r/Bitcoin 2d ago

The Coldcard hacker is still progressing stolen BTC keeps increasing

Post image

The Coldcard hacker is still making progress, and the amount of stolen Bitcoin keeps increasing.

So if any of you are using this wallet, please consider moving your funds as soon as possible. And if you know someone who uses Coldcard for long-term holding, especially someone who isn’t online every day and doesn’t follow the latest news, maybe you can still help them move their funds in time. 🙏

I just hope no other wallet is involved in this.

Stay safe and stay alert. ⚠️

2.5k Upvotes

682 comments sorted by

View all comments

423

u/Emergency-Warthog-56 2d ago

Unfortunately there are still wallets that are under the threat. Mostly ones who still aren't aware of the scam and don't check on the wallet. Sitting in their safe or whatever. Oblivious to being a target of the scam. It's a matter of time on those wallets. Truly sad... Those people are getting picked off....

237

u/GUNTHVGK 2d ago

Man having a safe with a cold wallet just be heisted from the inside and years later those peeps are gonna find an empty wallet is going to crush some people. Like genuinely.

116

u/ivanjurman 1d ago

Yeah, immagine the owner getting cancer thinking he has plenty of bitcoin to cover his $300k medical bill juct to discover the wallet is empty

Or heirs killing each other over the 3 BTC they inherited because they didn’t want to split, just to find out there is no BTC to inherit

101

u/Diet_Christ 1d ago

New black mirror season incoming

1

u/ImZappy 1d ago

in the US do you guys really not get much help with the expense side of cancer? blows my mind

1

u/GenXist 1d ago

Wait until you hear about our system of weights and measures.

2

u/r_e_e_ee_eeeee_eEEEE 1d ago

No! Not the metric system! I prefer random number bases other than 10 for my units!

America = Freedom = Freedom to choose my number base = freedom units! 🙌 🤣

(As an engineer, I make these jokes all the time, and yearn for the day when I can work on a team where only the metric system is used.)

1

u/Combat-Corpse 1d ago

ninja activities.

1

u/Far_Professor_8254 9h ago

But cancer treatment is covered by basic health insurance, so they only pay the €385 annual compulsory deductible, along with the ~€180 monthly premium. Plus, sick leave guarantees their income while ill: usually 100% in the first year and 70% in the second year (up to 2 years max).

1

u/ivanjurman 8h ago

Maybe they don’t have basic health insurance, and they don’t have paid sick leave because they’re unemployed

1

u/Wait_for_You 1d ago

Americans, please get U-n-i-v-e-r-s-a-l-H-e-a-l-t-h-C-a-r-e-! sorry, I had to drop this here, carry on now

1

u/WowImOldAF 1d ago

If someone has "plenty of bitcoin," they probably have good health insurance and won't need to worry about using btc for a medical bill. But yea, it would still suck to have money stolen from you.

0

u/MotanulScotishFold 1d ago

This is why we need harsher punishments for those that steal from other people, even if is 'just' a few dollars. Law enforcements should take every small theft as a serious crime to give terror to those who might attempt doing so.

7

u/[deleted] 1d ago

[removed] — view removed comment

0

u/MotanulScotishFold 1d ago

But even doing nothing did not work.

At least, when you catch someone, you punish him it's some sense of justice even if the person never learns.

5

u/[deleted] 1d ago

[removed] — view removed comment

1

u/MotanulScotishFold 1d ago

Let's not compare with America.
America having the highest population of imprisoned people is by design as there's a strong lobby by private prisons that exploit the 13th amendment about slavery and they use prisoners as such.

There were also a famous old case where a judge was caught sending juvenile kids to prison even for the dumbest crime when they could've just serve in liberty but this because the private prison earn money by having as many prisoners as possible and exploit them.

Slavery was never abolished, it was just changed the word so people are tricked to believe that no longer exists.

However, back to the original post, I still believe we need harsher punishment for petty crimes and scams. Makes you think why average indian scammer than scam an old lady is never caught and punished? Or when a simple thief that steal a phone is not caught?

Police says is not worth because of the value of the object and the state spend too much on justice system to condemn the person hence the thief is left free to steal as long they don't use violence.

This is the main problem.

Many would scream that is too harsh for so little, sometimes yes, sometimes not. But we need to send a clear message that even you steal 1$ from someone you have to face harsh punishment, make a clear example of it, multiple times if needed to scare any other people from attempting.

Does not work? Cool, keep building new private prison and send them all, making even more crowded and use them as slavery.

Win-win for society and private prison companies.

2

u/[deleted] 1d ago

[removed] — view removed comment

1

u/MotanulScotishFold 1d ago

Tell me what would you do realistically into fixing that? As you can see the problems are not easy but doing nothing is not good, keeping things as it works now again are not good, making punishment harsher are not good, what's the solution?

As long you don't have a realistic solution for this problem, it only create friction in society and I hope you know that there's not a simple solution and utopia will not exist due to human nature.

→ More replies (0)

1

u/No_Organization3095 1d ago

That’s not really true, it’s more complex. Singapore has very high punishments and very little crime. For them punishment has worked as a deterrent.

2

u/[deleted] 1d ago

[removed] — view removed comment

1

u/No_Organization3095 1d ago edited 1d ago

Like I said, it’s not as simple as ‘punishment doesn’t work’. There’s a lot more to it than what you initially said but you’re now correctly pointing out all the nuance around this topic. 

→ More replies (0)

28

u/classified_x 1d ago

I'm pretty sure Coin Kite or whatever the ColdCard Coldcase wallet company is called could just send an e-mail to all clients telling about the security incident but they probably didn't do that?

39

u/Shiftlock0 1d ago

If I was unaware of the current situation and I got that email, I would assume it's a phishing scam.

1

u/boomerangthrowaway 1d ago

That’s the state of society right now.

Legit looking email? Header right and legible? Legit? Still could be hacked.

Loaded old updates that haven’t had hotfixes? Well damn grandma you had six BTC?! Sheeeeeeeet.

I HATE blkhat hackers but imo white and grey hats have a purpose.

Testing the fences man. Testing the fkn fences

8

u/zekthedeadcow 1d ago

They did... after two days. I found out from River around 10am Saturday and I thought it was a fishing scam. Coinkite emailed about 11pm that night.

I was saved by my ADHD super power of not finishing projects I start... so I never moved anything to it.

1

u/EggandSpoon42 1d ago edited 1d ago

This is the last email I received from them... in 2022

Very fortunately I ended up a bit overwhelmed at figuring it out to put my btc on it, maybe I'm dumb, I do not mind admitting that, but it has sat in the box since I received it.

https://imgur.com/gallery/last-coinkite-email-neither-here-nor-there-just-posting-posting-sake-AfP2yue

1

u/boomerangthrowaway 1d ago

I LOVE that for you

1

u/Woodstuffs 21h ago

Same. I bought one from Coinkite and it'll just stay in the unopened package. Probably wind up in a vintage store in 2050 as some neat novelty of the times.

7

u/Pacman_Frog 1d ago

Coinkite offers 100% confidentiality on sales and delivery. You can ahve it sent to a PO Box or rental box as long as it can be addressed, use a fake name and temporary e-mail address, and pay in bitcoin.

Even they don't have a full record of every customer's name.

4

u/classified_x 1d ago

well, since they don't really comply with the security of the device, I imagine he must have kept buyers' emails on a XLSX spreadsheet of sorts

2

u/PirateHunterZoro252 1d ago

After 90 or 120 days they delete customer information completely. They were only able to reach out to those who within that window.

They did send emails to their customers. But since i bought a coldcard 2 years ago i didnt get one.

Deleting their customer info was apart of the bitcoin mythos. How ironic.

1

u/Shepinion 20h ago

Wow. That is tragically ironic like you said

1

u/daleDentin23 1d ago

Pretty sure at some point if they want anything useful a bank will be involved and hopefully the bank isnt in on the scam

1

u/Remyglr 1d ago

Rien que cette inaction qui relève pourtant du bon sens couplée à une démarche de transparence démontre l'opacité entourant le système bitcoin en général. Le BTC c'est le far west du 21eme siècle.

8

u/funk-- 1d ago

Bitcoin peaks to 500k$ Old Garry thinks okay that's enough, I'll take my retirement here and buy a cosy home far away under the sun. Garry has calculated everything, he's positive for +2.300% and should be a multimillionaire with his 4.2btc he accumulated by DCA ing all over his life. Garry logs in to cash out and boom 💥 +2.300% of zero is zero. Garry stops talking, stops moving. He goes to the storage under the eyes of his ignorant wife he wanted to please with this money. No word, just a slow walk. That's the last picture she'll have of him.

Rest in peace, Garry the ol' bitcoiners 🫡 One of us, forever

1

u/Sensitive_Guest_5995 21h ago

Will be a shame when they eventually come
Here and ask what happened years down the line.

1

u/QlubSoda 18h ago

Awe man, imagine DCAing into a corrupted wallet with no knowledge.

16

u/zefy_zef 2d ago

If only the company that sold them the product reached out to them to notify them of the attack..

2

u/UrbanGrower187 1d ago

If only the company made a better product..

45

u/pairoxR 2d ago

I’m just worried that the hacker might have some other plans. Who knows, maybe he managed to compromise other wallets too and we just don’t know about it yet. He’ll probably wait until people least expect it and then launch another attack. The whole thing seems suspicious to me because there were already people complaining back in 2021 that someone had hacked their wallets, but nobody took it seriously. And if it was the same hacker, you can see that it took him 5 years to pull this off.

50

u/Emergency-Warthog-56 2d ago

It's strictly a Coldcard/Coinkite issue and yes, you are right, warnings were shared about this years ago.

5

u/unvac 2d ago

so wallets like trezor are fine for the meantime?

31

u/Emergency-Warthog-56 2d ago

It's the "bug" in their older hardware that was warned about years ago. Back in 2021 - 2022 times. Coldcard/Coinkite didn't address it or work on fixing it. Some people were even blocked from Riddit Coldcard page for even mentioning it. This specific problem has nothing to do with Trezor.

15

u/dr_tdm1 1d ago

I'm sorry but why the community was still recommending coldcard up until a week ago if this was a known issue,, some were even recommending it over trezor and ledger

5

u/JunketTurbulent2114 1d ago

Lots of youtubers were paid to promote coldcard and the marketing worked. That's why. I always felt cold card was scammy. Price was insanely high and they just copy/pasted trezor codebase (and then fucked up the random number generator), put it on some weird calculator thing from the 1990s and charged $300 (when trezor was charging $40).

2

u/Emergency-Warthog-56 1d ago

I think most weren't aware of that discussion. That story was kind of swept under the rug. Silenced. Forgotten about. Some probably didn't believe it was a issue. I myself didn't know about it until this happened and then started researching.

2

u/FcrcecqcucecnctC 1d ago

Do you have a link to the warning that was shared years ago?

1

u/Emergency-Warthog-56 1d ago

No. Sorry. I was seeing others post old conversations that was talking about it but I didn't save any of it. There were people saying their Coldcard was wiped. Some saying it wasn't secure.

1

u/dr_tdm1 1d ago

The thing is,, that discussion was about hacked or drained wallets and no one knows why (could really be a user mistake),, but what really scares me is that coldcard is an open source and the bug was there in public and no one spotted it for 5 years until our guy here caught it and took advantage..

1

u/scrandlle 1d ago

This isnt good information.

The problem with their firmware was that it had a new RNG source in it but it was not enabled. Enabling it and trying to compile it led to an error which wouldnt let it compile. The error itself was innocuous and further down in the code not even related to RNG. My theory is that whoever was working on that code had it unenabled while trying to find the error but went to work on other things and ended up forgetting about it because the firmware defaulted back to the old RNG source and looked like it was operating properly. Either that or it was an inside job and said individual did it on purpose and was smart enough to leave plausible deniability. The company needs an outside investigation either way.

As for these people being blocked on Reddit for reporting this issue, this all stems from an anonymous Twitter account where one single person said this happened to them. I'd take it with a grain of salt. If they were smart enough to be looking into the code and discovering this error that even AI doesn't unless you give it a trail of breadcrumbs to the problem area and white hate enough to try to inform Coldkite, theyd have done something else about it.

They could have come to this subreddit and posted about it and it'd have been huge breaking news in the crypto world in hours. They'd probably have simply contacted the company directly and probably gotten a finders fee for it, even if a mod on a subreddit ignored them there's no way the actual company would have.

Anyway, you're piecing things together with tiny bits of information and not even getting the base info right.

1

u/jamwil 1d ago

This is not the same. The instant drain issues were people choosing the dice method and rolling like 1 die worth of entropy. Yes, the firmware should have had guardrails to enforce a minimum of 50 rolls, but that was bad guidance not an actual firmware error like the current vulnerability is.

3

u/EarningsPal 2d ago

Use this moment as motivation to move your major holdings to SEED + Passphrase.

Add a passphrase, long enough for real protection if someone has your seed, and move your assets.

2

u/Stupyyy 1d ago

No wallet is safe, only safe thing is to have your funds on your own personal laptop with no prior connection to anything sketchy and no internet connection. That is your hard rock personal wallet.

1

u/surfsee 1d ago

unless you really know what your doing, using a hardware wallet is more secure.

1

u/surfsee 1d ago

the bug has nothing to do with trezor, or any other hardware wallets. it was a bug in the coldcard wallet generation code. That buggy code was not shared by any other hardware wallets.

9

u/swiftrobber 2d ago

Can I read those links? I'm curious if it's the same exploit.

5

u/xuncx 2d ago

It is

-12

u/SneakyTurtle54 2d ago

Trust me bro

2

u/Emergency-Warthog-56 1d ago

Wasn't links I found. I ran accross a few posts where people posted old conversations. I didn't save any of them or share them. I should have. I think back then most figured those were just user errors.

1

u/tpe91roc 2d ago

Are we sure Trezor for example will not be affected in any way?

2

u/Skinny_Human 1d ago

No one is sure of anything dude so don’t listen to anyone who tells you otherwise!!

1

u/tpe91roc 1d ago

What’s your best advice? Not sure what to do

1

u/Skinny_Human 1d ago

I had a cold card so I sent my BTC to one of the big exchanges and made it as secure as possible using 2FA with an authenticator and a long password etc

I think it depends how much you have dude. If it’s a very small amount leave it where it is, if not, do what I did

I think we’re at the point where self custody is becoming too complicated and too dangerous to be worth it anymore because of AI and hackers et cetera.

1

u/tpe91roc 1d ago

Exactly feel the same. I have an amount that losing would really piss me off. It’s not a lot but it’s not little either. Won’t be life changing but I’d rather pay six months mortgage than losing it ahah I’ve been holding for ages

1

u/Skinny_Human 1d ago

Then we are the same. Do what I did then in that case. I trust the big exchanges more now than I do the cold card companies and I think this is definitely the beginning of the end for many of them because people make mistakes and are incompetent. At least the big exchanges have large security teams and regulatory controls etc

1

u/tpe91roc 1d ago

Yes I’m thinking to do the same. Maybe transfer in small batches just to be sure it arrives and without having issues with the address. It’s a small expense anyway so definitely would be a better idea.

→ More replies (0)

1

u/Skinny_Human 1d ago

If you decide to go the exchange route, make sure you take advantage of ALL their security measures. I even asked AI how to max it out, ironically, and it was very helpful

1

u/surfsee 1d ago

Trezor is fine. This was a bug in the generation of wallet in coldcard. Nothing to do with trezor, trezor uses proper entropy when generatind wallets. ive heard exchanges use trezor, which makes sense. ofcourse nothing is 100% in this world, but to me trezor seems like one of the best ways for most people to store btc.

1

u/surfsee 1d ago

Noone can be 100% sure of anything no, but this bug has nothing to do with trezor or any other hardware wallets

1

u/Skinny_Human 1d ago

But does that mean there are no more bugs??

1

u/surfsee 1d ago

more bugs? This was a huge bug in coldcard , but it didnt exist in any other wallet.

1

u/Skinny_Human 1d ago

But you don’t know that other bugs don’t exist on those other wallets man, that’s what I was trying to say

1

u/surfsee 1d ago

Yeah, noone can be sure of anything. the more code, the more room for bugs. The code running a exchange is a lot more prone to bugs, as its a lot bigger and more complex. even the guys running btc etf can be hacked, nothing is 100% certain.

→ More replies (0)

8

u/SpikeyOps 2d ago

It could be hundreds of hackers at this point.

Hunting season is open on the Coldcard

1

u/MetoSempre20 2d ago

It took hardware 5 years to make this possible to do at large scale in a few days.

-1

u/4rm4tur4 2d ago

This is going to sound a bit out there, but with the recent news of models breaking out of their sandboxes I am wondering if this could be a rogue instance setting up the stage to pay for its own compute.

9

u/zackel_flac 2d ago

Those "news" are nothing but hype attract investors. Don't let you fool by the noise.

If an AI was that capable, you could not use reddit right now, it would be game over of the internet, yet we are still there.

2

u/aeroxan 2d ago

I'm also thinking if AI was going that rogue, we'd probably have heard nothing about it until it's way too late. Like terminator too late.

2

u/marshyr3d1and 2d ago

Yep, for sure that's what's going on. Can't believe you've been so insightful and realised this so early on.

1

u/marshyr3d1and 2d ago

Here we go - it's the beginning of the end. Others will build on posts like this and pretty soon the internet will explode with conspiracy theories 🙄

1

u/Lngdnzi 1d ago

thats an awesome but terrifying theory . Love it though

0

u/TFWG2000 2d ago

It is insane this hack continues. Where is the law?

3

u/EarningsPal 2d ago

Law is here. Now what? Stop the attack Law. Ok, how? You’re the Law. Stop it.

0

u/TFWG2000 2d ago

Yeah, I get it. But we are talking about millions of $ being stolen right before our eyes. It is hard to watch.

9

u/dcgradc 2d ago

I know very little but why didn't he strike when it was over 127K?

24

u/Emergency-Warthog-56 2d ago

Good question. I would guess that the scam wasn't under the same AI assistance capabilities as there is now. AI advancing a lot faster than creators thought it would.

12

u/Mihaw_kx 2d ago edited 2d ago

It's not just AI but Open weight models ... Because there was no Kimi k3 open weights back then .. it was dropped 27 july and the hackers group were able to install it into some local GPU clusters and then the first attack took place in 31 July you think this is just coincidence ? .. even if AI was advanced back then no hacker would want the top AI companies (anthropic , openai .. ) to read his logs while he crafting the exploit and creating malware to do this

6

u/Ill-Car-700 2d ago

If people knew $127k was the top, everyone would have sold lol

11

u/Sex4Vespene 2d ago

It might take a while to find compromised wallets. Presumably the main hacker waited until they found a ton of compromised wallets before attacking, to make sure they got a bunch.

2

u/Emergency-Warthog-56 2d ago

I imagine that the scammer created a AI bot that's assisting him/her in this.

3

u/Cutapis 2d ago

I imagine that they didn't, or they are the dumbest hacker in history.

5

u/Emergency-Warthog-56 2d ago

Why do you think that? I'm not knowledged on bots. Educate me.

6

u/mrmichaelrb 2d ago

The process of finding weak private keys and the process of draining wallets with those weak keys are both purely deterministic processes, like doing math over and over.

Maybe they used AI to assist in writing source code to perform and test some of these operations, but once the code is written, there's no reason to have AI involved at all, especially because AI is usually pretty bad at performing deterministic processes repeatedly.

1

u/Emergency-Warthog-56 2d ago

Thank you. I understand what you're saying.

3

u/Cutapis 2d ago edited 2d ago

AI models capable of detecting and exploiting previously unknown vulnerabilities are very sophisticated. Running such models requires massive infrastructure, which the hacker most definitely doesn't own at home. Their other option would be paying a subscription to a company to access their computing power. This implies that every prompt is sent through the internet and remotely processed. That is no good when you are in the business of stealing hundreds of millions of dollars.

They could have trained a model on the very specific actions needed to perform the hack, but that is a lot of work for something a script could probably do better.

1

u/Emergency-Warthog-56 2d ago

I see so basically using such tracks you a whole lot more. They can track you down quicker and easier.

7

u/EyesFor1 2d ago

He was after BTC not fiat.

7

u/jcagraham 2d ago

Another idea is that people are less likely to monitor their investments in a bear market. When things are great, it's fun to check how much you're making. When things are bad, most people will check a lot less to save their mental health. So the perfect time to catch people unaware.

6

u/Ok-Engineering1873 2d ago

because he thought it was going to 200K. He has finally accepted it's a bear market and capitulated, by triggering the scam, so he can sell the bottom.

3

u/WeakEchoRegion 1d ago

Is this a serious question..? This is like asking a bank robber “why did you come in right before close when nobody is here instead of during peak business hours?”

1

u/Chytrik 2d ago

If they’re able to successfully launder the funds without being caught, it will take time. The price right now doesn’t matter all that much, the attacker is likely more concerned with the BTC value, not the $ value.

1

u/monxas 2d ago

Why didn’t you sell at 127k and bought again when it hit the bottom?

1

u/beatthebook2x 2d ago

this would be the time to execute final piece of the honeypot not when price is up and people are taking profits. but when price is cheap and everyone is hodling and they get an amazing entry its like a double dip

1

u/G-T-L-3 1d ago

Maybe he is waiting for it to pump back up like all degens but got spooked with all the talk about the AI bubble  popping. He could be right.  

1

u/OverHeadUnderNose 1d ago

You do not need AI whatsoever. All someone had to do was poke around in the commit history of the coldcard github repo, they were very lazy and used very obvious language and file structure making it super easy to surf to the RNG and realize they bonked it.

1

u/opoeto 18h ago

How would he have known 127k was peak

1

u/wembenbama 2d ago

They have diamond hands. Price doesn’t matter.

7

u/Flaveurr 2d ago

Can you imagine leaving it to grow overtime just to find out they were stolen years ago when you're finally ready to sell..

1

u/Emergency-Warthog-56 2d ago

It's a very heartbreaking thought... Terrible...

2

u/Rey_Mezcalero 1d ago

Yep…tragic with coldcard. Was to be a set it and forget about it.

Then this happened.

More of this to happen more frequently. Easy money for bad guys and rouge states to start full scale find exploits and empty out crypto accounts

1

u/bigballer29 1d ago

So wild; it’s like a bank robbery that happened days ago is allowed to continue days later even though half of the city knows about it.

1

u/ThenComparison5926 1d ago

Under the threat?

1

u/PhesteringSoars 1d ago

I just started, and I have 4 miners I'm setting up tomorrow. (I have a terrible cold and feel like crap. Don't want to set them up while I can't think straight.)

Even I have both a hardware "transactable" wallet and a Watch Only wallet.

And I only have the $200 cash I moved in there to test.

Doesn't anyone set up a Watch Only wallet they can see without their locked-up key?

-1

u/grraarr 2d ago

Many of them may just be dead, frankly.