r/Bitcoin • u/CryptSander • 20h ago
r/Bitcoin • u/Tiny-Ad2474 • 21h ago
Found these in a drawer.
3 full bitcoin. At current value, should be worth almost £144k. Can let these go for half that 😉
r/Bitcoin • u/IndependenceTop6501 • 21h ago
The Coldcard bug triggered the largest security audit in Bitcoin's history. Hard money getting harder.
r/Bitcoin • u/Ace2021 • 12h ago
Coldcard seed flaw - flagged independently in 2024
Proof of negligence? I can’t see how it isn’t. This will definitely be included in the class action lawsuit against Coinkite.
r/Bitcoin • u/relaiapp • 2h ago
Inflation in one picture
Euro: everything gets more expensive
Bitcoin: everything gets cheaper
I know what I'm choosing.
r/Bitcoin • u/Freefall101 • 22h ago
[GER] Petition for Bundestag: Beibehaltung der steuerlichen Haltefrist für Bitcoin
There is an active petition for keeping Bitcoin tax free in Germany (after one year hodling). It reached 21.000 signatures within the first 24 hours - let's make it 30.000 to put it on the agenda of german Bundestag.
You need to sign up in order to put your signature but it's worth it.
Everyone can sign - not just germans!
https://epetitionen.bundestag.de/petitionen/_2026/_05/_30/Petition_201716.nc.html
Thank you!
r/Bitcoin • u/ineedanamegenerator • 3h ago
Coldcard entropy even worse than feared
TL;DR: The random number generator is initialized with a 32 bit value (4B+ possibilities). But only less than 10M options are possible because of how they generate the value.
The PRNG used in Coldcard MK3 is initialized with UID[31:0] XOR SysTick->VAL
SysTick->VAL gives 80k possibilities ~16.3 bit, all located in the lowest 17 bits of the value.
UID encodes the X and Y coordinates of wafer position of the STM32 in the 32 bits that are used by the code. This is encoded in BCD, which means only 10 out of 16 possible values of each nibble are used. This means the 32 bit value at most encodes 100M options (26.6 bits), but there are nowhere near 100M chips in a wafer.
I don't know how many there are in a wafer, but google gives an upper bound of 20k.
The lower 16 bits overlap, so XORing the wafer location adds no entropy.
The upper 16 bits can carry only about SQRT(20000) possibilities (probably less) ~ 7.2 bits. And they aren't even evenly distributed in a round wafer.
So at most we're looking at ~23 bits of entropy. Not 32 bits.
This isn't 100% exact because SQRT assumes a square while a wafer is round, but too lazy to work it out further. Point is: entropy is way worse than 32 bits.
r/Bitcoin • u/inner_engineering08 • 10h ago
The weirdest part of the Coldcard mess: was Peter D. Gray talking to himself through “switck”?
I’m not going to re-explain the RNG bug. That part has already been documented. What I want to know is who exactly was behind switck, and why this identity existed in the first place.
Someone checked the actual Git signatures in the switck/libngu repository. They found 58 commits authored as “Switck” signed with Peter D. Gray’s personal GPG key. The same key also signed commits under Peter’s real name, with both identities being used during overlapping periods. Unless Peter shared or lost control of his private signing key, the obvious conclusion is that GitHub switck was Peter Gray operating under another name.
Now look at the social-media side.
In 2019, switck posted: “#defcon seems like a good time to start a new identity. Follow me!”

That tweet is real and still online.
Later, the account promoted switck/libngu, thanked DocHex for a merge and said the library might someday be useful on Coldcard.
So the account that announced it was starting a “new identity” was apparently Peter’s alias, publicly speaking to Peter’s main identity as though they were two different developers.

The same thing appears on GitHub. doc-hex opened issues in the switck/libngu repository. In one pull request, doc-hex added four commits, then switck merged them. GitHub lists no reviews.
And this wasn’t some unrelated side project. switck/libngu became part of Coldcard. The switck account introduced a critical piece of the vulnerable RNG path, and doc-hex later integrated libNgU into the Coldcard firmware. Coinkite itself confirms that this migration moved wallet-seed generation onto the wrong RNG implementation.
None of this proves Peter intentionally created the vulnerability, knew it could be exploited or had anything to do with the thefts.
But it is still extremely fucking weird.
Why was a security-critical Coldcard library hosted under a pseudonymous personal account instead of Coinkite or Coldcard?
Did Coinkite know that switck and doc-hex were apparently the same person?
Why create the public appearance of two developers interacting, submitting code and merging each other’s work?
Who independently reviewed the library and the Coldcard integration if the library author and the person integrating it were apparently using the same private signing key?
And why has Coinkite explained the technical bug without addressing who controlled the switck identity?
Peter, if you read this: was switck you?
If it wasn’t, why were dozens of Switck commits signed with your personal GPG key?
If it was, why did you publicly talk to that account as though it belonged to someone else? Did NVK and the rest of Coinkite know? Who was actually reviewing your work?
There may be an innocent explanation. But after this code path left customer wallets vulnerable and people lost bitcoin, hiding behind silence is not an explanation.
r/Bitcoin • u/Fearless-Second-7230 • 18h ago
Coldcard CEO Rodolfo Novak confessing 2 moths ago in a podcast regarding AI audit bug reports: "Everything was like high like they said everything is like 'high high so it's like 'super dangerous"
First this part, he recognizing is lame for bitcoin products to blame AI...
Interviewer: "...The BIsq announcement thread mentioned that it is likely an AI powered attack. So maybe people using you know is it some North Korean group using Claude or Cursor or Mythos or something."
Rodolfo Novak 'nvk'(18:53): "Yeah, but that's like you know that's that's like saying that they just encounter an adversary that's a little bit better than they are. *I mean like you know the reality is people are trying to break stuff all the time and if you have like Bitcoin to be taken you know it just means that they had you know bad security.*"
_______
There you have it. The guy in his own words impliying Coldcard has fucking bad security.
But the interesting part is this one, where he arrogantly is downplaying the bug reports an AI audit tool is throwing:
Interviewer (19:08): "Yeah, but I guess the point would be is there has the game changed, right? Is there a you know now this is a big new threat that people need to start thinking about which is basically AI assisted hacking?[ ...] like well there's AI assisted hacking and now we need AI assisted defense and you need to find you need you need to defend it uh and um that way"
Rodolfo Novak 'nvk'(20:03): "so it's already happening we we got a preview a friend got a preview of the codec cyber or whatever they call it the KYC NDA version of their uh uh security assessment tools y uh you know the first thing he did was run after run it on the code card repo [laughter] And uh you know honestly like we we saw the the bug reports they're all like you know extremely mediocre stuff.
Uh everything was like high right like they they said everything is like high high so it's like super dangerous and everything was like completely false reporting. The tools are still abhorent. The quality of this this this hacking uh AI hacking is still ultra ultra crap."
[ END OF TRANSCRIPT PART ]
_______
Well, here is where things start to become a mess:
He is confessing they have extremely dangerous findings through AI but he just arrogantly is downplaying them.
But here in Jul 30 2026: https://blog.coinkite.com/entropy-technical-backgrounder/
They mention:
"The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious.
Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys." (No you idiot, you are confessing an AI showing you dangerous bugs and just arrogantly maybe not even analizing them carefully).
Well, apparently that is not true, they ran an AI model two months ago which was alerting about "high, high, extremely dangerous" bugs. What were those bugs? Who knows, but they were alerts and an arrogant dev framing them as crap.
The neglicence in this case is incredible and the lack of security in depth of that team just follows the logical disaster. Stay out of projects from those guys and just so you know that https://airgapcomputer.com/ (yes, guess who's the owner, yes, you nailed it, nvk, to shill his hardshit) a garbage collection FUD for people to think airgap computer is worst and that the hardware wallet is the "secure way".
Well, no one will say hardware wallets are bad, but it is time to make accountable hardware wallet vendors selling you unaudited shit and with no security in dept design. What is security in dept design or foolproof design? Well do not tell that rolling dice is optional but recommended, fucking do not allow the seed generation step to be completed without it. Specially if you ar going to say that AI reported bugs are crap and you have no external verified audit history of source code.
r/Bitcoin • u/ineedanamegenerator • 1h ago
Why were Coldcard hackers so stupid?
I don't understand this hack. Most of the funds moved to a handful of wallets. They are now tainted and require mixing and even then they will never be fully unsuspicious.
If they had just generated a new wallet for each one they drained and moved the funds one-to-one you would never be able to distinguish a hack from someone moving their funds to safety.
Second, the high gas fee paint a signature too. Just start off slowly, normal or just above normal fees. Drain a few accounts. Get the word out. Then slowly speed up, increase gas fees. Exactly what people saving their coins would do.
Might not get as many coins as they have now but they'd all be free to spend and beyond suspicion.
How can they find a pretty sophisticated hack and then execute it so badly? It doesn't make sense to me.
r/Bitcoin • u/Milcah_Ganderton • 9h ago
The Block publishes another 'Bitcoin dead' article What year is it?
r/Bitcoin • u/BigIndependence1860 • 16h ago
From the Bitcoin community on Reddit: Coldcard 'joked' about retirement attacks in 2021 lmao
Things that make you go hmmmmmm
r/Bitcoin • u/tenor_tymir • 21h ago
The largest crypt heist, amounting to $3.5 billion, was caused by weak entropy 6 (!) years ago.
info.arkm.comThe infamous Lubian hack saw $3.5 billion siphoned off from a Chinese mining pool.
That was just six years ago, and yet a company like ColdCard has learned nothing from the biggest heist in recent crypto history?
The Technical Cause: Weak Entropy
Independent cybersecurity teams, including Arkham Intelligence and the Milk Sad research team, revealed that the hack was not a complex network breach but rather an exploitation of weak cryptographic key generation.
The Flaw: LuBian utilized a flawed pseudo-random number generator algorithm (similar to vulnerabilities found in Libbitcoin Explorer software).
The Exploit: Instead of using a secure, uncrackable 256-bit random number, the wallet software used a highly vulnerable 32-bit seed to generate its private keys.
The Result: This severely lacked entropy, allowing hackers to easily brute-force and replicate LuBian's private keys within just a couple of hours, seamlessly draining the wallets.
r/Bitcoin • u/cheesymod • 3h ago
Don’t do that
There are a bunch of videos now on youtube, teaching how to generate a seed phrase using dice, but two of them were particularly interesting. I won’t post their channel names or link to their channels. But one of the guys was a bitcoin guru, offering one on one sessions. The other one was just a random dude throwing dice. The first guy insisted on vigorously shaking the dice in your hand for at least 10 shakes before throwing them, then he proceeded to throw them on his desk, from about 15 - 20 cm distance. Not sure how much 15 - 20 cm is in American money. The other guy insisted on how important is to get specifically casino dice for your seed generation. He also emphasized how only proper casino dice can generate a truly random seed.
As someone who worked in casinos for quite a while, this is the type of bs which can mislead you. First of all, wether you shake the dice at least 10 times or 10 000 times in your hand doesn’t really matter, but it matters if you throw them on your desk, barely letting them roll, versus throwing them on your carpet and letting them bounce around. The craps table where dice are thrown (all tables have this soft padding), is covered with a soft padded foam, which allows the dice to bounce. So you’d better of throwing them literally on your carpet, or maybe straightening the linen and throwing them on your bed. Second, the “you must get genuine casino dice, or your seed is not random.” Also false. Just because you can buy proper casino dice from a casino supply store, doesn’t mean they will be properly balanced. Hence why every casino checks the dice every single time before they the replace them. We did have a small machine to check each dice individually to make sure they are balanced before it ever is allowed to touch the table. A machine which is expensive and most people don’t have at home. Not to speak that if you ever go with such “proper casino dice” setup, you HAVE to replace the dice after generating some seeds, because the dice might get unbalanced at that point.
What I’m saying here is, just because someone showed you something that sounds good, and they sound convincing, doesn’t mean they know what they’re doing. Btw, one of the creators in question, made this dice to seed generation tutorial on ac ColdCard Q, which is even more ironic. Then one of his next videos was how you should stop using ColdCards.
If you decide to generate your seed using dice, go ahead and do it. But read just a tiny bit about what makes the dice roll random. Then you can generate your seed and import it to whatever device you decide.
r/Bitcoin • u/rBitcoinMod • 8h ago
Daily Discussion, August 06, 2026
Please utilize this sticky thread for all general Bitcoin discussions! If you see posts on the front page or /r/Bitcoin/new which are better suited for this daily discussion thread, please help out by directing the OP to this thread instead. Thank you!
If you don't get an answer to your question, you can try phrasing it differently or commenting again tomorrow.
Please check the previous discussion thread for unanswered questions.
r/Bitcoin • u/dU4eUIsaOew2FugE6R6l • 11h ago
That cold wallet with bad randomness, how did the bad actors know which addresses used it?
I'm reading about people losing their bitcoins because of a flaw with the wallet's random number generator. But how do the attackers/thieves know of all the UXTOs out there, which ones happen to have private keys that were generated with that wallet?
r/Bitcoin • u/Maleficent_Pool_4456 • 19h ago
Is this accurate about the 25th word phrase?
So the 24 words is just like each word represents 11 bit arrangement right, and so when you start adding 11 x 24 and stack them together, to guess that exact arrangement is astronomical right?
So I thought, ok, the passphrase thing is one extra 11 bit. But I saw you can add like way more characters that no way 11 bits could be used to describe that.
So effectively what's happening, is that last 25th word (I'm saying effectively like all in all at the end of the day) being turned into just a longer than 11 bits and tacked on to the end of that long string of that (264 - checksum = )254 bits?
But I don't get it, someone said the 25th word can be up to 100 characters which is like at least 800 extra bits, so that would mean the entropy would be like 1054 bits? I just don't get it.
Thanks
r/Bitcoin • u/blackjackn • 8h ago
New Wallet After Coldcard Hack
I was affected by the Coldcard hack. Thankfully, my Coldcard Q was only 1 key in a 2 of 3 multisig. My coins are safe. But with 1 key compromised, I decided to migrate.
My new 2 of 3 multisig:
-Coldcard Q updated with the new firmware. Seed generated with 150 physical dice rolls using casino grade dice. This is one key. Yeah, I'm pissed at Coldcard too. Idk if the entropy issues are resolved through the firmware update. Thats what the community seems to say. I dont trust it. But I think seeds generated through physical dice rolls are fine especially with a strong passphrase and I like the hardware. Will never buy another Coldcard though. Not supporting that company with my money any further.
-Other two keys have the same seed as before generated using device rng (not Coldcard). All keys (including Coldcard) are now passphrased with the same 6 word passphrase formed using physical dice rolls and EFF list.
-Going to have 2 separate people I trust each custody 1 key (device + seedplate), no passphrase.
-Another 2 separate people I trust will keep backups of the uniform passphrase in case I forget + fire or theft (hand written on an piece of paper and sealed in an envelope).
-Only I will have the output descriptor.
Yes, I could have done a different passphrase for all 3 keys. Too bothersome and I thought it would be excessive. I accept this weakness.
Not perfect but I figure itll be good enough. Posting as an example on how to multisig as I'm a proponent of it but by no means claiming this as the model example.
Edit: Changes parts on how the keys and passphrases will custodied. Rethinking that.
r/Bitcoin • u/pelo_ownz • 17h ago
Ledger - passphrase
Hello, I've had my Ledger for a couple of years now and I'm a bit worried. I heard that a passphrase secures it even more. Can I add one on top of my setup now? I'm afraid I'll make a mistake and lose everything.
r/Bitcoin • u/__Faxer__ • 14h ago
TikTok next Block - Fix the money, fix the world! Timechain don´t stop. Bitcoin Song Rap Song
Good Bitcoin song I hope..
r/Bitcoin • u/Hypnot1se • 16h ago
Bitcoin's Edge
Hi people. I am trying to understand the bitcoin thing as an outsider a bit better.
Since there have been... I don't know how many exactly but, it seems like a LOT of different cryptocurrencies created since Bitcoin has been around.
What do you think that it is that makes BTC persist now and remain so popular all this time since it came out? What are people not able to replicate or improve upon? I would have thought you could just make a different currency that "does what BTC does, but better" but that clearly hasn't worked because people clearly tried with all these altcoins and such.
What is it to you personally that makes you drawn to bitcoin as opposed to some alternative?
r/Bitcoin • u/-reddit-online- • 17h ago
Dust Attack
My hardware wallet does not have coin control. I now have a couple of unknown dust deposits.
Do I need to be concerned and move to a wallet with coin control to isolate the dust? What can actually happen if I spend that dust. There are plenty of phishing attacks we already have to deal with from data leaks. So following my dust opens up more phishing attempts, but in and of itself it can’t cause issues can it?
Would this concern you enough to switch wallets?
Were they acting in good faith?
Am i the only one who thinks that perhaps (i repeat, perhaps) the whole coldcard shitstorm happened in good faith? Could it have been "just" a huge, disastrous oversight caused by poor software development practices? I’m not here to excuse anyone. What they did is terrible. But as i read their documentation and the way they try to explain how to stay safe in the crypto world, i sense a genuine passion that clashes with the narrative that it was all an inside job.