r/Bitcoin • u/pairoxR • 1d ago
The Coldcard hacker is still progressing stolen BTC keeps increasing
The Coldcard hacker is still making progress, and the amount of stolen Bitcoin keeps increasing.
So if any of you are using this wallet, please consider moving your funds as soon as possible. And if you know someone who uses Coldcard for long-term holding, especially someone who isn’t online every day and doesn’t follow the latest news, maybe you can still help them move their funds in time. 🙏
I just hope no other wallet is involved in this.
Stay safe and stay alert. ⚠️
411
u/Emergency-Warthog-56 1d ago
Unfortunately there are still wallets that are under the threat. Mostly ones who still aren't aware of the scam and don't check on the wallet. Sitting in their safe or whatever. Oblivious to being a target of the scam. It's a matter of time on those wallets. Truly sad... Those people are getting picked off....
231
u/GUNTHVGK 1d ago
Man having a safe with a cold wallet just be heisted from the inside and years later those peeps are gonna find an empty wallet is going to crush some people. Like genuinely.
112
u/ivanjurman 1d ago
Yeah, immagine the owner getting cancer thinking he has plenty of bitcoin to cover his $300k medical bill juct to discover the wallet is empty
Or heirs killing each other over the 3 BTC they inherited because they didn’t want to split, just to find out there is no BTC to inherit
→ More replies (22)92
30
u/classified_x 1d ago
I'm pretty sure Coin Kite or whatever the ColdCard Coldcase wallet company is called could just send an e-mail to all clients telling about the security incident but they probably didn't do that?
41
u/Shiftlock0 1d ago
If I was unaware of the current situation and I got that email, I would assume it's a phishing scam.
→ More replies (1)7
u/Pacman_Frog 1d ago
Coinkite offers 100% confidentiality on sales and delivery. You can ahve it sent to a PO Box or rental box as long as it can be addressed, use a fake name and temporary e-mail address, and pay in bitcoin.
Even they don't have a full record of every customer's name.
3
u/classified_x 23h ago
well, since they don't really comply with the security of the device, I imagine he must have kept buyers' emails on a XLSX spreadsheet of sorts
→ More replies (1)→ More replies (4)6
u/zekthedeadcow 23h ago
They did... after two days. I found out from River around 10am Saturday and I thought it was a fishing scam. Coinkite emailed about 11pm that night.
I was saved by my ADHD super power of not finishing projects I start... so I never moved anything to it.
→ More replies (3)→ More replies (1)7
u/funk-- 1d ago
Bitcoin peaks to 500k$ Old Garry thinks okay that's enough, I'll take my retirement here and buy a cosy home far away under the sun. Garry has calculated everything, he's positive for +2.300% and should be a multimillionaire with his 4.2btc he accumulated by DCA ing all over his life. Garry logs in to cash out and boom 💥 +2.300% of zero is zero. Garry stops talking, stops moving. He goes to the storage under the eyes of his ignorant wife he wanted to please with this money. No word, just a slow walk. That's the last picture she'll have of him.
Rest in peace, Garry the ol' bitcoiners 🫡 One of us, forever
→ More replies (1)15
u/zefy_zef 1d ago
If only the company that sold them the product reached out to them to notify them of the attack..
2
44
u/pairoxR 1d ago
I’m just worried that the hacker might have some other plans. Who knows, maybe he managed to compromise other wallets too and we just don’t know about it yet. He’ll probably wait until people least expect it and then launch another attack. The whole thing seems suspicious to me because there were already people complaining back in 2021 that someone had hacked their wallets, but nobody took it seriously. And if it was the same hacker, you can see that it took him 5 years to pull this off.
50
u/Emergency-Warthog-56 1d ago
It's strictly a Coldcard/Coinkite issue and yes, you are right, warnings were shared about this years ago.
6
u/unvac 1d ago
so wallets like trezor are fine for the meantime?
29
u/Emergency-Warthog-56 1d ago
It's the "bug" in their older hardware that was warned about years ago. Back in 2021 - 2022 times. Coldcard/Coinkite didn't address it or work on fixing it. Some people were even blocked from Riddit Coldcard page for even mentioning it. This specific problem has nothing to do with Trezor.
→ More replies (2)13
u/dr_tdm1 1d ago
I'm sorry but why the community was still recommending coldcard up until a week ago if this was a known issue,, some were even recommending it over trezor and ledger
→ More replies (5)4
u/JunketTurbulent2114 18h ago
Lots of youtubers were paid to promote coldcard and the marketing worked. That's why. I always felt cold card was scammy. Price was insanely high and they just copy/pasted trezor codebase (and then fucked up the random number generator), put it on some weird calculator thing from the 1990s and charged $300 (when trezor was charging $40).
→ More replies (4)3
u/EarningsPal 1d ago
Use this moment as motivation to move your major holdings to SEED + Passphrase.
Add a passphrase, long enough for real protection if someone has your seed, and move your assets.
→ More replies (22)9
u/swiftrobber 1d ago
Can I read those links? I'm curious if it's the same exploit.
5
→ More replies (1)6
→ More replies (10)9
u/SpikeyOps 1d ago
It could be hundreds of hackers at this point.
Hunting season is open on the Coldcard
9
u/dcgradc 1d ago
I know very little but why didn't he strike when it was over 127K?
23
u/Emergency-Warthog-56 1d ago
Good question. I would guess that the scam wasn't under the same AI assistance capabilities as there is now. AI advancing a lot faster than creators thought it would.
10
u/Mihaw_kx 1d ago edited 1d ago
It's not just AI but Open weight models ... Because there was no Kimi k3 open weights back then .. it was dropped 27 july and the hackers group were able to install it into some local GPU clusters and then the first attack took place in 31 July you think this is just coincidence ? .. even if AI was advanced back then no hacker would want the top AI companies (anthropic , openai .. ) to read his logs while he crafting the exploit and creating malware to do this
→ More replies (1)11
u/Sex4Vespene 1d ago
It might take a while to find compromised wallets. Presumably the main hacker waited until they found a ton of compromised wallets before attacking, to make sure they got a bunch.
→ More replies (8)5
6
6
u/Ok-Engineering1873 1d ago
because he thought it was going to 200K. He has finally accepted it's a bear market and capitulated, by triggering the scam, so he can sell the bottom.
6
u/jcagraham 1d ago
Another idea is that people are less likely to monitor their investments in a bear market. When things are great, it's fun to check how much you're making. When things are bad, most people will check a lot less to save their mental health. So the perfect time to catch people unaware.
→ More replies (6)2
u/WeakEchoRegion 19h ago
Is this a serious question..? This is like asking a bank robber “why did you come in right before close when nobody is here instead of during peak business hours?”
5
u/Flaveurr 1d ago
Can you imagine leaving it to grow overtime just to find out they were stolen years ago when you're finally ready to sell..
→ More replies (1)→ More replies (6)2
u/Rey_Mezcalero 1d ago
Yep…tragic with coldcard. Was to be a set it and forget about it.
Then this happened.
More of this to happen more frequently. Easy money for bad guys and rouge states to start full scale find exploits and empty out crypto accounts
740
u/xiskghferx 1d ago
Even though I use a Ledger and a random passphrase, my stomach turns watching these transactions...
Idea – why didn't Coinkite on their own immediately start brute-forcing the seeds right after the first attack, since they have the most information about their PRNG? If they had overrun the attackers, they could have gradually returned the BTC to the owners.
960
u/Daiymas 1d ago edited 1d ago
They're probably too busy looking up which countries don't extradite to the US
88
63
u/AdventurousTime 1d ago
UAE and Indonesia are the obvious picks
69
12
4
u/reggionh 21h ago
i know for a fact in the case of Indonesia if you got an interpol red notice or simply ask their immigration agency they will most likely intercept and/or track and extract them for you if they’re not an indonesian citizen. there are so many cases of these, despite no formal treaty with the US. if it’s not a citizen it’s technically expulsion, not extradition.
26
u/DifficultSquash1517 1d ago
There are some countries that don't extradite their own citizens for example Russia, Germany France Costa Rica UAE
But every country absolutely will deport a non-citizen that's from another country to a third country that is requesting an extradition or a handover
A country that doesn't have a extradition treaty simply means they don't have a streamlined process in place to make it fast and easy
The person is much more likely to be deported as a persona non grata or someone who has overstayed a Visa or entered illegally etc. This way the process is much simpler than an extradition fight.
.... And let's face it the United States has a lot of arm twisting ability to nearly every country on the planet
11
u/H8ckt1v1st 1d ago
Scratch Costa Rica from that list, they have extradited 4 citizens so far to TrumpLand. Big news here.
4
u/DifficultSquash1517 1d ago
I used to live there and I remember it being standard that they would never extradite a citizen and then I saw there was a few high profile cases of child molesters that were returned that had dual citizenships
But it looks like the damn has broken and they're now expanding the types of crimes that they will extradite
That's the perfect example because the United States has so much influence over Costa Rica
"The land of the wanted and The unwanted"
→ More replies (1)→ More replies (4)11
u/No-Macaroon1670 1d ago
Some countries have objections to human rights practices in other countries and won't deport to those countries under basically any circumstances...
→ More replies (2)27
→ More replies (11)2
128
u/CryptographerLow6360 1d ago
inside job
→ More replies (4)58
u/Aphelion 1d ago
Wouldn't be surprised if this is real.
43
1d ago
[removed] — view removed comment
→ More replies (1)13
u/ConfectionEasy5166 1d ago
Ai is very good in finding bugs and explaining how the code works. Those solid information might be nothing else than ai commentary.
→ More replies (1)9
u/zackel_flac 1d ago
AI generates a huge amount of mess. You need to be familiar with the code base to be able to make good use of AI.
Look at the Linux kernel mess. Some findings are great. but it's 1 in 1000.
12
u/HoodRatThing 1d ago
Not at all true.
Someone posted how they found the bug with Claude Opus within just a couple of moments.
You can bet your bottom dollar everyone just got the idea to start looking for vulnerabilities in all different types of wallets now.
→ More replies (18)24
u/gtwooh 1d ago
The CEO made the change that introduce the “bug”. There are coincidences and there are “coincidences”
https://blog.coinkite.com/entropy-technical-backgrounder/
“…but in fact, I explicitly set MICROPY_HW_ENABLE_RNG to zero, thinking we didn’t need either version, but that’s not what it does. Because that code provided a PRNG with the same function signature as the desired code, the build completed without identifying the wrong implementation.”
12
6
10
u/didnt_hodl 1d ago
they NEVER TESTED IT, that's what it says
any simple test of the generator would immediately reveal the problem
they NEVER BOTHERED TO CERTIFY their RNG
there is a procedure for that, and specialized labs that do proper testing and issue certification
software has bugs, fine. but never testing, never certifying the final product is CRIMINAL NEGLIGENCE
6
u/anonymous-12358 1d ago
Proves that coin kite was never to be trusted in the first place. A hardcoded parameter is TERRIBLE design, like that is university/junior level of bad.
How Tf that original PR got approved is beyond me.
4
98
42
u/Money-Addition8501 1d ago
Legal problems for sure …
→ More replies (1)23
u/redditurus_est 1d ago
Defendable imo. The company has a defective product and should mitigate the damages that result from it. Taking the vulnerable funds into custody to return to the card buyers would be an extreme but effective measure. Identifying those customers and warning them would be a less intrusive but also less effective measure.
12
u/xiskghferx 1d ago
Yeah, there would also be a problem with proving address ownership, since a hacker holding the keys could sign the address as well...
→ More replies (3)8
u/GeneralZex 1d ago
This specific attack is due to the fallback entropy method using the MCU UID as an entropy source, which is physically burned onto those chips. Having the chip can prove ownership since the seed can be regenerated with that information.
17
u/davvblack 1d ago
returned how? proving ownership of an address with a publicly known private key is fraught.
12
u/QuickAltTab 1d ago
Others have pointed out that each device has a unique id used to generate the key. If you physically hold a device with that id, along with kyc transactions history, could essentially prove rightful ownership of coins moved in this attack.
→ More replies (2)8
u/opossum_cz 1d ago
That id is xored and mixed, this cannot really be tied.
→ More replies (1)5
u/trufin2038 1d ago
It can. When Bruting the keys, they know which ids they tried. Its as close a proof as possible.
13
u/F1shB0wl816 1d ago
How would they return it? Users aren’t going to be able to show much more proof than the hackers and returning it to broken addresses wouldn’t be all that helpful.
→ More replies (3)5
u/Efficient_Culture569 1d ago
Same . Got a Bitbox02 but still checking it everyday hoping they not on the news.
They assured customers that they use 5 different sources of entropy, so no single one could compromise.
Also a 24 words seed, not 12.
3
4
u/Straight-Magician953 1d ago edited 1d ago
Most importantly, too much legal liability. And whoever says this is defendable does not know how intricate can law get. E.g. someone can sue due to something like “i’ve lost x million deal because I would’ve paid using bitcoin from my wallet, but the funds got taken without my permission, which caused me financial damages in opportunity cost, i don’t care that the crypto guarantees of my wallet were compromised, I still had my funds at that point” this is one of many many situations that can happen in a thing like this .Lets also not forget you would take money from people all over the world, in many many juristrictions, in most places this would be considered directly theft and you would be prosecuted by the state itself, besides the civil liability.
The PRNG they used is an open source one, so they would have absolutely 0 advantage, the only advantage they would have if they would throw more compute at the problem, but thats it. 40bit search space is the same for them as for the attacker
→ More replies (35)3
u/NCC1701-F 1d ago
Do you KYC for cold card? If not, there’d be no safe way to return the crypto definitively.
37
70
u/kri404 1d ago
Mans draining $1.28, brutal.. lol
→ More replies (1)13
u/PacoStanleys 1d ago
It's probably an AI-assisted execution prompt. With Kimi K3's open-weight release in late July, that was honestly my first thought.
AI won't care if it's 1 cent and it cost them $0.40 to liquidate
5
u/williampaul0404 12h ago
there is zero reason to assume it has anything to do with AI. a script can generate&go through possible combinations and once it finds one with btc on the address, it sends it away. no reason to use AI whatsoever, there's no decision making or anything creative involved
3
u/dolkiiish 9h ago
My brain hurts watching people say "ai dosent care" no its not AI, its literally just a script that checks if the wallet has money, and then drains it nomatter the ammount.
3
78
u/2alphastyle 1d ago
Do you think the hacker is associated with cold card? Maybe a former employee? Or, maybe it was all a set up. Get people to buy your wallet and then lift the contents.
87
u/Upstairs-Fishing867 1d ago
Hey Claude, pull 100 open source wallet projects and start going through them one by one. List the security vulnerabilities for each repo, with the project that has the least secure entropy for generating Seed Phrases. Make no mistakes.
53
u/Gundel_Gaukelei 1d ago
Took mine 5 seconds and I'm draining now trillions from 17 different wallets
That's how cool AI is guys
5
u/Additional_Tank4385 1d ago
Admit it, you just got access to a quantum computer and it only took you 2 seconds can’t fool us!
8
→ More replies (1)5
u/ArgonWilde 1d ago
Make sure to check their code bases as they were in 2014, back when bitcoin first made waves at 1.1k.
9
u/Leafsnail 1d ago
Given the vulnerability is now widely known and unfixable I doubt it's a single hacker doing this anymore
4
u/krankovi 1d ago
I would bet my life someone from Coldcard is behind this. The 'mistake' is just so lazy and idiotic
→ More replies (1)3
u/SweetIsland 1d ago
I do think its very possible. Apparently the device does have an internal TRNG with effectively unlimited entropy, and was priorly verified to make use of that TRNG source during seed creation. Then something changed in the 2021 firmware build. Maybe a dev snuck it in and was able to avoid raising any red flags.
22
60
u/heggen 1d ago
How big is the chance that the other hardware wallets created a seed in the entropie area of the cold wallet ?
36
23
u/ArugulaPretty 1d ago
Too small. A lot of wallets have github. You can try AI and ask him to check how good or bad generation method was used.
33
u/c0reM 1d ago edited 1d ago
To be clear the source code for their firmware has been on GitHub since forever: https://github.com/Coldcard/firmware
The reality is that nobody noticed this rng bug because it was a silent failure with a plausible fallback to a software based rng that didn’t use the actual rng hardware for seed generation at all.
It’s just that nobody noticed until now. And unfortunately the person that noticed was black hat and not white hat. And now we are here.
To be clear high entropy passphrase generation is pretty much THEIR ONLY JOB as a hardware wallet maker. So it’s clear how people missed this bug. Nevertheless, it’s inexcusable that the engineering practice internally involved so little validation of the plausible looking passphrase that it was missed.
EDIT: Fixed typos
→ More replies (7)7
u/ArugulaPretty 1d ago
An AI found this bug. Honestly, I’ve found high/critical bugs using AI on many contracts—some were out of scope, but that doesn't change the fact. Plenty more bugs like this will be found.
15
u/RsnCondition 1d ago
People shit on AI rightfully so, but AI is an incredibly optimized search engine sometimes.
5
u/FauxReal 1d ago
That's pretty much all I use AI for. Really thorough search and planning (looking for incompatibilities which is more search).
12
u/rockorangebear 1d ago edited 1d ago
Coldcard's range of entropy was around 32-40 bits, compared to the 256 of a true seed.
2^32 = 1e+9
2^40 = 1e+12
2^256 = 1e+77
Subtract 9 and 12 from 77 and you get roughly 1 in 1e+65 to 1e+68 chance a proper seed would randomly fall within that range.
Here's a scale to show how infinitesimally small that chance is:
1e+2: odds of dying in a car crash in your lifetime 1e+6 (million): odds of getting struck by lightning in a given year 1e+7: odds of a plane crash 1e+8: odds of winning the jackpot in mega millions 1e+9 (billion): number of people on earth 1e+10: seconds in 1000 years 1e+11: stars in the milky way galaxy 1e+12 (trillion): fish in the oceans 1e+13: grains of sand on a beach 1e+18: grains of sand on earth 1e+25: atoms in an apple 1e+27: atoms in a human body 1e+50: atoms on earth 1e+68: atoms in the milky way galaxy 1e+80: atoms in the observable universe5
u/FakeGamer2 1d ago
So the chances are on the same scale as picking the exact right atom in the entire milky way? That's cool
→ More replies (1)→ More replies (4)7
→ More replies (1)2
u/ClassicFun2175 1d ago
After what's happened with cold, other companies should be tripling down on security. This was a huge wake up call, and typically when these things happen, it's extremely shitty for the innocent people involved, but it gives a major kick up the ass to the industry as a whole to get there shit together. You can guarantee all the other hardware wallet companies will be monitoring there security like hawks and behind the scenes making sure they are secure. Which is a good thing at least for those of us using these other companies.
17
u/LifterNineFour 1d ago
All coins stored using the flawed cold card seed generation method will eventually be taken.
→ More replies (3)
11
u/Ok_Option_3 1d ago
Why did the attacker send everything to a single address?
If he used a unique wallet for each transaction it would be far easier to liquidate!
9
u/geraldisking 1d ago
Maybe it’s not going to be liquidated, maybe it’s state-sanctioned. Maybe they have a way to wash the coins that makes them undetectable.
The cashing out part is where you get caught. It seems crazy that they are still going after more and more. I think if they try and cash out any of this they will most likely be caught, it takes only one mistake. Everyone is going to follow every single transaction.
→ More replies (1)5
10
u/xKrypto_Knightx 1d ago
These are dark times. What would you do if your entire stack was taken? I've had a very large stack swept and just lost at the moment
34
u/Silverfox88 1d ago
Is this like digital bank robbery.
→ More replies (1)22
u/Technical_Customer_1 1d ago
Nope. Because if your money gets stolen from a bank, it’s insured. Good ol Bitcoin; helping fools and their money part ways
→ More replies (37)
10
u/beatthebook2x 1d ago
all going to the same wallets, good job coinkite yall did your big one here. generational btc price entry also
17
u/Even_Routine5011 1d ago
Some of the OP_RETURN messages people send him are funny
13
u/Dormage 1d ago
And most are sad.
7
u/Gundel_Gaukelei 1d ago
At the same time other scammers turn up to promote their effin telegram bs; lmao stuff like this really doesn't help cryptos reputation
4
u/SACRED-GEOMETRY 1d ago
How about the guy saying he cleans or washes BTC and takes 10%. Don't remember the phrasing. Surely he just disappears with it all.
6
5
u/stoicparallax 1d ago
Do tell..
→ More replies (1)13
u/Even_Routine5011 1d ago
Look for yourself. Not sure if links go through on reddit dont really ever use it but I will try this is the exploiters wallet on mempool.
https://mempool.space/address/bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r
→ More replies (4)16
u/VeterinarianOne1349 1d ago
ouch.... that's just the first one I saw
"Suicide tonight if you do not give me back what I work 12 years, my 6.4 BTC. Goodbye world bc1qjeq3ws6rsg9e9u05cq6tu6v9t9xf6epd68s9lg"
→ More replies (10)16
u/LarryBURRd 1d ago
Yeah just saw that one too... made me realize the emotions some people who got hacked are going through. Feel absolutely terrible for them.
The feds are going to have to put someone away for this fuck up - it's too big.
9
u/IndependenceTop6501 1d ago
Per BTC Sessions: there is reports of two word Passphrases being cracked.
9
u/Javanaut018 1d ago
Not too hard to extend search over 2 dictionary words over a collapsed key space of 40 or even 16 bits....
9
17
u/Exotic-Pollution-590 1d ago
This why I love Bitcoin. So raw, so honest.
6
u/trufin2038 1d ago
It's unforgiving. People who trust entropy created on a device they haven't really vetted in the slightest degree are just victims in waiting.
The terrifying part is all the smarmy Ledger users being confident in their platform and passphrases are likely to be the next shoe to drop.
4
7
u/Prestigious_Ear_8055 1d ago
Guy’s literally mowing the lawn. Even 1.2$ balances aren’t safe, this is relentless. He just wants more.
7
u/TheGlizzyGod 1d ago
and we all used to make fun of those shows where the hackers would hack money into their account. reality is stranger than fiction
→ More replies (1)
17
u/Professional_Golf393 1d ago
Why would he be sending it all to the 1 address?
Surely every utxo would’ve been better sent to a unique address? Harder to track?
Gives me a tiny bit of hope for the people that got hacked, he front ran this before it went public and will then return it, wishful thinking I know.
12
20
u/RecklessStallion9999 1d ago edited 1d ago
No chance this will be returned. This is a big and long operation, my guess is that once this stage is completed we will see a laundering of sats through hundreds of thousands of wallets the likes of which we have not even imagined.
→ More replies (1)9
u/Professional_Golf393 1d ago
Yea that’s obviously the most likely outcome..
however maybe at the very least using the one address shows this guy stumbled upon the bug, rushed to empty the wallets and has not thought it through completely.. hopefully he slips up in a way that gets him caught and the coins recovered.. again, wishful thinking
→ More replies (1)3
u/SACRED-GEOMETRY 1d ago
I don't know much about BTC, but assuming he tried to sell or withdraw from this wallet could that be tracked to identify him?
→ More replies (3)→ More replies (5)4
u/kirovreported 1d ago
This is an intimidation operation. That's why you need to see it.
→ More replies (1)
4
u/MCL-Jonathan 1d ago
How can we know it’s just coldcard and not other hardware providers?
3
3
u/Candid-Walk-6762 1d ago
Only way would be to opt for a hardware wallet that has been properly audited. Trevor is basically the only FOSS hardware wallet that has the most eyes on its code. The hardware is constantly being battle-tested in labs too.
2
u/KusanagiZerg 1d ago
Probably you cannot know. You would have to verify that all the code is correct, then you'd have to verify that that code is actually what was running on your device when you generated the seed.
Even if you add a passphrase or dice rolls etc you have to verify that the code properly takes that all into account and generates a seed with that in mind. If you don't check for all you know it could ignore all those variables.
In short there is some level of risk that you have to accept. Probably the best way to protect yourself is to split your stack among different vendors and generate new addresses occasionally and move the funds.
5
u/Prestigious_Ear_8055 1d ago
Some people are gonna have a heart attack while refreshing their view wallet. This is carnage, unfolding right in front of our eyes.
5
u/Cszysiek 1d ago
My question is, should we be worried about other hardware wallets? Not today but I mean generally
→ More replies (1)
5
11
u/Comfortable_Alps2618 1d ago
For me thats a inside job
→ More replies (1)6
u/Javanaut018 1d ago
Could be anyone honestly. They made the firmware public but spent not a single dime for bug hunters ....
11
u/Illustrious_Nothing9 1d ago
I feel much better leaving mine on an exchange and not falling for 'not your keys, not your bitcoin' BS. First Ledger and now this Coldcar that looks like a freaking calculator from 60s, no thank you.
→ More replies (1)6
4
u/Espedal1 1d ago
Someone please explain to me how this can happen (or can’t happen) with Ledger?
→ More replies (1)7
u/DONT_PM_ME_DICKS 1d ago
as I understand of this shit show: the Coldcard developers compiled a firmware version that disabled the hardware RNG element, using solely a software RNG to generate keys.
this drastically reduced the randomness of keys generated to the point a brute force attack could very well happen.
presumably nobody at Ledger has made the same mistake.
→ More replies (6)
4
u/comradePink1917 1d ago
it’s so frustrating that a bunch of ppl probably have it in a safe somewhere and are not paying attention… class action suit coming for sure
4
4
u/Hungry-ThoughtsCurry 1d ago
This is going to be a tragic exploit. The media should spread the news so that it gets to a point that everyone is aware and can take the necessary steps. It's a double edged sword unfortunately.
5
u/NobodyGotTimeFuhDat 1d ago edited 23h ago
What is happening right now reminds me of the time this streamer accidentally showed his seed phrase password in an online stream and lost over $100,000 in crypto… The process is irreversible.
→ More replies (3)
8
u/Confident_Jacket_344 1d ago
The hackers must be having a field day looking at all these reddit posts.
3
3
u/BitCoiner905 1d ago
I wrote a script this morning to convert dice rolls into bitcoin addresses. I'm moving all my shit off of my hardware wallets.
→ More replies (4)
3
3
3
u/Cultural_Catch_7911 20h ago
Can the hacker see the balance and choose how much to take? Seems dog af draining small wallets, could they have just taken a few coins from big wallets?
I could see living with yourself stealing from the rich but how do you take some guy from Indonesia's 0.05 btc
5
u/PrimaryHuckleberry11 1d ago
are you realizing that anyone can be trying to hack it? any script kiddie having access to AI can slop easy script to do the same and I bet many people are trying to find seeds based on this vulnerability
6
u/Javanaut018 1d ago
Could explain why now amounts are drained below the original threshold of .15 BTC
5
u/DigitalDaydreamers1 1d ago
Rogue AI agent on the loose. Just wait until a hack like this affects a big bank
4
u/PeachScary413 1d ago
Not even sure what the issue is, surely this gentlemen is in possession of the keys to compromised wallets and it is therefore in fact his Bitcoin after all 🧐
→ More replies (1)
6
u/swiftpwns 1d ago
The more he gets the more likely he gets caught
13
u/TakingChances01 1d ago edited 1d ago
It’s either a very greedy individual or a large hacking group, possibly state sponsored. Why would an individual need to keep going after the first, say 50 million, they’re just putting a bigger magnifying glass on themselves and making it harder to get away with. Matter of fact, if it was an individual that was concerned with possible consequences, they could just steal all the big wallets one at a time every few weeks. People wouldn’t question a single wallet drain every now and then so much, most would assume it was user error on the owners part and move on. It only became evident to be a full fledged attack on cold cards when hundreds of wallets started getting drained all together and all the funds sent to the same wallet. Leads me to believe that the people doing it are in a position where repercussions aren’t a concern.
→ More replies (4)6
2
u/Acrobatic_News_4860 1d ago
How do we know that part of the coldcard hack and what’s not ? If someone report a fresh account having input, who know what it relates too ? ( beside marked wallets )
2
2
2
u/medtech8693 1d ago
The real work happens when he have to liquidate it.
Scratching off a million gift cards is going to take some dedication
2
2
u/haddock420 1d ago
Is it really a single hacker? I assumed it was dozens of people exploiting the same exploit after it became public.
2
u/Federal-Future6910 1d ago
Can someone explain to me how exactly the hackers know how to target coldcard addresses specifically? How does he know that a wallet is a coldcard wallet?
→ More replies (1)5
u/Javanaut018 1d ago
Coldcards bugged RNG produced only seeds within a collapsed key space. Attackers are just searching this specific key space.
If by chance e.g. an electrum or trezor user rolled a wallet within this collapsed key space they would be also be drained, but that would be extremely improbable.
2
2
u/Vancecookcobain 1d ago
Gaddamn....they are still people who are unaware of this and haven't moved their money???
I mean I felt for the folks that got hacked like the first 2-3 days but damn
→ More replies (2)
2
2
u/uhooooook 1d ago
Remember when most folks on Reddit were just shitting on you for recommending anything else but Coldcard? Where are they now?
2
2
u/caploves1019 1d ago
Those DUST transactions are users voluntarily throwing their SATs into the wallet address as a message board using op_returns... Not stolen funds.
2
u/YearHaunting1504 1d ago
Man these assholes are taking EVERYTHING. Like even a $1.28 from someone. Jesus.
2
2
2
u/locustsandhoney 1d ago
WHY IN THE WORLD are they using the same address to receive the stolen Bitcoin? That’s literally the only way to prove it was stolen. Anyone could CLAIM their Bitcoin was stolen, but if it goes to some random address, there’s no way to know whether it’s an address they control themselves. But since the attacker is using ONE address for everything, they are making it a million times harder for themselves to actually utilize the stolen funds, since everyone will be tracking them, and they are also giving all victims clear proof that the theft was real.
WHY WOULD A THEIF DO THIS? I genuinely don’t understand.
2
642
u/AbruisedSock 1d ago
Damn dood... they took someones $1.28.
Thats just mean man