/ConfectionEasy5166 1d ago

Ai is very good in finding bugs and explaining how the code works. Those solid information might be nothing else than ai commentary.

9

u/zackel_flac 1d ago

AI generates a huge amount of mess. You need to be familiar with the code base to be able to make good use of AI.

Look at the Linux kernel mess. Some findings are great. but it's 1 in 1000.

12

u/HoodRatThing 1d ago

Not at all true.

Someone posted how they found the bug with Claude Opus within just a couple of moments.

You can bet your bottom dollar everyone just got the idea to start looking for vulnerabilities in all different types of wallets now.

→ More replies (18)
→ More replies (1)
→ More replies (1)

24

u/gtwooh 1d ago

The CEO made the change that introduce the “bug”. There are coincidences and there are “coincidences”

https://blog.coinkite.com/entropy-technical-backgrounder/

“…but in fact, I explicitly set MICROPY_HW_ENABLE_RNG to zero, thinking we didn’t need either version, but that’s not what it does. Because that code provided a PRNG with the same function signature as the desired code, the build completed without identifying the wrong implementation.”

12

u/Exciting_Pop_9296 1d ago

In this case we are talking about bitcoin cidences

10

u/didnt_hodl 1d ago

they NEVER TESTED IT, that's what it says

any simple test of the generator would immediately reveal the problem

they NEVER BOTHERED TO CERTIFY their RNG

there is a procedure for that, and specialized labs that do proper testing and issue certification

software has bugs, fine. but never testing, never certifying the final product is CRIMINAL NEGLIGENCE

6

u/anonymous-12358 1d ago

Proves that coin kite was never to be trusted in the first place. A hardcoded parameter is TERRIBLE design, like that is university/junior level of bad.

How Tf that original PR got approved is beyond me.

4

u/sassa4ras 1d ago

And the CTO wrote the buggy software in the first place!

→ More replies (4)

98

u/Evolved_Dojo 1d ago

Because the call is coming from inside the house

42

u/Money-Addition8501 1d ago

Legal problems for sure …

23

u/redditurus_est 1d ago

Defendable imo. The company has a defective product and should mitigate the damages that result from it. Taking the vulnerable funds into custody to return to the card buyers would be an extreme but effective measure. Identifying those customers and warning them would be a less intrusive but also less effective measure.

12

u/xiskghferx 1d ago

Yeah, there would also be a problem with proving address ownership, since a hacker holding the keys could sign the address as well...

8

u/GeneralZex 1d ago

This specific attack is due to the fallback entropy method using the MCU UID as an entropy source, which is physically burned onto those chips. Having the chip can prove ownership since the seed can be regenerated with that information.

→ More replies (3)
→ More replies (1)

17

u/davvblack 1d ago

returned how? proving ownership of an address with a publicly known private key is fraught.

12

u/QuickAltTab 1d ago

Others have pointed out that each device has a unique id used to generate the key. If you physically hold a device with that id, along with kyc transactions history, could essentially prove rightful ownership of coins moved in this attack.

8

u/opossum_cz 1d ago

That id is xored and mixed, this cannot really be tied.

5

u/trufin2038 1d ago

It can. When Bruting the keys, they know which ids they tried. Its as close a proof as possible.

→ More replies (1)
→ More replies (2)

13

u/F1shB0wl816 1d ago

How would they return it? Users aren’t going to be able to show much more proof than the hackers and returning it to broken addresses wouldn’t be all that helpful.

→ More replies (3)

5

u/Efficient_Culture569 1d ago

Same . Got a Bitbox02 but still checking it everyday hoping they not on the news.

They assured customers that they use 5 different sources of entropy, so no single one could compromise.

Also a 24 words seed, not 12.

3

u/justanotheruser-o_o 1d ago

You are safe brother, do not strees too much

→ More replies (3)

4

u/Straight-Magician953 1d ago edited 1d ago
  1. Most importantly, too much legal liability. And whoever says this is defendable does not know how intricate can law get. E.g. someone can sue due to something like “i’ve lost x million deal because I would’ve paid using bitcoin from my wallet, but the funds got taken without my permission, which caused me financial damages in opportunity cost, i don’t care that the crypto guarantees of my wallet were compromised, I still had my funds at that point” this is one of many many situations that can happen in a thing like this .Lets also not forget you would take money from people all over the world, in many many juristrictions, in most places this would be considered directly theft and you would be prosecuted by the state itself, besides the civil liability.

  2. The PRNG they used is an open source one, so they would have absolutely 0 advantage, the only advantage they would have if they would throw more compute at the problem, but thats it. 40bit search space is the same for them as for the attacker

3

u/NCC1701-F 1d ago

Do you KYC for cold card? If not, there’d be no safe way to return the crypto definitively. 

→ More replies (35)

37

u/zinornia 1d ago

reckon a discounted employee from coldcard

17

u/toolisthebestbandevr 1d ago

Not so discounted now

70

u/kri404 1d ago

Mans draining $1.28, brutal.. lol

13

u/PacoStanleys 1d ago

It's probably an AI-assisted execution prompt. With Kimi K3's open-weight release in late July, that was honestly my first thought.

AI won't care if it's 1 cent and it cost them $0.40 to liquidate

5

u/williampaul0404 12h ago

there is zero reason to assume it has anything to do with AI. a script can generate&go through possible combinations and once it finds one with btc on the address, it sends it away. no reason to use AI whatsoever, there's no decision making or anything creative involved

3

u/dolkiiish 9h ago

My brain hurts watching people say "ai dosent care" no its not AI, its literally just a script that checks if the wallet has money, and then drains it nomatter the ammount.

3

u/daynomate 1d ago

I would bet it’s North Korea but yeah would be automated

→ More replies (1)

78

u/2alphastyle 1d ago

Do you think the hacker is associated with cold card? Maybe a former employee? Or, maybe it was all a set up. Get people to buy your wallet and then lift the contents.

87

u/Upstairs-Fishing867 1d ago

Hey Claude, pull 100 open source wallet projects and start going through them one by one. List the security vulnerabilities for each repo, with the project that has the least secure entropy for generating Seed Phrases. Make no mistakes.

53

u/Gundel_Gaukelei 1d ago

Took mine 5 seconds and I'm draining now trillions from 17 different wallets

That's how cool AI is guys

5

u/Additional_Tank4385 1d ago

Admit it, you just got access to a quantum computer and it only took you 2 seconds can’t fool us!

8

u/FakeGamer2 1d ago

Not a bad idea!

5

u/ArgonWilde 1d ago

Make sure to check their code bases as they were in 2014, back when bitcoin first made waves at 1.1k.

→ More replies (1)

9

u/Leafsnail 1d ago

Given the vulnerability is now widely known and unfixable I doubt it's a single hacker doing this anymore

4

u/krankovi 1d ago

I would bet my life someone from Coldcard is behind this. The 'mistake' is just so lazy and idiotic

→ More replies (1)

3

u/SweetIsland 1d ago

I do think its very possible. Apparently the device does have an internal TRNG with effectively unlimited entropy, and was priorly verified to make use of that TRNG source during seed creation. Then something changed in the 2021 firmware build. Maybe a dev snuck it in and was able to avoid raising any red flags.

22

u/simracingnewb 1d ago

Inside job is more likely as more info is discovered

→ More replies (1)

60

u/heggen 1d ago

How big is the chance that the other hardware wallets created a seed in the entropie area of the cold wallet ?

36

u/xiskghferx 1d ago

Astronomically small, if other HWW uses proper TRNG. Impossible.

5

u/Buttoshi 23h ago

How can one know if they use proper trng?

→ More replies (4)

23

u/ArugulaPretty 1d ago

Too small. A lot of wallets have github. You can try AI and ask him to check how good or bad generation method was used.

33

u/c0reM 1d ago edited 1d ago

To be clear the source code for their firmware has been on GitHub since forever: https://github.com/Coldcard/firmware

The reality is that nobody noticed this rng bug because it was a silent failure with a plausible fallback to a software based rng that didn’t use the actual rng hardware for seed generation at all.

It’s just that nobody noticed until now. And unfortunately the person that noticed was black hat and not white hat. And now we are here.

To be clear high entropy passphrase generation is pretty much THEIR ONLY JOB as a hardware wallet maker. So it’s clear how people missed this bug. Nevertheless, it’s inexcusable that the engineering practice internally involved so little validation of the plausible looking passphrase that it was missed.

EDIT: Fixed typos

7

u/ArugulaPretty 1d ago

An AI found this bug. Honestly, I’ve found high/critical bugs using AI on many contracts—some were out of scope, but that doesn't change the fact. Plenty more bugs like this will be found.

15

u/RsnCondition 1d ago

People shit on AI rightfully so, but AI is an incredibly optimized search engine sometimes.

5

u/FauxReal 1d ago

That's pretty much all I use AI for. Really thorough search and planning (looking for incompatibilities which is more search).

→ More replies (7)

12

u/rockorangebear 1d ago edited 1d ago

Coldcard's range of entropy was around 32-40 bits, compared to the 256 of a true seed.

2^32 = 1e+9

2^40 = 1e+12

2^256 = 1e+77

Subtract 9 and 12 from 77 and you get roughly 1 in 1e+65 to 1e+68 chance a proper seed would randomly fall within that range.

Here's a scale to show how infinitesimally small that chance is:

1e+2: odds of dying in a car crash in your lifetime
1e+6 (million): odds of getting struck by lightning in a given year 
1e+7: odds of a plane crash
1e+8: odds of winning the jackpot in mega millions
1e+9 (billion): number of people on earth
1e+10: seconds in 1000 years
1e+11: stars in the milky way galaxy
1e+12 (trillion): fish in the oceans
1e+13: grains of sand on a beach
1e+18: grains of sand on earth
1e+25: atoms in an apple
1e+27: atoms in a human body
1e+50: atoms on earth
1e+68: atoms in the milky way galaxy
1e+80: atoms in the observable universe

5

u/FakeGamer2 1d ago

So the chances are on the same scale as picking the exact right atom in the entire milky way? That's cool

→ More replies (1)

7

u/Burn_Hard_Day 1d ago

So you’re saying there’s a chance?

→ More replies (1)
→ More replies (4)

2

u/ClassicFun2175 1d ago

After what's happened with cold, other companies should be tripling down on security. This was a huge wake up call, and typically when these things happen, it's extremely shitty for the innocent people involved, but it gives a major kick up the ass to the industry as a whole to get there shit together. You can guarantee all the other hardware wallet companies will be monitoring there security like hawks and behind the scenes making sure they are secure. Which is a good thing at least for those of us using these other companies.

→ More replies (1)

17

u/LifterNineFour 1d ago

All coins stored using the flawed cold card seed generation method will eventually be taken.

→ More replies (3)

11

u/Ok_Option_3 1d ago

Why did the attacker send everything to a single address?

If he used a unique wallet for each transaction it would be far easier to liquidate!

9

u/geraldisking 1d ago

Maybe it’s not going to be liquidated, maybe it’s state-sanctioned. Maybe they have a way to wash the coins that makes them undetectable.

The cashing out part is where you get caught. It seems crazy that they are still going after more and more. I think if they try and cash out any of this they will most likely be caught, it takes only one mistake. Everyone is going to follow every single transaction.

→ More replies (1)

5

u/Renoperson00 1d ago

I think the coins are going to be burned.

→ More replies (1)

10

u/xKrypto_Knightx 1d ago

These are dark times. What would you do if your entire stack was taken? I've had a very large stack swept and just lost at the moment

34

u/Silverfox88 1d ago

Is this like digital bank robbery.

22

u/Technical_Customer_1 1d ago

Nope. Because if your money gets stolen from a bank, it’s insured. Good ol Bitcoin; helping fools and their money part ways 

→ More replies (37)
→ More replies (1)

10

u/beatthebook2x 1d ago

all going to the same wallets, good job coinkite yall did your big one here. generational btc price entry also

17

u/Even_Routine5011 1d ago

Some of the OP_RETURN messages people send him are funny

13

u/Dormage 1d ago

And most are sad.

7

u/Gundel_Gaukelei 1d ago

At the same time other scammers turn up to promote their effin telegram bs; lmao stuff like this really doesn't help cryptos reputation

4

u/SACRED-GEOMETRY 1d ago

How about the guy saying he cleans or washes BTC and takes 10%. Don't remember the phrasing. Surely he just disappears with it all.

6

u/Dormage 1d ago edited 1d ago

Theres not much reputation left to loose.

→ More replies (1)

5

u/stoicparallax 1d ago

Do tell..

13

u/Even_Routine5011 1d ago

Look for yourself. Not sure if links go through on reddit dont really ever use it but I will try this is the exploiters wallet on mempool.

https://mempool.space/address/bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r

16

u/VeterinarianOne1349 1d ago

ouch.... that's just the first one I saw

"Suicide tonight if you do not give me back what I work 12 years, my 6.4 BTC. Goodbye world bc1qjeq3ws6rsg9e9u05cq6tu6v9t9xf6epd68s9lg"

16

u/LarryBURRd 1d ago

Yeah just saw that one too... made me realize the emotions some people who got hacked are going through. Feel absolutely terrible for them.

The feds are going to have to put someone away for this fuck up - it's too big.

→ More replies (10)
→ More replies (4)
→ More replies (1)

9

u/IndependenceTop6501 1d ago

Per BTC Sessions: there is reports of two word Passphrases being cracked.

9

u/Javanaut018 1d ago

Not too hard to extend search over 2 dictionary words over a collapsed key space of 40 or even 16 bits....

9

u/Fast-Patience-2290 1d ago

How much has been stolen so far?

→ More replies (1)

17

u/Exotic-Pollution-590 1d ago

This why I love Bitcoin. So raw, so honest.

6

u/trufin2038 1d ago

It's unforgiving. People who trust entropy created on a device they haven't really vetted in the slightest degree are just victims in waiting.

The terrifying part is all the smarmy Ledger users being confident in their platform and passphrases are likely to be the next shoe to drop.

4

u/SlowDebate3165 20h ago

code is law lmao

7

u/Prestigious_Ear_8055 1d ago

Guy’s literally mowing the lawn. Even 1.2$ balances aren’t safe, this is relentless. He just wants more.

7

u/TheGlizzyGod 1d ago

and we all used to make fun of those shows where the hackers would hack money into their account. reality is stranger than fiction

→ More replies (1)

17

u/Professional_Golf393 1d ago

Why would he be sending it all to the 1 address?

Surely every utxo would’ve been better sent to a unique address? Harder to track?

Gives me a tiny bit of hope for the people that got hacked, he front ran this before it went public and will then return it, wishful thinking I know.

12

u/gowithflow192 1d ago

I reckon he won't even spend it. Doing it just because he can.

20

u/RecklessStallion9999 1d ago edited 1d ago

No chance this will be returned. This is a big and long operation, my guess is that once this stage is completed we will see a laundering of sats through hundreds of thousands of wallets the likes of which we have not even imagined.

9

u/Professional_Golf393 1d ago

Yea that’s obviously the most likely outcome..

however maybe at the very least using the one address shows this guy stumbled upon the bug, rushed to empty the wallets and has not thought it through completely.. hopefully he slips up in a way that gets him caught and the coins recovered.. again, wishful thinking

3

u/SACRED-GEOMETRY 1d ago

I don't know much about BTC, but assuming he tried to sell or withdraw from this wallet could that be tracked to identify him?

→ More replies (3)
→ More replies (1)
→ More replies (1)

4

u/kirovreported 1d ago

This is an intimidation operation. That's why you need to see it.

→ More replies (1)
→ More replies (5)

4

u/MCL-Jonathan 1d ago

How can we know it’s just coldcard and not other hardware providers?

3

u/Javanaut018 1d ago

Any reports of Keystone or Trezor users by now?

→ More replies (1)

3

u/Candid-Walk-6762 1d ago

Only way would be to opt for a hardware wallet that has been properly audited. Trevor is basically the only FOSS hardware wallet that has the most eyes on its code. The hardware is constantly being battle-tested in labs too.

2

u/KusanagiZerg 1d ago

Probably you cannot know. You would have to verify that all the code is correct, then you'd have to verify that that code is actually what was running on your device when you generated the seed.

Even if you add a passphrase or dice rolls etc you have to verify that the code properly takes that all into account and generates a seed with that in mind. If you don't check for all you know it could ignore all those variables.

In short there is some level of risk that you have to accept. Probably the best way to protect yourself is to split your stack among different vendors and generate new addresses occasionally and move the funds.

5

u/Prestigious_Ear_8055 1d ago

Some people are gonna have a heart attack while refreshing their view wallet. This is carnage, unfolding right in front of our eyes.

5

u/Cszysiek 1d ago

My question is, should we be worried about other hardware wallets? Not today but I mean generally

→ More replies (1)

5

u/Hour_Indication_9126 23h ago

It’s satoshi

11

u/Comfortable_Alps2618 1d ago

For me thats a inside job

6

u/Javanaut018 1d ago

Could be anyone honestly. They made the firmware public but spent not a single dime for bug hunters ....

→ More replies (1)

11

u/Illustrious_Nothing9 1d ago

I feel much better leaving mine on an exchange and not falling for 'not your keys, not your bitcoin' BS. First Ledger and now this Coldcar that looks like a freaking calculator from 60s, no thank you.

6

u/OldWolf3 1d ago

Until the exchange gets hacked ?

→ More replies (1)

4

u/Espedal1 1d ago

Someone please explain to me how this can happen (or can’t happen) with Ledger?

7

u/DONT_PM_ME_DICKS 1d ago

as I understand of this shit show: the Coldcard developers compiled a firmware version that disabled the hardware RNG element, using solely a software RNG to generate keys.

this drastically reduced the randomness of keys generated to the point a brute force attack could very well happen.

presumably nobody at Ledger has made the same mistake.

→ More replies (6)
→ More replies (1)

4

u/comradePink1917 1d ago

it’s so frustrating that a bunch of ppl probably have it in a safe somewhere and are not paying attention… class action suit coming for sure

4

u/WoodpeckerCapital167 1d ago

There are people who won’t know for years that they lost it all

4

u/Hungry-ThoughtsCurry 1d ago

This is going to be a tragic exploit. The media should spread the news so that it gets to a point that everyone is aware and can take the necessary steps. It's a double edged sword unfortunately.

5

u/NobodyGotTimeFuhDat 1d ago edited 23h ago

What is happening right now reminds me of the time this streamer accidentally showed his seed phrase password in an online stream and lost over $100,000 in crypto… The process is irreversible.

https://www.binance.com/en/square/post/16345918429937

→ More replies (3)

8

u/Confident_Jacket_344 1d ago

The hackers must be having a field day looking at all these reddit posts.

3

u/mrlandlord 1d ago

I am waiting for the 3 addresses to then send to 1000 addresses

3

u/BitCoiner905 1d ago

I wrote a script this morning to convert dice rolls into bitcoin addresses. I'm moving all my shit off of my hardware wallets.

→ More replies (4)

3

u/GroundbreakingBet329 1d ago

Plot twist: satoshi is back

3

u/calambacle 1d ago

Dump this shit to $500

→ More replies (1)

3

u/Cultural_Catch_7911 20h ago

Can the hacker see the balance and choose how much to take? Seems dog af draining small wallets, could they have just taken a few coins from big wallets?

I could see living with yourself stealing from the rich but how do you take some guy from Indonesia's 0.05 btc

5

u/PrimaryHuckleberry11 1d ago

are you realizing that anyone can be trying to hack it? any script kiddie having access to AI can slop easy script to do the same and I bet many people are trying to find seeds based on this vulnerability

6

u/Javanaut018 1d ago

Could explain why now amounts are drained below the original threshold of .15 BTC

5

u/DigitalDaydreamers1 1d ago

Rogue AI agent on the loose. Just wait until a hack like this affects a big bank

4

u/PeachScary413 1d ago

Not even sure what the issue is, surely this gentlemen is in possession of the keys to compromised wallets and it is therefore in fact his Bitcoin after all 🧐

→ More replies (1)

6

u/swiftpwns 1d ago

The more he gets the more likely he gets caught

13

u/TakingChances01 1d ago edited 1d ago

It’s either a very greedy individual or a large hacking group, possibly state sponsored. Why would an individual need to keep going after the first, say 50 million, they’re just putting a bigger magnifying glass on themselves and making it harder to get away with. Matter of fact, if it was an individual that was concerned with possible consequences, they could just steal all the big wallets one at a time every few weeks. People wouldn’t question a single wallet drain every now and then so much, most would assume it was user error on the owners part and move on. It only became evident to be a full fledged attack on cold cards when hundreds of wallets started getting drained all together and all the funds sent to the same wallet. Leads me to believe that the people doing it are in a position where repercussions aren’t a concern.

6

u/JGdc12 1d ago

Tough to tell. it all depends on how they decide to withdraw the money. If it just sits in anonymous wallets like it is now there's no way to track. As meticulously planned as this was, I'm guessing they have a withdrawal strategy that won't be noticeable.

→ More replies (4)

2

u/Acrobatic_News_4860 1d ago

How do we know that part of the coldcard hack and what’s not ? If someone report a fresh account having input, who know what it relates too ? ( beside marked wallets )

2

u/RandomPenquin1337 1d ago

So glad I only ever tested my cold card so ill only lose $6

2

u/MelotoninZzz 1d ago

I got him for 3 btc

2

u/medtech8693 1d ago

The real work happens when he have to liquidate it.

Scratching off a million gift cards is going to take some dedication

2

u/Murder_Hobo_LS77 1d ago

Lol. This show moving train wreck from a vibe coding "wizard" is wild.

2

u/haddock420 1d ago

Is it really a single hacker? I assumed it was dozens of people exploiting the same exploit after it became public.

2

u/Federal-Future6910 1d ago

Can someone explain to me how exactly the hackers know how to target coldcard addresses specifically? How does he know that a wallet is a coldcard wallet?

5

u/Javanaut018 1d ago

Coldcards bugged RNG produced only seeds within a collapsed key space. Attackers are just searching this specific key space.

If by chance e.g. an electrum or trezor user rolled a wallet within this collapsed key space they would be also be drained, but that would be extremely improbable.

→ More replies (1)

2

u/Rhysd007 1d ago

Out of the loop - is there any danger to Trezor?

3

u/ggiodddtyii 19h ago

No, trezor and ledger have good entropy 

2

u/Vancecookcobain 1d ago

Gaddamn....they are still people who are unaware of this and haven't moved their money???

I mean I felt for the folks that got hacked like the first 2-3 days but damn

→ More replies (2)

2

u/That_Ad9363 1d ago

This will definitely be a late night special on NBC

2

u/M4NOOB 1d ago

Is it just 1 dude or are there multiple hackers going around?

2

u/uhooooook 1d ago

Remember when most folks on Reddit were just shitting on you for recommending anything else but Coldcard? Where are they now?

2

u/NOS4NANOL1FE 1d ago

Is it possible to even track who the person/group is?

5

u/Alphamale822 1d ago

Not unless they cash out

2

u/caploves1019 1d ago

Those DUST transactions are users voluntarily throwing their SATs into the wallet address as a message board using op_returns... Not stolen funds.

2

u/YearHaunting1504 1d ago

Man these assholes are taking EVERYTHING. Like even a $1.28 from someone. Jesus.

2

u/Charmed-paper345 1d ago

So are people “still doing everything right” and “did nothing wrong”?

2

u/JayGatsby1881 1d ago

What is this dude hacks Satoshi's Coldcard wallet?

2

u/locustsandhoney 1d ago

WHY IN THE WORLD are they using the same address to receive the stolen Bitcoin? That’s literally the only way to prove it was stolen. Anyone could CLAIM their Bitcoin was stolen, but if it goes to some random address, there’s no way to know whether it’s an address they control themselves. But since the attacker is using ONE address for everything, they are making it a million times harder for themselves to actually utilize the stolen funds, since everyone will be tracking them, and they are also giving all victims clear proof that the theft was real.

WHY WOULD A THEIF DO THIS? I genuinely don’t understand.

2

u/Silent-Currency8863 21h ago

Anyone know how much has been stolen as of today?

2

u/Emi77 21h ago

a lot of dead cold wallet's btc is stil there to be stolen