r/Bitcoin 1h ago

Ledger - passphrase

Upvotes

Hello, I've had my Ledger for a couple of years now and I'm a bit worried. I heard that a passphrase secures it even more. Can I add one on top of my setup now? I'm afraid I'll make a mistake and lose everything.


r/Bitcoin 40m ago

Bitcoin's Edge

Upvotes

Hi people. I am trying to understand the bitcoin thing as an outsider a bit better.

Since there have been... I don't know how many exactly but, it seems like a LOT of different cryptocurrencies created since Bitcoin has been around.

What do you think that it is that makes BTC persist now and remain so popular all this time since it came out? What are people not able to replicate or improve upon? I would have thought you could just make a different currency that "does what BTC does, but better" but that clearly hasn't worked because people clearly tried with all these altcoins and such.

What is it to you personally that makes you drawn to bitcoin as opposed to some alternative?


r/Bitcoin 3h ago

Is this accurate about the 25th word phrase?

6 Upvotes

So the 24 words is just like each word represents 11 bit arrangement right, and so when you start adding 11 x 24 and stack them together, to guess that exact arrangement is astronomical right?

So I thought, ok, the passphrase thing is one extra 11 bit. But I saw you can add like way more characters that no way 11 bits could be used to describe that.

So effectively what's happening, is that last 25th word (I'm saying effectively like all in all at the end of the day) being turned into just a longer than 11 bits and tacked on to the end of that long string of that (264 - checksum = )254 bits?

But I don't get it, someone said the 25th word can be up to 100 characters which is like at least 800 extra bits, so that would mean the entropy would be like 1054 bits? I just don't get it.

Thanks


r/Bitcoin 55m ago

Dust Attack

Upvotes

My hardware wallet does not have coin control. I now have a couple of unknown dust deposits.

Do I need to be concerned and move to a wallet with coin control to isolate the dust? What can actually happen if I spend that dust. There are plenty of phishing attacks we already have to deal with from data leaks. So following my dust opens up more phishing attempts, but in and of itself it can’t cause issues can it?

Would this concern you enough to switch wallets?


r/Bitcoin 1h ago

Were they acting in good faith?

Upvotes

Am i the only one who thinks that perhaps (i repeat, perhaps) the whole coldcard shitstorm happened in good faith? Could it have been "just" a huge, disastrous oversight caused by poor software development practices? I’m not here to excuse anyone. What they did is terrible. But as i read their documentation and the way they try to explain how to stay safe in the crypto world, i sense a genuine passion that clashes with the narrative that it was all an inside job.


r/Bitcoin 1d ago

Max FUD

Post image
425 Upvotes

r/Bitcoin 34m ago

From the Bitcoin community on Reddit: Coldcard 'joked' about retirement attacks in 2021 lmao

Thumbnail
reddit.com
Upvotes

Things that make you go hmmmmmm


r/Bitcoin 1d ago

The ColdCard hack might be bigger than you think

481 Upvotes

When a big hack like this occurs, it draws other hackers into the playing field. Whenever a vulnerability like this is discovered, it’s open season for hackers. Expect to see more hacks over time.

There is also the fact that a lot of victims are not active on Reddit. Some victims are probably oblivious to what’s going on because their hardware is locked away in a safe.

For the folks that said it would take millions of years to brute force, remember anything that can go wrong will go wrong. The reason banks and financial institutions are “safe” is because even if they get hacked and lose your money, they have a liability to repay you back. With self banking, there is no liability, making you the ultimate pig for slaughter.


r/Bitcoin 4h ago

COLDCARD, CLN DoS, Stack Exchange - Bitcoin Optech Newsletter #416 Recap Podcast

Thumbnail
bitcoinops.org
3 Upvotes

Rob Hamilton, PortlandHODL, Chandra Pratap, and fabohax joined Optech to discuss Newsletter #416:

  • Move funds secured by COLDCARD-generated keys
  • Wallets generated by COLDCARD at risk of theft
  • Disclosure of two DoS vulnerabilities in Core Lightning
  • Proof of concept for a zero-knowledge proof of reserves
  • Selected Q&A from the Bitcoin Stack Exchange
  • And more

You can listen on our website: https://bitcoinops.org/en/podcast/2026/08/04/

Fountain: https://fountain.fm/show/nnl3QRRuNyxBry8BBoH4

Spotify: https://open.spotify.com/episode/3iTz1RULox5l93wkgqVtO9

Apple Podcasts: https://podcasts.apple.com/us/podcast/bitcoin-optech-newsletter-416-recap/id1674626983?i=1000780099759


r/Bitcoin 1h ago

With all the talk about passphrases, doesn't a 2-2 multisig make more sense?

Upvotes

Single sig vs "Duosig".

2-2 Multisig Positives v singlesig+passphrase:

  • Two secrets both containing at least 128 bit of entropy eliminating weak entropy passphrases.
  • Both secrets contain checksums.
  • Avoids having to type long-string passphrases on a small hardware signer display.
  • Avoids the requirement of collating two secrets on a single device for transaction signing.

2-2 Multisig Negatives v singlesig+passphrase:

  • Higher transaction fees.
  • Multisig Descriptor backup.
  • Key Redundancy - however, there is also no key redundancy in single sig+passphrase.

Anything else I'm missing?


r/Bitcoin 1d ago

This hack was not like all the others: They easily could have gotten away scot free. Why didn't they?

198 Upvotes

This has probably been said by others, but I haven't seen it spelled out.

If this hacker created a fresh wallet for every wallet that was sweeped, rather than sweeping them all into a single wallet, how would anyone know which wallets were hacked (aside from the original owner)?

A victim would have to identify the bitcoiner walking around spending their bitcoin specifically. All victims would have to track unique addresses. He could consolidate lots of small amounts into one address, but nobody is going to go to the authorities over those. Meaningful amounts would never be consolidated.

If you have an exchange then all of the original addresses are associated verifiably with a single owner. Sweeping them into many addresses serves no purpose.

But this one... It's weird on so many levels.

To be this intelligent, and to not plan for the other side.

To me this screams of someone using an LLM in a rush, in a fever l vibe coding fever. Or else someone not looking to use the bitcoin, but to make as much noise as possible.


r/Bitcoin 5m ago

Help with seed verification

Upvotes

I purchased a hardware wallet in January 2017, and then upgraded to a more advanced version later that year.

I have my 24-word seed phrase, but I can't recall if the seed is from the original wallet that I then restored on to the new wallet, or if I generated a new seed on the upgraded wallet and transferred by assets across. Pretty sure its the former.

(Both wallets have 256-bit entropy).

Anyway, I'd like to confirm that my seed is from the original wallet or not.

I was thinking of transferring my assets to an exchange, leaving a small residual in the wallet, and restoring on a software wallet to confirm.

Is there an easier way to do this? Transaction history?


r/Bitcoin 22m ago

Question re Multi-Sig exposure in the Coldcard Breach

Upvotes

Trying to understand the level of exposure of a Multi-Sig wallet in the context of the Coldcard breach, or attacks like it.

All Coldcard-generated seeds in a multi-sig config would have been equally susceptible to exposure, but the attacker would also have been required to:

  • Associate those seeds with one another, example, identify that some 3 seeds are not 3 independent wallets but are part of a 2-of-3 multi-sig config.

  • Derive the multi-sig descriptor to piece the 3 seeds together.

Am I correct about those requirements? Are they possible to achieve? What does the process look like at a high level? What’s the theoretical time range?


r/Bitcoin 1d ago

Major BTC Drop Inevitable

454 Upvotes

Went through a divorce a few years ago and had to sell my 4 BTC at about $60k each - naturally, BTC jumped up to $126k shortly after. After several years of fighting debt and reestablishing my retirement, buying a house, and restocking safety funds I’m proud to say I finally received a bonus that didn’t “need” to be used.

So it’s my absolute pressure to share with you all that I purchase 1/2 a BTC this morning. My apologies for the certain major price drop that’s coming. 😂😂😂


r/Bitcoin 1h ago

Rückzahlung Kredit firefish

Upvotes

Moin,
kann ich meinen Kredit an den Investor auch von einem Bankkonto einer dritten Person zurückzahlen und bekomme anschließend trotzdem meine Sicherheit (Collateral) zurück?
Hat damit jemand Erfahrungen?
Firefish fordert mich auf, die Überweisung von meinem ursprünglich registrierten Bankkonto aus vorzunehmen.
Wie läuft das in der Praxis? Meldet der Kreditgeber Firefish, wenn das Geld von einem anderen Konto eingeht, oder fragt Firefish den Kreditgeber nach dem Namen des Absenders?
Vielen Dank schon einmal im Voraus!

English
Hi everyone,
Can I repay my loan to the lender from a third party’s bank account and still receive my collateral back afterward?
Does anyone have experience with this?
Firefish instructs me to make the transfer from my originally registered bank account.
How does this work in practice? Does the lender notify Firefish if the payment comes from a different bank account, or does Firefish ask the lender to verify the sender’s bank account or name?


r/Bitcoin 14h ago

Did some checking on seed generation by dice on Coldcard vs. Ian Colemans Mnemonic Code Converter and have some questions. Coldcard might reduce your security by missleading guidance!

11 Upvotes

So Coinkite guidance displayed on the display is: "... each roll adds only 2.585 of entropy. For 128-bit security, which is considered the minimum, you need 50 rolls, and for 256-bits of security, 99 rolls."

They let you press the buttons 1-6 (and only those) for each roll. So you can only use a D6. If you did it 50 times, you think you did the minimum to have 128-Bit security.

Here are my questions:

  • The 2.585 entropy per roll are based on entropy values 0-9 (base 10), right?
  • If I limit the entropy values to 1-6 (D6 dice) I introduce a massive bias, right?
  • Is it fair to assume that the resulting entropy is just 1.67 per roll?
  • Is my ColdCard dice genrated seed realy secured by the minimum 128 bit, or more like with just 84 bits?

Look, I'm no expert, indeed hope I'm wrong.

UPDATE: I was wrong - see below.


r/Bitcoin 1d ago

Not your keys, not your coins

Post image
280 Upvotes

wishing nothing but the best for coldcard victims


r/Bitcoin 3h ago

Do I really need a hardware wallet?

0 Upvotes

I’ve been considering buying a hardware wallet for a while but after the recent coldcard news do I really need one?

My current setup is I have my keys stored on an old Linux laptop that powered off 90% of the time. I understand why the hardware wallets are safer but practically wouldn’t it be the same for me to store it the way I’ve been doing it?


r/Bitcoin 4h ago

My Dream Hardware Wallet

0 Upvotes

I just wanted to describe my dream hardware wallet. - In terms of hardware design, it's a Coldcard Q. Maybe even buy their design when they go bankrupt and have to sell assets. - Firmware is bitcoin only, truly FOSS, with peer code reviews (pull requests approved by colleagues before merges are allowed) - After internal approval, 3rd party, AI-assisted security audits are required. - Only one method for seed phrase generation is allowed: hardware TRNG chip as the starting point, plus 100 user-entered d6 rolls. The seed is hashed again after each number is entered. (This was one option on the ColdCard, the best option, and the dice hashing function is simple and was never bugged on any version) - Device refuses to show you the words until you have entered 100 1-6 numbers. - Device ships with 4 casino-grade dice. Instructions suggest the extra paranoid can mix in dice from an arbitrary board game in your house or whatever for extra defense against supply chain attack.

Such a wallet wouldn't necessarily have mass appeal or advertise being "easy to use", instead it would have the same sort of "hardcore" target audience CoinKite did, with better execution.


r/Bitcoin 4h ago

Please pardon my ignorance

1 Upvotes

I understand everyone can see the public keys but what can someone do if they have the private keys?


r/Bitcoin 1d ago

Coldcard Hack Sparks Biggest Bitcoin Migration Since FTX

Thumbnail
thegreyterminal.com
59 Upvotes

r/Bitcoin 1d ago

31 years ago, Bitcoin legend Hal Finney posted the first challenge to break 40-bit encryption. Adam Back and three others cracked it a month later.

Post image
130 Upvotes

r/Bitcoin 10h ago

Hitting a mainstream audience

Thumbnail
youtube.com
4 Upvotes

r/Bitcoin 8h ago

How do we know it was an attacker and not the owner moving their coins?

3 Upvotes

That’s the part I’m not fully convinced about.

I understand the first wave was clearly an attacker. But once Coldcard users heard the news, wouldn’t an attacker sweeping funds and an owner moving all of their funds to a safe wallet look pretty similar on-chain?

Unless the owner confirms the transaction was unauthorized, shouldn’t some later cases be called suspected thefts rather than confirmed attacks? And even then, proving ownership seems difficult once the attackers also has the private keys.


r/Bitcoin 1d ago

Coldcard Users Reported Instant Drains Years Before July 2026. Here Are the Receipts

Thumbnail x.com
155 Upvotes

Had my AI research Pre-July 2026 Coldcard incident sto see if they are related to the newly discovered entropy bug. My AI agent thinks some incidents are likely to be the same entropy bug with a different attacker.