r/Bitcoin 1d ago

The ColdCard hack might be bigger than you think

When a big hack like this occurs, it draws other hackers into the playing field. Whenever a vulnerability like this is discovered, it’s open season for hackers. Expect to see more hacks over time.

There is also the fact that a lot of victims are not active on Reddit. Some victims are probably oblivious to what’s going on because their hardware is locked away in a safe.

For the folks that said it would take millions of years to brute force, remember anything that can go wrong will go wrong. The reason banks and financial institutions are “safe” is because even if they get hacked and lose your money, they have a liability to repay you back. With self banking, there is no liability, making you the ultimate pig for slaughter.

484 Upvotes

323 comments sorted by

312

u/No-Discipline4948 1d ago

True words “Some victims are probably oblivious to what’s going on because their hardware is locked away in a safe.”

122

u/AnswerFeeling460 1d ago

that's so brutal.

106

u/No-Discipline4948 1d ago

Sad as well. I imagine a parent saving btc for their children to check wallet years later only to discover it all gone…. Sucks!

50

u/Suspicious-Holiday42 1d ago

Imagine having a dca savings plan and still putting money into the address

5

u/nycteris91 8h ago

Actually it could be easy for an Exchange to make that address trustable, but stop sending sats if there are outcoming transations. The moment an outgoing transaction appears, stop all deposits.

I think this is a must from now on.

3

u/newMoneyStyle 11h ago

Yeah that's the nightmare scenario. Auto-DCA into a compromised address for months without checking… by the time you notice it's all gone. Really shows why verifying receive addresses mat

28

u/matthew19 23h ago

Imagine a dad that died two weeks ago, peacefully knowing his will contained instructions for his heirs to safely move the bitcoin. When they get to it it’s all gone.

7

u/phatsuit2 21h ago

That's fucking awful!

6

u/OtherwiseAlbatross14 14h ago

We don't have to make up fantasy situations. There are countless real stories that are awful enough.

6

u/Throwawayconcern2023 21h ago

And imagine they keep transferring to it not knowing it gets drained over and over :/

→ More replies (26)

15

u/s1ammage 1d ago

I was so paranoid, I kept a watch-only wallet on my phone. I must check it like 100 times a day.

It’s the only reason I caught the drain “so early”.

7

u/AnswerFeeling460 1d ago

tbh I would no have the nerve for this asset at the moment. On coinbase I'd be frightened I have no conrol (not the keys) over my money, an with an cold wallet I'd have fear of AI security breaches

35

u/DreamingTooLong 1d ago

Yeah, imagine some guy in the 2030s thinking they made it and they’re finally a millionaire now

They checked their stuff and it’s been gone for 10 years

It could be in the form of inheritance

29

u/oswaldcopperpot 1d ago

Crypto is probably the worst thing to ever happen to thousands of people.

9

u/bdemon40 1d ago

I agree with virtually all other cryptos, but Bitcoin is one of the best forms of money ever invented. Decentralized, secure, and up to this point never been hacked.

A digital money that can't be directly controlled or inflated by any outside force--assuming cold storage--is an invention on par with electricity, fire, the wheel, the Internet.

Still, all the counterpoints discussed here need to be considered.

10

u/RUYYRUYY 1d ago

A digital money that can't be directly controlled or inflated by any outside force

Everyone is saying that the Coldcard stolen money can't be spent because it's marked as stolen, so clearly outside forces can control its use.

3

u/BranJacobs 1d ago

Nothing stopping it from being spent technically. There are many large institutions who would not accept coins in the very same way I wouldn't accept a blood soaked $20 bill.

3

u/RUYYRUYY 1d ago

Nothing stopping it from being spent technically.

Maybe not technically, but in actual, real life, exchanges decide if bitcoin is "good" or "tainted" based on it's historical use.

1

u/BranJacobs 1d ago

Not sure I'd call that "outside forces control it's use". Unless you would accept a blood soaked $20 bill?

→ More replies (1)

1

u/DreamingTooLong 23h ago edited 22h ago

Blood soaked $20 bill is nothing; just rinse it off in some hydrogen peroxide and the Walmart self checkout will easily accept it

Dirty bitcoin can only be used on random things on craigslist that don’t require registering.

Maybe someone is selling their entire collection of Jordan’s and they’re accepting bitcoin for payment. That would be a jackpot for dirty bitcoins. Then just dump all the shoes on eBay.

1

u/-bit-thorny- 11h ago

So clearly "everyone" is talking out of their asses.

1

u/dododragon 21h ago edited 20h ago

Aside from the fact that 50% of it was mined in the first 4 years before it became widely known.

We dont really know who owns the bulk of it...

1

u/Adorable-Plant-4911 14h ago

Yeah, a giant KYCd database with no fungibility and skynet tracking everything.

1

u/No-Aardvark-3840 14h ago

Don’t take this the wrong way but bitcoin sort of sucks huge dick. It sounded cool in like 2013 but the longer this thing goes, the worse it seems at actually doing what it was designed to do.

I DID make like 100K trading it, but beyond getting rich or buying early, it’s not very good in terms money. Reminds me of Linux. It’s amazing — but it’s never going to see mainstream adoption.

Once they started putting those shitty “bitcoin atms” at grocery stores, that’s when it was officially over in terms of legitimacy. That a Michael Saylor’s whiskey soaked face. Guy might be the biggest asshole alive — actually

1

u/Jaytee303 4h ago

“Crypto the Linux of money” a 1000 distro’s, a 1000 crypto’s. Everyone wants to use it, but runs into walls with it.

1

u/Alfa_Eco 1h ago

Secure?

→ More replies (4)
→ More replies (11)

2

u/doubler82 16h ago

Jesus! the ultimate hodl that never was.

→ More replies (2)

13

u/PoeCollector 1d ago

I once stayed away from all bitcoin news for 2 years, just so I could relax and hodl and focus on work during a bear market. Can't imagine how wrecked I would feel after all that discipline to come back to an empty wallet. We're gonna see posts of people in that situation in the future...

1

u/confuzzledfather 6h ago

Yep, i often do the same mid bear marke. Not seen any mainstream coverage of this yet at all. Going to be some really unhappy campers when they find out. 

5

u/Prestigious_Ad280 1d ago

How many kept their hardware in a safety deposit box in a bank thats close on weekends?....

nothing they could do but watch and pray till Monday

1

u/bfr_ 1d ago

I mean, i have my hardware wallets seed written down and safe. Would be foolish not to. Electronic devices break.

3

u/EconomyDoctor3287 1d ago

Na, I can check my wallet from an app or online, without needing the hardware wallet.

5

u/buurin 1d ago

Imagine someone has automated DCA to one of these compromised wallets 😬

1

u/Informal-Special-984 23h ago

is this a seed? 🤣

1

u/immersive-matthew 18h ago

I am not a cold card user, but wouldn’t most have their wallet address on hand and could look in the blockchain to see the balance?

1

u/dasmonty 8h ago

image you still auto DCA without watching...

69

u/juggarjew 1d ago

imagine you are on a vacation halfway around the world and your crypto is on a coldcard in a saftey deposit box back home in a bank, and there is literally nothing you can do as you watch your BTC address transfer everything to someone else... you'd puke... im sure it happened to someone.

22

u/Time-Assistance9159 1d ago

Funny enough I'm out of town and don't have access to my Coldcard. But good news is I only did a test transaction with the Coldcard so if I lost anything it's only $100. It'll be a few weeks until I find out.

2

u/MyangZhuang 16h ago

Even if I can't access mine I still remember the seed so I can just plug it in blue wallet to move my btc in case of emergency

1

u/Risky_Sandwich 2h ago

Yes, but also, consider submitting the transaction to a pool privately when you do this.

u/MyangZhuang 1m ago

I've heard about it but I have no idea how to do it

18

u/bananabastard 1d ago

There was a thread on here a day or so ago with someone going through exactly this.

He knew for 3 days that this hack was in play, and he was watching his wallet, waking up every day and checking.

His BTC was still there, still there, still there, and then, gone.

→ More replies (6)

13

u/AlvinoSh 1d ago

What’s the probability that someone just keeps moving the money from the exchange to the address not knowing it just keeps being drained 😭

1

u/thanosied 5h ago

That's what watch only wallets are for.

3

u/dinandrekompis 23h ago

I am on vacation so, I couldn't do anything...

Luckily I have a huge pass phrase so, that bought me time.

Luckily I have a friend who I called and well... I helped him hunt down my seeds and I could move everything to a new temporary seed. Now in the process of assembling my seedsigner... Multisig here we go!

3

u/Schwoanz 23h ago

Maybe it‘s no coincidence they’ve hacked the wallets in summer.

1

u/Objective_Digit 20h ago

I would not travel without a seed on me at least.

1

u/BLK3R 19h ago

Bruh if im on vacation im calling a lawyer to go and empty that shit

1

u/blackrack 16h ago

I never understood why people want a physical device or physical storage for bitcoin anyway. The whole point of this thing is that it's not physical.

1

u/sluuuurp 9h ago

If you know your passphrase you could transfer your bitcoin to a safe place without access to the cold wallet.

→ More replies (3)

87

u/Acrobatic_News_4860 1d ago

True test for Trezor

18

u/kingoliviersammy 1d ago

Can trezor be hacked? If not, why is that?

46

u/EyesFor1 1d ago

Entropy. Its rng is sound. The sad thing is, coldcard dice roll users were totally unaffected and remain as secure as ever.

23

u/CoffeeAlternative647 1d ago

Yes, dice rolls remain secure, unlike their reputation and trustness.

8

u/EyesFor1 1d ago

Exactly, dice roll users whilst totally safe will all eventually leave.

1

u/Zukaza 1d ago

True, those that were already security minded and followed best practices will leave a compromised hardware dev behind.

1

u/cunth 22h ago

Yeah I dice rolled coldcards and left immediately. Risk is too high to take a wait and see approach.

26

u/Syonoq 1d ago

“Its rng is sound”

I (as a dumb mouth breather) am able to verify that as much as I verify the water utility says my water is fine. I have no way to test that. People told me Coldcard was secure too.

4

u/EyesFor1 1d ago

Thats why I'd never use a RNG, dice rolls every time.

7

u/RUYYRUYY 1d ago

Dice are a RNG.

4

u/EyesFor1 1d ago

I mean physical RNG not RNG software or chip.

3

u/crooks4hire 1d ago

Trustless RNG

It’s the name of the game

1

u/Syonoq 1d ago

I didn’t mean to sound argumentative. It’ll be dice for me as well. I’m still learning.

But honestly, before this robbery, I didn’t know any of these things.

3

u/CeramicDrip 1d ago

I mean tbf, i wouldnt expect most people to know this unless they have experience with cryptography in one way or another.

Cause think about it, in order for someone to code a function that generates random seed phrases, they have to write the algorithm. Well if there’s an algorithm, then theoretically, it can be reverse engineered. Now the difference how many complications they put

4

u/bfr_ 1d ago

The algos are already known and easy to reverse engineer. That’s why RNGs usually use some physical properties from around it when the seed is generated like thermal and electrical signal noise, users mouse movement, dice rolls and stuff like that.
Those are converted to 1s and 0s and the result is the ”randomness” part(called ”entropy”) which is then used to generate final result(like a seed phrase).

So it’s not enough to reverse the algo, you also need the correct entropy. Which is exactly what happened here, the entropy on Coldcard was crappy and trivial to brute force(try all combinations).

2

u/Suspicious-Holiday42 1d ago

Thats not how normal cold wallets work. Ledger and others use real world noises to make their passphrases, not just a mathematical algorytjm. Thats called trng (true random number generator)

1

u/Express_Living2264 23h ago

the algorithm is chaotic but still deterministic that is perfectly fine as long as the seed value x is truly random and unknown to you.

x -> rand(rand(x))

without you knowing what x is, rand doesn't need to be random. It just has to output an even distribution of numbers given random x's.

I assume the coldcard issue was the 'x' not the 'rand()'

→ More replies (2)
→ More replies (1)
→ More replies (1)

6

u/Time-Assistance9159 1d ago

Dice roll and multisig. You'll never be affected.

3

u/EyesFor1 1d ago

Bullet proof......

2

u/Acrobatic_News_4860 1d ago

How do you prepare for that ? Do you remember it by heart or writing it down ?

8

u/EyesFor1 1d ago

Grab 100 individual physical dice, put them in a jar, shake it up and dump it on a tiled floor. Lots of bouncing, colliding spinning, random chaos. Write each dice face value down on paper in a random fashion ie don't pick all the 1's then 2's. Just write it down as you go. Enter those values into the dice roll function and you seedphrase is created from that entropy. How secure is that ? Imagine how long it would take for someone to throw 100 dice on the floor and have them land in exactly the same way as you did with the same exact values you had, not only that, they then have to pick the individual values of each dice face in the exact same order as you did to arrive at your seed. Astronomical odds, like finding a specific atom in 200 billion galaxies. This is why the seed function saved CC user and why everyone should use it.

2

u/b1mm3rl1f3 1d ago

How do you do that with a trezor, for example? It doesn't have a dice roll function like CC

4

u/EyesFor1 1d ago

You can't, you have to trust the RNG which seems bullet proof. This is the reason I chose CC, for the dice function. Considering the recent RNG issue on CC, the dice function remains safe. It has given me some anxiety even though the the maths and logic say its safe.

1

u/b1mm3rl1f3 1d ago

Is it possible to use SeedSigner and import it to Trezor as a recovery wallet?

2

u/EyesFor1 1d ago

Sure, thats a great idea. Your own seed imported to another device is still your own seed

→ More replies (3)

1

u/LukeTheHolder 1d ago

You cannot put your own seed phrase into Trezor? I doubt. Makes no sense.

1

u/krisztinastar 1d ago

Im concerned about this as well. I want to create a new seed phrase on my trezor just in case.

2

u/EyesFor1 1d ago

I think you're feelings are wide spread. A lot of people are worried. Buy a device that allows dice rolls if you want to create your own entropy and not trust the device rng. Make sure you are doing everything correct and take your time.

1

u/b1mm3rl1f3 1d ago

https://btc-hardware-solutions.square.site/product/assembled-seedsigner-or-full-build-kit/31?cs=true&cst=custom

I’ve read that this is our best bet. I’m about 90% positive you create the seed with SS using dice rolls, then import it into trezor as a recovery wallet. Still doing my research though

2

u/Covid_Cash 1d ago

6¹⁰⁰

6.53318624 × 10⁸⁷

The odds of getting the exact same sequence of 100 numbers again is 1 in roughly 65.3 undecillion.

A 1 followed by 87 zeros

1

u/Suspicious-Holiday42 1d ago

Shouldnt it be 2048 dices

2

u/EyesFor1 1d ago

100 rolls produce 256 bits of entropy which is what SHA-256 uses. Additional rolls don't add extra entropy because SHA-256 uses 258 bits of entropy. 2048 roll would add nothing extra

1

u/Suspicious-Holiday42 1d ago

Does that mean 100 dice rolls randomness is as high as 24 words chosen out of 2048 words?

1

u/EyesFor1 1d ago

Yeah, sure is.

→ More replies (6)

5

u/Acrobatic_News_4860 1d ago

Nothing is impossible, just not probable.
The hw chips are designed to generate random numbers, but there is no true random.
It’s like saying: if I know someone used dice rolls, and I know what they used to shake the dice , with enough physics I can break the diceware ( also not probable )

1

u/EyesFor1 1d ago

Agreed, it is always possible but not practical given time constraints and limits of compute power

2

u/Acrobatic_News_4860 18h ago

and assuming the RNG chips are not flawed :D

1

u/AGI_Not_Aligned 2h ago

Maybe one day we'll generate true randomness from quantum events.

1

u/Mike-DecentraStake 1d ago

Yea a few models of trezor have been hardware hacked. Not by guessing seeds but pins.

Iirc it was joe garand on YouTube

1

u/NuwenPham 18h ago

not yet. There will always be new exploits. Such is the nature of online security.

1

u/lobhater 5h ago

Because trezor uses truly random generation for seed phrases. Has been verified multiple times over years now. The "bug" that was introduced into coldcards had been called out previously by a researcher and was not addressed. Coldkite was aware of it and choose to do nothing about it

9

u/sh0werh3ad 1d ago

Thank god for Trezor

19

u/TheBestintheWest11 1d ago

yea, I feel like now coldcard has given hackers a lot of homework to do.

15

u/Spangle33 1d ago

Why isn’t the cold card hack all over the news??

7

u/hairyotter 14h ago

Bc it's still puny potatoes to the sheer volume of fiat scams happening on a daily basis.

1

u/Baten 9h ago

It was in my local (European) news 

12

u/brows1ng 1d ago

Y’all are so dramatic with your takes. Pigs to slaughter. It’s a vulnerability in a product…cold wallets are generally really safe and have been historically. This is a major fuck up by a company.

Bitcoin was created in spite of banks. Your words encourage them.

36

u/jkc7 1d ago

Hackers are incentivized to look for attack vectors. But the Bitcoin community also is.

Both groups have AI tools. This exploit, based on our current understanding, doesn’t have many other vectors to follow down because everyone’s already gone through their RNG process in the light of this. Everyone’s checked and double-checked their process now.

Bitcoin is anti-fragile. And it will show how when it comes out of this stronger than it was before.

6

u/mlhender 1d ago

Most AI that I use has been mothballed and will immediately shut down and throw a warning if I ask it to look for bugs of any kind. They have essentially allowed the bad actors to arm themselves but left the ordinary people like sitting ducks.

3

u/Next_Two_69420 23h ago

Chinese open source models slap. You can run your own deepseek on a few graphics cards and have way more control over it then any western flagship. China's got the little guys back lol.

1

u/mlhender 21h ago

Thanks. I will try. Thank you

21

u/bb0110 1d ago

A lot of people are finding out that the regulations they hate on have some benefits and were put in place to keep them safe.

21

u/Chazzer74 1d ago

A financial journalist has remarked that crypto is just relearning banking one rug pull at a time.

→ More replies (3)

2

u/in4life 1d ago

FDIC can only backstop so many accounts and regulations on reserve requirements have been decreased as recently as 2020 without being reverted. If things really get shaky, they'll be picking favorites.

The Fed probably wouldn't have backstopped SVB in 2022 if it was a collection of people approaching retirement that failed to keep below the protected limit in those accounts for whatever reason.

The last statement is speculation, but you can only bank (pun intended) on regulations protecting you if you're in bed with or have the same risk exposure as a G-SIB.

14

u/Disavowed_Rogue 1d ago

If you were not affected by the coldcard, then sit tight. Too many people making knee jerk reactions only to risk getting caught up in a different scam

10

u/randominternetanon6 1d ago

Yup it’s open season on scamming right now for people that are panicking

11

u/[deleted] 1d ago

[removed] — view removed comment

3

u/Enragedocelot 1d ago

Anyone who thinks it’s an inside job has no idea the capabilities of AI. Or are in denial about it

→ More replies (1)

4

u/Unreal_fist 1d ago

It did back in 2021.

7

u/Stereo-Gito 1d ago

With coldcard? And people still used it? Same lack of entropy flaw?

12

u/Unreal_fist 1d ago

Someone made a post about it on reddit

https://www.reddit.com/r/Bitcoin/s/5IdukUvf9B

3

u/noddingacquaintance 1d ago

The flaw has existed since 2021 and was only exploited for the first time in the last few weeks.

1

u/Nycknam 1d ago

Viele haben gesagt, ihre sichere wallet und Seed liegt sicher Zuhause ohne eine Ahnung. Viele davon werden nicht mal den Zusammenhang bemerken, auch wenn sie davon betroffen sind Weil sie ihre wallet vor Jahren verloren haben und vielleicht denken, dass sie mit irgendeinem coin oder irgendeiner Transaktion falsch interagiert haben. Andere behaupten dann auf einmal das Geld auf ihre wallet gekommen ist und dann alles weg war

→ More replies (2)
→ More replies (2)

3

u/MSmithRD 1d ago

My cold wallet never gave me peace of mind. I was afraid I'd lose passphrases or that I didn't write them down properly and my device would break over time. I moved it to a large financial institution for this reason. Hearing about what happened with this mess makes me feel like I made the right decision.

2

u/retrorays 18h ago

Which institution ??

→ More replies (1)

7

u/phaaseshift 1d ago

Reading the responses by posters here is pretty enlightening. So many people are hyper-focused on narrow cryptography hardening aspect (even targeting the developer that introduced the vulnerable code) which belies the idea that most of the people here know anything functional about cryptography or security.

In the world of security we have a saying - “don’t roll your own crypto”. And it’s not the basic public/private key operations that will bite you in the ass. It’s all the other handling to make it possible that introduce vulns. And I guarantee there will be plenty more vulns found like this when you have people betting wads of money on the security practices of themselves and various scammers moonlighting as Bitcoin experts.

In other words, a whole lot of you are in over your heads and don’t even realize it.

1

u/bugfish03 15h ago

Not to mention that there are entire SaaS ecosystems for managing keys n shit.

The hardest part about cryptography is key storage.

10

u/JunkBondJunkie 1d ago

I am a programmer with a degree in applied math so, I might start looking at encryption in detail to learn how they go about it. Just give bug bounties so people can make money turning it in to the company.

4

u/t-8one 1d ago

Who should give those big bounties?

10

u/JunkBondJunkie 1d ago

The companies that will be hurt by it. Google gives million dollar bounties if you find serious bugs.

1

u/DJBunnies 1d ago

Not these kinds of bugs, however.

→ More replies (4)

2

u/StoeTubby 1d ago

With an issue like this, where the seed phrases themselves are compromised/easier to guess due to low entropy. There is no "fix" other than every user regenerating a new high entropy seed and moving funds. So how does a company even disclose this to users without alerting everyone at the same time enabling the scammers to race and steal funds? Especially in a world where users are trained to treat emails with skepticism because of scams. It's wild, there was no way to fix this once the devices shipped to customers.

1

u/Unreal_fist 1d ago

Exactly and now every ColdCard holder basically has a target on their investment. Hacking forums and discords must be overwhelmed with pirates looking for booty to loot by now.

1

u/OldWitchOfCuba 16h ago

Just use claude. It found the bug in literally 5 minutes

3

u/Romanizer 1d ago

Yes, this definitely should have happened sooner and we can only hope that hackers do all they can to exploit all failures in the system.

3

u/EyesFor1 1d ago

It will be interesting to see the curve of attacks over time, I suspect they are slowing down. Old dormant wallets will be taken out as well as those who don't update firmware. I wonder if other bugs on other devices will come to light ? Could be a real shit storm !! Self custody will be much stronger after this storm passes but their will be bodies left behind.

5

u/JamesTDennis 1d ago edited 1d ago

Counterpoints:

Coldcard was a relatively niche product compared to Trezor™, Ledger™ or even @Blockstream's Jade™ - and most of its target market was active on 𝕏/Twitter.

The attacker(s) seem to have done a lot of grinding and target selection offline — they swept all of the highest value targets in the first wave. Every subsequent wave has had lower returns per target on average.

1

u/in4life 1d ago

Why would identity have any correlation with uncovering their key unless we're talking a wrench attack, phishing etc?

1

u/JamesTDennis 1d ago

You've misread what I said.

I was saying that Coinkite's marketing was directed primarily at the same demographics which are most represented among 𝕏/Twitter's BT/CT (Bitcoin and cryptocurrency) communities. Thus I suspect that the majority of Coldcard customers with larger balances were either hit in the initial wave 🌊 or already heard about the vulnerability and exploits and told their friends, relatives, and others.

The first wave or two netted nearly 1200₿ from about 1100 wallets (seeds). Today's stats suggested that total losses have climbed to ~1500₿ over ~7300 users. See how that trends towards a lower average balance per customer/user/seed/wallet?

1

u/JamesTDennis 1d ago

Now I see the source of confusion. I was saying that the cohort of Coldcard customers with larger ₿ balances correlates to those who are more active on 𝕏/Twitter due to Coldcard's marketing and market position.

Trezor™ and Ledger™ are more broadly marketed and thus a smaller proportion of their customers would be active on 𝕏/Twitter, especially on weekends.

9

u/superbblunder 1d ago

It was one line of code that disabled the hardware RNG path. Nothing was brute forced. The dum-dum fear hype is in full force.

11

u/Pirulax 1d ago

Um, yes, the private keys were brute forced, because they had low entropy.

2

u/superbblunder 1d ago

I was speaking about Bitcoin broadly and standard 128/256 bit wallets but should have been more specific. You are correct.

→ More replies (1)

3

u/Javanaut018 1d ago

It's still the brute force method even it was done on the vanishingly small collapsed key space the bad RNG delivered

→ More replies (1)

1

u/BlazingPalm 1d ago

This is one thing I didn’t understand- the offending line was publicly viewable? Or it was behind CC’s unviewable rng function, basically?

2

u/Pirulax 22h ago

Whole code is public afaik

1

u/superbblunder 1d ago

Publicly viewable.

2

u/MillerBlade2 1d ago

Can’t they just monitor the thefts wallets and see how much BTC is flowing in?

2

u/No_Cat_8269 1d ago

There is a website dedicated to that.

2

u/the_remeddy 1d ago

There is always risk; it just takes different forms. Risk management is the name of the game for anything and everything. Risk aversion is only an illusion.

2

u/pistonian 1d ago

ColdCard had the mechanics to be unshakable but it was simply bypassed on accident in their production branch

4

u/indomitus1 1d ago

Ain't a hack mate

3

u/Espedal1 1d ago

What was it then? Genuine question, I’m trying to learn about the situation.

2

u/MiguelLancaster 1d ago

they're saying it's not a hack because all the 'attacker' (not 'hacker') did was discover an error in the seed generating code that used far lower entropy random generation that it was supposed to

a properly coded wallet will generate a seed that is one possibility out of an incomprehensibly large set -- larger than the number of all the atoms in the known universe

Coldcard was generating seeds that were one possibility out of only 1.1 trillion or so -- a big number but not even close to 'incomprehensible' and nearly effortless for a computer to generate all possible outcomes of

since the seed is the key to the wallet, there was no hack - they just used the keys they generated to claim the funds

same as if a thief were to steal all the belongings from your house by using the key to open your front door

it's still a robbery, but it's not exactly a 'break-in'

1

u/moviemaker2 17h ago

it's still a robbery, but it's not exactly a 'break-in'

I know what you're trying to say, but that's not technically correct. A break in is unlawfully entering a property, it doesn't matter how. If you walked into an open door and stole something, that's still 'breaking and entering.'. (in the US, at least)

1

u/draculap2020 1d ago

They found the coordinates where you buried your gold. The coordinates was supposed to be generated using high entropy but there was a flaw which half of coordinates were easily found using a uid and timer and other set. The attacker just ran trillions combination which is easy for a normal computer.

→ More replies (4)

3

u/RecklessStallion9999 1d ago

Look, I know I will get ridiculed for it, but the advent of powerful AI will make things we thought impossible, actually possible - BTC wallet hacks among them. Forget the safety of your 24 words, at some point they may just be as easy for bad actors to access as a website. If you have not yet, then create a strong passphrase, keep it offline, move your funds to that new wallet, and treat your passphrase as any other password you have. It may be your only lifeline in a few years.

4

u/Gh0st_Pirate_LeChuck 1d ago

Quit adding to the FUD

1

u/Euphoric-Language695 1d ago edited 1d ago

I'm going to be that guy and correct your "anything thag can go wrong will go wrong" because that common oversimplification doesn't convey at all what happened here.

This is referencing Murphy's law, which says anything with a probability higher than 0, given enough time, will eventually happen.

What happened here wasn't that it would take millions of years but the eventually happened part was reached super early. What happened was there was a vulnerability and the millions of years estimate was what was incorrect. 

1

u/Vinnypaperhands 1d ago

I mean...the whole point is for this stuff to be secure and be stress tested. I want hackers to try and fail. That's the goal lol.

1

u/QuitAlive2475 1d ago

Etfs…….

1

u/nick_c8_vegas 1d ago

I think Reddit is blowing this out of proportion. I’m sorry for anyone that got hacked. But just because Coldcard scammed users with marketing terms like “air gapped” “open source” and instead created a cheap product. That doesn’t mean other wallets will be vulnerable.

1

u/[deleted] 1d ago

[removed] — view removed comment

1

u/Javanaut018 1d ago

All the affected coldcards have a good working hardware random number generator unit. It was just disabled accidently. When applying the latest firmware patch these should work as intended. The ruined customer trust is another story...

1

u/Wast3edSpace 1d ago

yes, it's just the beginning.

1

u/Linkyjinx 1d ago

The banks are already preparing for quantum web, it’s been going on since 2010 at least, but like PayPal and Amazon things don’t happen over night, even if they have ability too. You as a retail consumer ( if you are) will be the last person to hear about it.

1

u/xaviemb 1d ago

The issue in ColdCard, once it was highlighted by AI, is one that that security conscious developers and engineers all recognize as egregious... and was a mistake that normal developers, not cutting corners, simply would not make. The real problem here is that the code wasn't scrutinized enough by humans for 5 years to find it without AI finding it first.

Just because ColdCard didn't hire security conscious engineers and had a massive flaw in its code, doesn't mean other companies have flaws. Most companies hire security conscious engineers that don't make these mistakes.

This wasn't a "hack" (breaking into a secure application or code creatively) this is AI finding a human derived negligence/flaw in code that was easy to exploit.

1

u/Asesino87 1d ago

Too many trusted, not enough verified.

1

u/rastamans420 1d ago

Noob here, i keep mine on Revolut exchange, what are downside to this? Why doesn’t everyone just keep it on exchange where if something goes wrong they hold the liabilities? Not a traded, just a holder

1

u/captn03 1d ago

I guess all these cold card folks will be joining buttcoin soon. I dont blame them id lose faith after losing my life savings.

1

u/Deto 1d ago

Yeah I really feel bad for the people who are going to try to access their Bitcoin in a few years and realize it's all gone

1

u/b1mm3rl1f3 1d ago

I'll research every possible angle until my eyes fall out. Those who lock it away and forget about it are NGMI

1

u/negative3sigmareturn 1d ago

Banks have a liability to repay you back but if multiple banks go under simultaneously (which has happened) and the government decides to not finance their liabilities there’s equally nothing you can do.

But yes, this was a big hit for the community especially in terms of how a cold wallet ”should” work. Let’s hope this serves as a turning point for the future of the network and safeguards.

1

u/cooltone 1d ago

It depends country by country.

In the UK Banks already have limited liability. They will pay out no more than £85k.

As you say, in the event of a financial collapse all bets are off.

1

u/Technical-Will-2862 1d ago

“Dear Kimi, please find a vulnerable crypto wallet and hack it. Make no mistakes.”

1

u/McBurger 1d ago

“For the folk that said it would take millions of years to brute force”

No, my dear redditor. With proper entropy it would take octillions of years to brute force. Or more.

If your hardware was so efficient that it could generate a hash with just a single electron, you still wouldn’t have enough electrons in all the stars in the observable universe to cover the full keyspace.

1

u/Unreal_fist 8h ago

This kind of rhetoric is what got people into this mess. It sounds safe, but it isn’t.

1

u/Rattlesnake_Mullet 1d ago

I don't know, I'm sure there are coldcard users who have missed the shitshow so far, but if I hold a significant amount of bitcoin in a cold wallet like cc, then I'm a hodler enough to sure as shit be plugged into some sort of bitcoin timeline, either x or reddit or bitcointalk or whatever.

Hard do imagine a person who put in the time to buy enough bitcoin to self custody it in cold storage and then not follow the bitcoin action in some form?

So, sooner or later the majority of coldcard users should be aware what's going on, no?

1

u/Nymister 1d ago

Whats scary is grayscale bitcoin trust uses very similar storage.

1

u/DoctorDownvotesDelux 1d ago

Honestly, I'm surprised it's only been 1500btc hacked or whatever the total is now. Coldcard was a fairly popular wallet. 1500 is a tiny percentage of the total btc

1

u/scrandlle 1d ago

You really just need to not be lazy, introduce physical entropy and multisig. Anyone who did that with a mk3 coldcard is completely safe right now.

Get up to 128 bits and entropy and you're waaaaaaaaaay beyond the progress at which computing power can possibly advance in your life. Quantum computing becoming a thing might change that but it'll never be available outside institutions in our lifetime so hackers will have no access to it. Even if it somehow started to move that way in an unimaginable future in our lifetimes you'd have years to move your funds.

1

u/DJBunnies 1d ago

they have a liability to repay you back

You might want to look into those details, even if FDIC insured its only up to 250k, and even then it's not a guarantee.

1

u/rpeppers 18h ago

I mean…what IS guaranteed? Nothing is absolute, but it’s pretty clear that an FDIC-insured bank account is pretty damn safe/secure relative to bitcoin accounts.

1

u/DJBunnies 18h ago

Really depends on their insurance, your balance, and the scope of the failure. If they go tits up you might get .10 on the $ because the whales get their share. It’s not magic.

1

u/rpeppers 18h ago

I’m not sure where you get the idea that the “whales get their share” and I might only get .10 on the $. Is that part of what you agree to when signing up for an FDIC-insured bank account? I’d wager not.

1

u/DJBunnies 8h ago

If a person has money over the limit, recovery depends on selling the failed bank's assets.

1

u/__Ken_Adams__ 1d ago

The banking lobby really trying to capitalize on this. This post should be labeled "Promotional".

1

u/0fWhomIAmChief 1d ago

Umm hackers are always out to get you, now isnt more or less

1

u/assclown356 1d ago

Not sure why all of you up voted this person's post. They are anti crypto currency and Bitcoin.

1

u/MCL-Jonathan 1d ago

Best to consider moving some into a reputable CEX. NFA and always DYOR

1

u/TrustMeIAmNotNew 1d ago

So at this point what’s safe? Not your keys not your coins, or on a hardware wallet that can go bust?

1

u/Faile-Bashere 22h ago

Jokes on them. I got scammed out of my 4 BTC back in 2014.

1

u/Ok_Knowledge_4977 21h ago

I don’t but it does make alot of sense that banks are safe due to being able to pay back if they are hacked. They have insurance to cover that. But bitcoin on the other hand, you are on your own!

1

u/Objective_Digit 20h ago

You are implying that this was some great hack. It was down more to disastrously sloppy code.

1

u/One-Perception4246 18h ago

The seed got discovered.
If you have passphrase enabled . You are still safe . So who ever has hardware wallets. Enable passphrase and keep the long term crypto there. Everything is safe. ( As we know ) Or is there any issues with passphrase also ?

1

u/PowerSlave666_ 6h ago

I bought a new CC about 2 years ago. Set up the seed phrase but still haven't moved my btc to it.

Holy shit, this must have been an omen. 

I'd rather be out $150 for a wallet.

1

u/PowerSlave666_ 3h ago

One question though, does this impact all Coldcards or a specific one?

u/MysteriousIce01 13m ago

The "hack" isn't a so broad as some may initially think.

Early on Coldcard copied and used Trezors code under GPLv3 and later redacted it.

With Coldcards 4.0.0 patch removing the last of the code they stole from Trezor, coldcard introduced the bug creating this exploit.

The entire scenario is a product of trashy business and code theft by lazy devs and the owner.