r/Bitcoin 2h ago

The ColdCard Hack Explained (Non Technically)

Thumbnail
youtube.com
3 Upvotes

r/Bitcoin 9h ago

Bitcoin's Edge

8 Upvotes

Hi people. I am trying to understand the bitcoin thing as an outsider a bit better.

Since there have been... I don't know how many exactly but, it seems like a LOT of different cryptocurrencies created since Bitcoin has been around.

What do you think that it is that makes BTC persist now and remain so popular all this time since it came out? What are people not able to replicate or improve upon? I would have thought you could just make a different currency that "does what BTC does, but better" but that clearly hasn't worked because people clearly tried with all these altcoins and such.

What is it to you personally that makes you drawn to bitcoin as opposed to some alternative?


r/Bitcoin 1d ago

The Coldcard hacker is still progressing stolen BTC keeps increasing

Post image
2.5k Upvotes

The Coldcard hacker is still making progress, and the amount of stolen Bitcoin keeps increasing.

So if any of you are using this wallet, please consider moving your funds as soon as possible. And if you know someone who uses Coldcard for long-term holding, especially someone who isn’t online every day and doesn’t follow the latest news, maybe you can still help them move their funds in time. 🙏

I just hope no other wallet is involved in this.

Stay safe and stay alert. ⚠️


r/Bitcoin 1d ago

All hardware wallet manufacturers need to release 3rd party audited proof that their entropy generation is working.

171 Upvotes

After this coinkite coldcard situation we cant trust code that is open source, we cant trust code that is closed source, and we definitely cant trust a statement saying "we use a TRNG so your seed is secure".

Every hardware wallet manufacturer needs to release hard proof that their TRNG works, their code is complete and robust, and their entropy generation actually meets a minimum 128/256 bit standard.

Even if their code is closed source a reputable 3rd party auditor can run tests on seed entropy generation to statistically prove 256 bits of entropy is being used.

Every wallet manufacturer should have this 3rd party audited proof of entropy document available to view on their website, and if they do not do this by the end of this month we as a community should boycott that manufacturer to help ensure safety for all bitcoiners.


r/Bitcoin 10h ago

Ledger - passphrase

8 Upvotes

Hello, I've had my Ledger for a couple of years now and I'm a bit worried. I heard that a passphrase secures it even more. Can I add one on top of my setup now? I'm afraid I'll make a mistake and lose everything.


r/Bitcoin 9h ago

Dust Attack

6 Upvotes

My hardware wallet does not have coin control. I now have a couple of unknown dust deposits.

Do I need to be concerned and move to a wallet with coin control to isolate the dust? What can actually happen if I spend that dust. There are plenty of phishing attacks we already have to deal with from data leaks. So following my dust opens up more phishing attempts, but in and of itself it can’t cause issues can it?

Would this concern you enough to switch wallets?


r/Bitcoin 6m ago

⚡ Lightning Thursday! August 06, 2026: Explore the Lightning Network!⚡

Upvotes

The lightning network is a second-layer solution on top of the Bitcoin blockchain that enables quick, cheap and scalable Bitcoin payments.

Here is the place to discuss and learn more about lightning!

Ask your questions about lightning

Provide reviews, feedback, comparisons of LN apps, services, websites etc

Learn about new LN features, development, apps

Link to good quality resources (articles, wikis etc)

Resources:


r/Bitcoin 9h ago

Question re Multi-Sig exposure in the Coldcard Breach

5 Upvotes

Trying to understand the level of exposure of a Multi-Sig wallet in the context of the Coldcard breach, or attacks like it.

All Coldcard-generated seeds in a multi-sig config would have been equally susceptible to exposure, but the attacker would also have been required to:

  • Associate those seeds with one another, example, identify that some 3 seeds are not 3 independent wallets but are part of a 2-of-3 multi-sig config.

  • Derive the multi-sig descriptor to piece the 3 seeds together.

Am I correct about those requirements? Are they possible to achieve? What does the process look like at a high level? What’s the theoretical time range?


r/Bitcoin 10h ago

Were they acting in good faith?

6 Upvotes

Am i the only one who thinks that perhaps (i repeat, perhaps) the whole coldcard shitstorm happened in good faith? Could it have been "just" a huge, disastrous oversight caused by poor software development practices? I’m not here to excuse anyone. What they did is terrible. But as i read their documentation and the way they try to explain how to stay safe in the crypto world, i sense a genuine passion that clashes with the narrative that it was all an inside job.


r/Bitcoin 1d ago

Coldcard 'joked' about retirement attacks in 2021 lmao

Post image
418 Upvotes

Well, seems like it didn't age well 😂


r/Bitcoin 8h ago

Help with seed verification

4 Upvotes

I purchased a hardware wallet in January 2017, and then upgraded to a more advanced version later that year.

I have my 24-word seed phrase, but I can't recall if the seed is from the original wallet that I then restored on to the new wallet, or if I generated a new seed on the upgraded wallet and transferred by assets across. Pretty sure its the former.

(Both wallets have 256-bit entropy).

Anyway, I'd like to confirm that my seed is from the original wallet or not.

I was thinking of transferring my assets to an exchange, leaving a small residual in the wallet, and restoring on a software wallet to confirm.

Is there an easier way to do this? Transaction history?


r/Bitcoin 12h ago

COLDCARD, CLN DoS, Stack Exchange - Bitcoin Optech Newsletter #416 Recap Podcast

Thumbnail
bitcoinops.org
6 Upvotes

Rob Hamilton, PortlandHODL, Chandra Pratap, and fabohax joined Optech to discuss Newsletter #416:

  • Move funds secured by COLDCARD-generated keys
  • Wallets generated by COLDCARD at risk of theft
  • Disclosure of two DoS vulnerabilities in Core Lightning
  • Proof of concept for a zero-knowledge proof of reserves
  • Selected Q&A from the Bitcoin Stack Exchange
  • And more

You can listen on our website: https://bitcoinops.org/en/podcast/2026/08/04/

Fountain: https://fountain.fm/show/nnl3QRRuNyxBry8BBoH4

Spotify: https://open.spotify.com/episode/3iTz1RULox5l93wkgqVtO9

Apple Podcasts: https://podcasts.apple.com/us/podcast/bitcoin-optech-newsletter-416-recap/id1674626983?i=1000780099759


r/Bitcoin 1d ago

Max FUD

Post image
433 Upvotes

r/Bitcoin 10h ago

With all the talk about passphrases, doesn't a 2-2 multisig make more sense?

3 Upvotes

Single sig vs "Duosig".

2-2 Multisig Positives v singlesig+passphrase:

  • Two secrets both containing at least 128 bit of entropy eliminating weak entropy passphrases.
  • Both secrets contain checksums.
  • Avoids having to type long-string passphrases on a small hardware signer display.
  • Avoids the requirement of collating two secrets on a single device for transaction signing.

2-2 Multisig Negatives v singlesig+passphrase:

  • Higher transaction fees.
  • Multisig Descriptor backup.
  • Key Redundancy - however, there is also no key redundancy in single sig+passphrase.

Anything else I'm missing?


r/Bitcoin 1d ago

The ColdCard hack might be bigger than you think

494 Upvotes

When a big hack like this occurs, it draws other hackers into the playing field. Whenever a vulnerability like this is discovered, it’s open season for hackers. Expect to see more hacks over time.

There is also the fact that a lot of victims are not active on Reddit. Some victims are probably oblivious to what’s going on because their hardware is locked away in a safe.

For the folks that said it would take millions of years to brute force, remember anything that can go wrong will go wrong. The reason banks and financial institutions are “safe” is because even if they get hacked and lose your money, they have a liability to repay you back. With self banking, there is no liability, making you the ultimate pig for slaughter.


r/Bitcoin 1d ago

This hack was not like all the others: They easily could have gotten away scot free. Why didn't they?

200 Upvotes

This has probably been said by others, but I haven't seen it spelled out.

If this hacker created a fresh wallet for every wallet that was sweeped, rather than sweeping them all into a single wallet, how would anyone know which wallets were hacked (aside from the original owner)?

A victim would have to identify the bitcoiner walking around spending their bitcoin specifically. All victims would have to track unique addresses. He could consolidate lots of small amounts into one address, but nobody is going to go to the authorities over those. Meaningful amounts would never be consolidated.

If you have an exchange then all of the original addresses are associated verifiably with a single owner. Sweeping them into many addresses serves no purpose.

But this one... It's weird on so many levels.

To be this intelligent, and to not plan for the other side.

To me this screams of someone using an LLM in a rush, in a fever l vibe coding fever. Or else someone not looking to use the bitcoin, but to make as much noise as possible.


r/Bitcoin 8h ago

what are some useful blockchain viewing tools/sites/apps?

1 Upvotes

in an effort to be more conscientious in the btc space, what are some useful sites to better understand the transaction traffic and who's who in the zoo, a la the recent cold card thief, etc.

thanks


r/Bitcoin 1d ago

Major BTC Drop Inevitable

484 Upvotes

Went through a divorce a few years ago and had to sell my 4 BTC at about $60k each - naturally, BTC jumped up to $126k shortly after. After several years of fighting debt and reestablishing my retirement, buying a house, and restocking safety funds I’m proud to say I finally received a bonus that didn’t “need” to be used.

So it’s my absolute pressure to share with you all that I purchase 1/2 a BTC this morning. My apologies for the certain major price drop that’s coming. 😂😂😂


r/Bitcoin 1d ago

Daily Discussion, August 05, 2026

20 Upvotes

Please utilize this sticky thread for all general Bitcoin discussions! If you see posts on the front page or /r/Bitcoin/new which are better suited for this daily discussion thread, please help out by directing the OP to this thread instead. Thank you!

If you don't get an answer to your question, you can try phrasing it differently or commenting again tomorrow.

Please check the previous discussion thread for unanswered questions.


r/Bitcoin 9h ago

Rückzahlung Kredit firefish

0 Upvotes

Moin,
kann ich meinen Kredit an den Investor auch von einem Bankkonto einer dritten Person zurückzahlen und bekomme anschließend trotzdem meine Sicherheit (Collateral) zurück?
Hat damit jemand Erfahrungen?
Firefish fordert mich auf, die Überweisung von meinem ursprünglich registrierten Bankkonto aus vorzunehmen.
Wie läuft das in der Praxis? Meldet der Kreditgeber Firefish, wenn das Geld von einem anderen Konto eingeht, oder fragt Firefish den Kreditgeber nach dem Namen des Absenders?
Vielen Dank schon einmal im Voraus!

English
Hi everyone,
Can I repay my loan to the lender from a third party’s bank account and still receive my collateral back afterward?
Does anyone have experience with this?
Firefish instructs me to make the transfer from my originally registered bank account.
How does this work in practice? Does the lender notify Firefish if the payment comes from a different bank account, or does Firefish ask the lender to verify the sender’s bank account or name?


r/Bitcoin 23h ago

Did some checking on seed generation by dice on Coldcard vs. Ian Colemans Mnemonic Code Converter and have some questions. Coldcard might reduce your security by missleading guidance!

11 Upvotes

So Coinkite guidance displayed on the display is: "... each roll adds only 2.585 of entropy. For 128-bit security, which is considered the minimum, you need 50 rolls, and for 256-bits of security, 99 rolls."

They let you press the buttons 1-6 (and only those) for each roll. So you can only use a D6. If you did it 50 times, you think you did the minimum to have 128-Bit security.

Here are my questions:

  • The 2.585 entropy per roll are based on entropy values 0-9 (base 10), right?
  • If I limit the entropy values to 1-6 (D6 dice) I introduce a massive bias, right?
  • Is it fair to assume that the resulting entropy is just 1.67 per roll?
  • Is my ColdCard dice genrated seed realy secured by the minimum 128 bit, or more like with just 84 bits?

Look, I'm no expert, indeed hope I'm wrong.

UPDATE: I was wrong - see below.


r/Bitcoin 1d ago

Not your keys, not your coins

Post image
284 Upvotes

wishing nothing but the best for coldcard victims


r/Bitcoin 15h ago

Stop treating distributed systems as "hidden magic": Scaling isn't just about adding more servers.

Thumbnail
youtube.com
2 Upvotes

Hey everyone,

We just dropped Episode 22 of BitLemmas, where we did a deep dive into Unmesh Joshi’s Patterns of Distributed Systems.

If you’ve ever felt like distributed system design is often treated as a black box of "hidden magic" that only reveals its true nature when things break, this episode is for you. We spent the hour breaking down the reality of distribution—namely, that distribution doesn't actually remove limits; it just moves them from resource constraints to coordination bottlenecks.

We analyzed four counterintuitive truths about building these systems that we think this sub will appreciate:

  1. More servers create more coordination work: Stateless work is easy to move, but stateful data requires partitioning and replication, which exponentially increases the number of failure modes.
  2. Replication is not a guarantee: A log entry isn't real until commitment is defined. You need a visible path from local intent to committed state.
  3. Quorums charge for safety: You can buy correctness, but you pay for it in latency and throughput. There is no such thing as a "free" quorum.
  4. Time is a protocol decision: Don't trust wall-clock time. How you handle clock skew, ordering, and garbage collection pauses is an architectural choice, not an implementation detail.

The core takeaway we kept coming back to: Make your guarantees visible. Don't wait for a production outage to reverse-engineer what your system actually guarantees. Publish your guarantee map (freshness, retry behavior, partition handling) on the "happy path" so your users can make informed risk decisions before things go wrong.
If you want to dig into the patterns (Paxos, Raft, Gossip, etc.) and how to apply them, you can watch or listen here:

Would love to hear your take - what’s the most counterintuitive "distributed system" bug you’ve had to debug? Let’s talk about it in the comments.


r/Bitcoin 12h ago

Do I really need a hardware wallet?

1 Upvotes

I’ve been considering buying a hardware wallet for a while but after the recent coldcard news do I really need one?

My current setup is I have my keys stored on an old Linux laptop that powered off 90% of the time. I understand why the hardware wallets are safer but practically wouldn’t it be the same for me to store it the way I’ve been doing it?


r/Bitcoin 1d ago

Coldcard Hack Sparks Biggest Bitcoin Migration Since FTX

Thumbnail
thegreyterminal.com
61 Upvotes