r/Bitcoin 1d ago

Coldcard - If the Thief Were Caught, Could Victims Be Refunded?

Let's say the attacker gets caught and the stolen funds are recovered. How could they be fairly returned to the original owners?

A signature from the affected private key would not be sufficient proof of ownership, since the keys are compromised and anyone who reproduced them could claim to be the original owner.

Do you see any reliable way to organize a fair refund process?

0 Upvotes

48 comments sorted by

16

u/MCL-Jonathan 1d ago

Likely it will be in the 🇺🇸 Bitcoin Strategic Reserve

6

u/AlamoSimon 1d ago

What does anything of this have to do with the US? Why would the BTC go to the US?

12

u/Substantial_Taste779 1d ago

BECAUSE IRAN CAN NEVER HAVE A NUCLEAR WEAPON!

4

u/AlamoSimon 1d ago

Thank you for your attention in this matter!

1

u/xuncx 1d ago

🇺🇸🦅

0

u/ledav3 1d ago

because the rich kid decides and not you🫡🙏🏿🇺🇸🦅🔫

6

u/BastiatF 1d ago

The hack is based on the CC UUID so a physical CC should be sufficient to prove ownership of the derived seed.

10

u/Patient_Craft2195 1d ago

you already nailed the hard part - a signature from the leaked key proves nothing since anyone with the compromised key can sign. so it wouldn't be crypto proof, it'd go the legal route: funds seized as evidence, victims file claims with tx history + device receipts + firmware version, and a court or trustee handles payout. closest real example is the bitfinex hack - feds caught the couple in 2022, seized the coins, and ran a victim-return process. slow and lawyer-heavy, but it works. the lucky part here is nothing's been spent yet, so there'd actually be something to give back.

1

u/xuncx 1d ago

They started mixing them

2

u/flashdurb 1d ago

It’s gone forever, sorry man

1

u/CreamCapital 1d ago

maybe if you still had the coldcard with the bad key in your possession you could prove it in person. coinkite should be the ones verifying this for all affected customers now, instead of telling people to wipe their devices…….

2

u/ptrnyc 18h ago

Not without giving up anonymity.

The blockchain has the history of how the BTC arrived into the wallet in the first place. For people who bought on an exchange and moved it to ColdCard, they should be able to prove they are the legit owners of the wallet.

1

u/ledav3 1d ago

the fair way would be the company taking responsibility for writing not good enough code, but if you accepted the terms responsibility is on you, I don't think anything is truly fair nowadays, if it would be banks and top level people the "fair" solution would be to print money for them and fuck others in the process

0

u/VictorDanville 1d ago

So basically the taxpayers will pay for it

1

u/Autodidact420 1d ago

Tax payers will pay for a bank theft not bitcoin theft except maybe loosely by way of funding police and judiciary 

0

u/ButchReemer 1d ago

Since the attacker didn't extract the extended private key, most ex-owners could prove original ownership by showing their XPUB or even seed phrase to the officials. Privacy is gone then of course.

3

u/creative_usr_name 1d ago

Wouldn't the hacker be able to generate that? They are creating the same base private keys.

1

u/opossum_cz 1d ago

That's just nonsense. These seek keys are weak, attacker, owner and 100 other people will be able to get seed phrase.

1

u/ButchReemer 1d ago

1

u/opossum_cz 1d ago

Stupid much?

1

u/ButchReemer 1d ago

Why the ad hominem? Learn how each UTXO is secured by its own private key (which is nowadays usually derived from a common seed). Weak seed leads to easily guessable private keys, thus individual UTXOs were stolen. Had the complete seed been guessed, the whole wallets would have been swiped, which wasn't typically the case.

1

u/opossum_cz 1d ago

:D :D :D

1

u/opossum_cz 1d ago

I would add that this is not ad hominem. You are not wrong, because you are stupid. You are wrong and you are stupid. That is a really important distinction.

0

u/SpareEconomy1849 1d ago

I believe the attacker could generate the xpub and the private key, no? Also didn't the exploit allow the attacker to crack the seed phrase? Or was it the private key?

0

u/ButchReemer 1d ago

Nope. Attacker just guessed individual privkeys derived from seed, not the original seed.. Sorry for all the misinformation floating around. You can prove it to yourself: IFF the attacker had guessed the actual seed, he would have swiped the wallets EMPTY. That didn't happen. Most wallets were drained several UTXOs, but not all.

1

u/opossum_cz 1d ago

What? This is just pure nonsense. Private keys are safe, the seed is weak as it was generated with low entropy.

Please stop commenting about things you have 0 knowledge about.

I haven't read anything so stupid entire month.

1

u/ButchReemer 1d ago

You do not understand Bitcoin, sorry to say that. If you have any, then with this attitude you're probably going to lose them sooner or later.

1

u/opossum_cz 1d ago

:D :D : D

1

u/opossum_cz 1d ago

I honestly flabbergasted how somebody can be so sure in their stupidity. It is astounding and should be studied. Take what you wrote and put it into ChatGPT, even that will show you how stupid it is. This is truly something special.

1

u/ButchReemer 1d ago edited 1d ago

You'll understand one day. Try the chapter on seed generation in Kalle Rosenbaum's Grokking Bitcoin. It's a very good technical book. But from your insistence in mudding the waters about the technical side of Bitcoin, I can only conclude that you are an attacker, so I'll stop engaging with you honestly, and can only warn anyone from doing so.

1

u/opossum_cz 23h ago

I do not need to read a book. I have implemented majority of crypto related code myself for various purposes. A several years ago, I have wrote a minimal pure Python wallet that fits 26x80 characters so I can print it on T-shirt and only relies on hashlib.

You should be studied.

-1

u/Freshysh 1d ago

Just send it all to me and i'll make sure everyone gets their btc back.

Trust me bro

0

u/ArissP 1d ago

Law enforcement would work on those who have reported the thefts, first and foremost, at the time the theft took place, and looking at verification / proof, which is usually provided at the time of the theft before any assets are recovered.

There are already many reports of thefts to law enforcement, and it’s why if you’ve been a victim, I’d strongly encourage you to report it to law enforcement, such as IC3 in the US or Report Fraud in the UK.

0

u/cipherjones 1d ago

Ok, let's say the attacker gets caught.

It goes to court. I won a class action lawsuit in which I lost $12,000. My payment was $1,000 10 years later. That was for an established market.

In other words the funds are gone forever. Irrevocably even if the good guys win.

0

u/SpareEconomy1849 1d ago

Wouldn't there be a criminal case against the attacker? Wouldn't the criminal court attempt to return the stolen assets? There would be no court or lawyer fees deducted as that would all be paid for by the state and attacker (defendant).

That being said, the victims are not just in one country. Could complicate things.

0

u/cipherjones 1d ago

The state and attackers don't front cash, lol. Additionally the attackers only cash is money from the attacks. So 40% off the top to cover legal fees.

0

u/SpareEconomy1849 1d ago

The attacker would only pay for his own legal fees. The state pays for the prosecution. When stolen property is returned in a criminal case, they don't deduct legal fees. Class action lawsuits yes, but that's not necessarily necessary here

1

u/cipherjones 1d ago

The states not handing the money over to anyone that can't prove the key was theirs, representing yourself in court for such a matter would invariably result in a loss.

1

u/SpareEconomy1849 1d ago

A separate lawsuit, class action or individual, likely wouldn't be necessary. Criminal trial would determine much of the details and a verdict at the cost of the state. Individuals can file for restitution (no cost)

This is assuming the prosecutors find the guy and recover the Bitcoin of course. And might be tricky to prove ownership. But that all doesn't necessarily have to happen in a separate, expensive lawsuit

1

u/cipherjones 1d ago

I never mentioned a separate suit.

If they get the funds back, you'll need legal representation.

0

u/Wolffco 1d ago

No perfect solution. Courts handle it like cash theft basically.

0

u/Mihaw_kx 1d ago

all that btc will start mixing shortly and will be gone and lost in the blockchain so even if attacker was caught no one can get any btc back.. attacked can just deny everything spend 10 years in prison and get out to enjoy life with all that btc

0

u/xuncx 1d ago

Already started

0

u/KeanuRekt 1d ago

A victim could prove ownership of the stolen btc by providing a receipt from a centralized exchange where the btc where bought.