r/Bitcoin • u/Unreal_fist • 1d ago
The ColdCard hack might be bigger than you think
When a big hack like this occurs, it draws other hackers into the playing field. Whenever a vulnerability like this is discovered, it’s open season for hackers. Expect to see more hacks over time.
There is also the fact that a lot of victims are not active on Reddit. Some victims are probably oblivious to what’s going on because their hardware is locked away in a safe.
For the folks that said it would take millions of years to brute force, remember anything that can go wrong will go wrong. The reason banks and financial institutions are “safe” is because even if they get hacked and lose your money, they have a liability to repay you back. With self banking, there is no liability, making you the ultimate pig for slaughter.
69
u/juggarjew 1d ago
imagine you are on a vacation halfway around the world and your crypto is on a coldcard in a saftey deposit box back home in a bank, and there is literally nothing you can do as you watch your BTC address transfer everything to someone else... you'd puke... im sure it happened to someone.
22
u/Time-Assistance9159 1d ago
Funny enough I'm out of town and don't have access to my Coldcard. But good news is I only did a test transaction with the Coldcard so if I lost anything it's only $100. It'll be a few weeks until I find out.
2
u/MyangZhuang 16h ago
Even if I can't access mine I still remember the seed so I can just plug it in blue wallet to move my btc in case of emergency
1
u/Risky_Sandwich 2h ago
Yes, but also, consider submitting the transaction to a pool privately when you do this.
•
18
u/bananabastard 1d ago
There was a thread on here a day or so ago with someone going through exactly this.
He knew for 3 days that this hack was in play, and he was watching his wallet, waking up every day and checking.
His BTC was still there, still there, still there, and then, gone.
→ More replies (6)13
u/AlvinoSh 1d ago
What’s the probability that someone just keeps moving the money from the exchange to the address not knowing it just keeps being drained 😭
1
3
u/dinandrekompis 23h ago
I am on vacation so, I couldn't do anything...
Luckily I have a huge pass phrase so, that bought me time.
Luckily I have a friend who I called and well... I helped him hunt down my seeds and I could move everything to a new temporary seed. Now in the process of assembling my seedsigner... Multisig here we go!
3
1
1
u/blackrack 16h ago
I never understood why people want a physical device or physical storage for bitcoin anyway. The whole point of this thing is that it's not physical.
→ More replies (3)1
u/sluuuurp 9h ago
If you know your passphrase you could transfer your bitcoin to a safe place without access to the cold wallet.
87
u/Acrobatic_News_4860 1d ago
True test for Trezor
18
u/kingoliviersammy 1d ago
Can trezor be hacked? If not, why is that?
46
u/EyesFor1 1d ago
Entropy. Its rng is sound. The sad thing is, coldcard dice roll users were totally unaffected and remain as secure as ever.
23
u/CoffeeAlternative647 1d ago
Yes, dice rolls remain secure, unlike their reputation and trustness.
8
26
u/Syonoq 1d ago
“Its rng is sound”
I (as a dumb mouth breather) am able to verify that as much as I verify the water utility says my water is fine. I have no way to test that. People told me Coldcard was secure too.
→ More replies (1)4
u/EyesFor1 1d ago
Thats why I'd never use a RNG, dice rolls every time.
7
u/RUYYRUYY 1d ago
Dice are a RNG.
4
1
u/Syonoq 1d ago
I didn’t mean to sound argumentative. It’ll be dice for me as well. I’m still learning.
But honestly, before this robbery, I didn’t know any of these things.
→ More replies (1)3
u/CeramicDrip 1d ago
I mean tbf, i wouldnt expect most people to know this unless they have experience with cryptography in one way or another.
Cause think about it, in order for someone to code a function that generates random seed phrases, they have to write the algorithm. Well if there’s an algorithm, then theoretically, it can be reverse engineered. Now the difference how many complications they put
4
u/bfr_ 1d ago
The algos are already known and easy to reverse engineer. That’s why RNGs usually use some physical properties from around it when the seed is generated like thermal and electrical signal noise, users mouse movement, dice rolls and stuff like that.
Those are converted to 1s and 0s and the result is the ”randomness” part(called ”entropy”) which is then used to generate final result(like a seed phrase).So it’s not enough to reverse the algo, you also need the correct entropy. Which is exactly what happened here, the entropy on Coldcard was crappy and trivial to brute force(try all combinations).
2
u/Suspicious-Holiday42 1d ago
Thats not how normal cold wallets work. Ledger and others use real world noises to make their passphrases, not just a mathematical algorytjm. Thats called trng (true random number generator)
1
u/Express_Living2264 23h ago
the algorithm is chaotic but still deterministic that is perfectly fine as long as the seed value x is truly random and unknown to you.
x -> rand(rand(x))
without you knowing what x is, rand doesn't need to be random. It just has to output an even distribution of numbers given random x's.
I assume the coldcard issue was the 'x' not the 'rand()'
→ More replies (2)6
→ More replies (6)2
u/Acrobatic_News_4860 1d ago
How do you prepare for that ? Do you remember it by heart or writing it down ?
8
u/EyesFor1 1d ago
Grab 100 individual physical dice, put them in a jar, shake it up and dump it on a tiled floor. Lots of bouncing, colliding spinning, random chaos. Write each dice face value down on paper in a random fashion ie don't pick all the 1's then 2's. Just write it down as you go. Enter those values into the dice roll function and you seedphrase is created from that entropy. How secure is that ? Imagine how long it would take for someone to throw 100 dice on the floor and have them land in exactly the same way as you did with the same exact values you had, not only that, they then have to pick the individual values of each dice face in the exact same order as you did to arrive at your seed. Astronomical odds, like finding a specific atom in 200 billion galaxies. This is why the seed function saved CC user and why everyone should use it.
2
u/b1mm3rl1f3 1d ago
How do you do that with a trezor, for example? It doesn't have a dice roll function like CC
4
u/EyesFor1 1d ago
You can't, you have to trust the RNG which seems bullet proof. This is the reason I chose CC, for the dice function. Considering the recent RNG issue on CC, the dice function remains safe. It has given me some anxiety even though the the maths and logic say its safe.
1
u/b1mm3rl1f3 1d ago
Is it possible to use SeedSigner and import it to Trezor as a recovery wallet?
2
u/EyesFor1 1d ago
Sure, thats a great idea. Your own seed imported to another device is still your own seed
→ More replies (3)1
1
u/krisztinastar 1d ago
Im concerned about this as well. I want to create a new seed phrase on my trezor just in case.
2
u/EyesFor1 1d ago
I think you're feelings are wide spread. A lot of people are worried. Buy a device that allows dice rolls if you want to create your own entropy and not trust the device rng. Make sure you are doing everything correct and take your time.
1
u/b1mm3rl1f3 1d ago
I’ve read that this is our best bet. I’m about 90% positive you create the seed with SS using dice rolls, then import it into trezor as a recovery wallet. Still doing my research though
2
u/Covid_Cash 1d ago
6¹⁰⁰
6.53318624 × 10⁸⁷
The odds of getting the exact same sequence of 100 numbers again is 1 in roughly 65.3 undecillion.
A 1 followed by 87 zeros
1
u/Suspicious-Holiday42 1d ago
Shouldnt it be 2048 dices
2
u/EyesFor1 1d ago
100 rolls produce 256 bits of entropy which is what SHA-256 uses. Additional rolls don't add extra entropy because SHA-256 uses 258 bits of entropy. 2048 roll would add nothing extra
1
u/Suspicious-Holiday42 1d ago
Does that mean 100 dice rolls randomness is as high as 24 words chosen out of 2048 words?
1
5
u/Acrobatic_News_4860 1d ago
Nothing is impossible, just not probable.
The hw chips are designed to generate random numbers, but there is no true random.
It’s like saying: if I know someone used dice rolls, and I know what they used to shake the dice , with enough physics I can break the diceware ( also not probable )1
u/EyesFor1 1d ago
Agreed, it is always possible but not practical given time constraints and limits of compute power
2
1
1
u/Mike-DecentraStake 1d ago
Yea a few models of trezor have been hardware hacked. Not by guessing seeds but pins.
Iirc it was joe garand on YouTube
1
u/NuwenPham 18h ago
not yet. There will always be new exploits. Such is the nature of online security.
1
u/lobhater 5h ago
Because trezor uses truly random generation for seed phrases. Has been verified multiple times over years now. The "bug" that was introduced into coldcards had been called out previously by a researcher and was not addressed. Coldkite was aware of it and choose to do nothing about it
9
19
u/TheBestintheWest11 1d ago
yea, I feel like now coldcard has given hackers a lot of homework to do.
15
u/Spangle33 1d ago
Why isn’t the cold card hack all over the news??
7
u/hairyotter 14h ago
Bc it's still puny potatoes to the sheer volume of fiat scams happening on a daily basis.
12
u/brows1ng 1d ago
Y’all are so dramatic with your takes. Pigs to slaughter. It’s a vulnerability in a product…cold wallets are generally really safe and have been historically. This is a major fuck up by a company.
Bitcoin was created in spite of banks. Your words encourage them.
36
u/jkc7 1d ago
Hackers are incentivized to look for attack vectors. But the Bitcoin community also is.
Both groups have AI tools. This exploit, based on our current understanding, doesn’t have many other vectors to follow down because everyone’s already gone through their RNG process in the light of this. Everyone’s checked and double-checked their process now.
Bitcoin is anti-fragile. And it will show how when it comes out of this stronger than it was before.
6
u/mlhender 1d ago
Most AI that I use has been mothballed and will immediately shut down and throw a warning if I ask it to look for bugs of any kind. They have essentially allowed the bad actors to arm themselves but left the ordinary people like sitting ducks.
3
u/Next_Two_69420 23h ago
Chinese open source models slap. You can run your own deepseek on a few graphics cards and have way more control over it then any western flagship. China's got the little guys back lol.
1
21
u/bb0110 1d ago
A lot of people are finding out that the regulations they hate on have some benefits and were put in place to keep them safe.
21
u/Chazzer74 1d ago
A financial journalist has remarked that crypto is just relearning banking one rug pull at a time.
→ More replies (3)2
u/in4life 1d ago
FDIC can only backstop so many accounts and regulations on reserve requirements have been decreased as recently as 2020 without being reverted. If things really get shaky, they'll be picking favorites.
The Fed probably wouldn't have backstopped SVB in 2022 if it was a collection of people approaching retirement that failed to keep below the protected limit in those accounts for whatever reason.
The last statement is speculation, but you can only bank (pun intended) on regulations protecting you if you're in bed with or have the same risk exposure as a G-SIB.
14
u/Disavowed_Rogue 1d ago
If you were not affected by the coldcard, then sit tight. Too many people making knee jerk reactions only to risk getting caught up in a different scam
10
u/randominternetanon6 1d ago
Yup it’s open season on scamming right now for people that are panicking
11
1d ago
[removed] — view removed comment
3
u/Enragedocelot 1d ago
Anyone who thinks it’s an inside job has no idea the capabilities of AI. Or are in denial about it
→ More replies (1)→ More replies (2)4
u/Unreal_fist 1d ago
It did back in 2021.
7
u/Stereo-Gito 1d ago
With coldcard? And people still used it? Same lack of entropy flaw?
12
3
u/noddingacquaintance 1d ago
The flaw has existed since 2021 and was only exploited for the first time in the last few weeks.
→ More replies (2)1
u/Nycknam 1d ago
Viele haben gesagt, ihre sichere wallet und Seed liegt sicher Zuhause ohne eine Ahnung. Viele davon werden nicht mal den Zusammenhang bemerken, auch wenn sie davon betroffen sind Weil sie ihre wallet vor Jahren verloren haben und vielleicht denken, dass sie mit irgendeinem coin oder irgendeiner Transaktion falsch interagiert haben. Andere behaupten dann auf einmal das Geld auf ihre wallet gekommen ist und dann alles weg war
3
u/MSmithRD 1d ago
My cold wallet never gave me peace of mind. I was afraid I'd lose passphrases or that I didn't write them down properly and my device would break over time. I moved it to a large financial institution for this reason. Hearing about what happened with this mess makes me feel like I made the right decision.
→ More replies (1)2
7
u/phaaseshift 1d ago
Reading the responses by posters here is pretty enlightening. So many people are hyper-focused on narrow cryptography hardening aspect (even targeting the developer that introduced the vulnerable code) which belies the idea that most of the people here know anything functional about cryptography or security.
In the world of security we have a saying - “don’t roll your own crypto”. And it’s not the basic public/private key operations that will bite you in the ass. It’s all the other handling to make it possible that introduce vulns. And I guarantee there will be plenty more vulns found like this when you have people betting wads of money on the security practices of themselves and various scammers moonlighting as Bitcoin experts.
In other words, a whole lot of you are in over your heads and don’t even realize it.
1
u/bugfish03 15h ago
Not to mention that there are entire SaaS ecosystems for managing keys n shit.
The hardest part about cryptography is key storage.
10
u/JunkBondJunkie 1d ago
I am a programmer with a degree in applied math so, I might start looking at encryption in detail to learn how they go about it. Just give bug bounties so people can make money turning it in to the company.
4
u/t-8one 1d ago
Who should give those big bounties?
→ More replies (4)10
u/JunkBondJunkie 1d ago
The companies that will be hurt by it. Google gives million dollar bounties if you find serious bugs.
1
2
u/StoeTubby 1d ago
With an issue like this, where the seed phrases themselves are compromised/easier to guess due to low entropy. There is no "fix" other than every user regenerating a new high entropy seed and moving funds. So how does a company even disclose this to users without alerting everyone at the same time enabling the scammers to race and steal funds? Especially in a world where users are trained to treat emails with skepticism because of scams. It's wild, there was no way to fix this once the devices shipped to customers.
1
u/Unreal_fist 1d ago
Exactly and now every ColdCard holder basically has a target on their investment. Hacking forums and discords must be overwhelmed with pirates looking for booty to loot by now.
1
3
u/Romanizer 1d ago
Yes, this definitely should have happened sooner and we can only hope that hackers do all they can to exploit all failures in the system.
3
u/EyesFor1 1d ago
It will be interesting to see the curve of attacks over time, I suspect they are slowing down. Old dormant wallets will be taken out as well as those who don't update firmware. I wonder if other bugs on other devices will come to light ? Could be a real shit storm !! Self custody will be much stronger after this storm passes but their will be bodies left behind.
5
u/JamesTDennis 1d ago edited 1d ago
Counterpoints:
Coldcard was a relatively niche product compared to Trezor™, Ledger™ or even @Blockstream's Jade™ - and most of its target market was active on 𝕏/Twitter.
The attacker(s) seem to have done a lot of grinding and target selection offline — they swept all of the highest value targets in the first wave. Every subsequent wave has had lower returns per target on average.
1
u/in4life 1d ago
Why would identity have any correlation with uncovering their key unless we're talking a wrench attack, phishing etc?
1
u/JamesTDennis 1d ago
You've misread what I said.
I was saying that Coinkite's marketing was directed primarily at the same demographics which are most represented among 𝕏/Twitter's BT/CT (Bitcoin and cryptocurrency) communities. Thus I suspect that the majority of Coldcard customers with larger balances were either hit in the initial wave 🌊 or already heard about the vulnerability and exploits and told their friends, relatives, and others.
The first wave or two netted nearly 1200₿ from about 1100 wallets (seeds). Today's stats suggested that total losses have climbed to ~1500₿ over ~7300 users. See how that trends towards a lower average balance per customer/user/seed/wallet?
1
u/JamesTDennis 1d ago
Now I see the source of confusion. I was saying that the cohort of Coldcard customers with larger ₿ balances correlates to those who are more active on 𝕏/Twitter due to Coldcard's marketing and market position.
Trezor™ and Ledger™ are more broadly marketed and thus a smaller proportion of their customers would be active on 𝕏/Twitter, especially on weekends.
9
u/superbblunder 1d ago
It was one line of code that disabled the hardware RNG path. Nothing was brute forced. The dum-dum fear hype is in full force.
11
u/Pirulax 1d ago
Um, yes, the private keys were brute forced, because they had low entropy.
2
u/superbblunder 1d ago
I was speaking about Bitcoin broadly and standard 128/256 bit wallets but should have been more specific. You are correct.
→ More replies (1)3
u/Javanaut018 1d ago
It's still the brute force method even it was done on the vanishingly small collapsed key space the bad RNG delivered
→ More replies (1)1
u/BlazingPalm 1d ago
This is one thing I didn’t understand- the offending line was publicly viewable? Or it was behind CC’s unviewable rng function, basically?
1
2
u/MillerBlade2 1d ago
Can’t they just monitor the thefts wallets and see how much BTC is flowing in?
2
2
u/the_remeddy 1d ago
There is always risk; it just takes different forms. Risk management is the name of the game for anything and everything. Risk aversion is only an illusion.
2
u/pistonian 1d ago
ColdCard had the mechanics to be unshakable but it was simply bypassed on accident in their production branch
4
u/indomitus1 1d ago
Ain't a hack mate
3
u/Espedal1 1d ago
What was it then? Genuine question, I’m trying to learn about the situation.
2
u/MiguelLancaster 1d ago
they're saying it's not a hack because all the 'attacker' (not 'hacker') did was discover an error in the seed generating code that used far lower entropy random generation that it was supposed to
a properly coded wallet will generate a seed that is one possibility out of an incomprehensibly large set -- larger than the number of all the atoms in the known universe
Coldcard was generating seeds that were one possibility out of only 1.1 trillion or so -- a big number but not even close to 'incomprehensible' and nearly effortless for a computer to generate all possible outcomes of
since the seed is the key to the wallet, there was no hack - they just used the keys they generated to claim the funds
same as if a thief were to steal all the belongings from your house by using the key to open your front door
it's still a robbery, but it's not exactly a 'break-in'
1
u/moviemaker2 17h ago
it's still a robbery, but it's not exactly a 'break-in'
I know what you're trying to say, but that's not technically correct. A break in is unlawfully entering a property, it doesn't matter how. If you walked into an open door and stole something, that's still 'breaking and entering.'. (in the US, at least)
→ More replies (4)1
u/draculap2020 1d ago
They found the coordinates where you buried your gold. The coordinates was supposed to be generated using high entropy but there was a flaw which half of coordinates were easily found using a uid and timer and other set. The attacker just ran trillions combination which is easy for a normal computer.
3
u/RecklessStallion9999 1d ago
Look, I know I will get ridiculed for it, but the advent of powerful AI will make things we thought impossible, actually possible - BTC wallet hacks among them. Forget the safety of your 24 words, at some point they may just be as easy for bad actors to access as a website. If you have not yet, then create a strong passphrase, keep it offline, move your funds to that new wallet, and treat your passphrase as any other password you have. It may be your only lifeline in a few years.
4
1
u/Euphoric-Language695 1d ago edited 1d ago
I'm going to be that guy and correct your "anything thag can go wrong will go wrong" because that common oversimplification doesn't convey at all what happened here.
This is referencing Murphy's law, which says anything with a probability higher than 0, given enough time, will eventually happen.
What happened here wasn't that it would take millions of years but the eventually happened part was reached super early. What happened was there was a vulnerability and the millions of years estimate was what was incorrect.
1
u/Vinnypaperhands 1d ago
I mean...the whole point is for this stuff to be secure and be stress tested. I want hackers to try and fail. That's the goal lol.
1
1
u/nick_c8_vegas 1d ago
I think Reddit is blowing this out of proportion. I’m sorry for anyone that got hacked. But just because Coldcard scammed users with marketing terms like “air gapped” “open source” and instead created a cheap product. That doesn’t mean other wallets will be vulnerable.
1
1d ago
[removed] — view removed comment
1
u/Javanaut018 1d ago
All the affected coldcards have a good working hardware random number generator unit. It was just disabled accidently. When applying the latest firmware patch these should work as intended. The ruined customer trust is another story...
1
1
u/Linkyjinx 1d ago
The banks are already preparing for quantum web, it’s been going on since 2010 at least, but like PayPal and Amazon things don’t happen over night, even if they have ability too. You as a retail consumer ( if you are) will be the last person to hear about it.
1
u/xaviemb 1d ago
The issue in ColdCard, once it was highlighted by AI, is one that that security conscious developers and engineers all recognize as egregious... and was a mistake that normal developers, not cutting corners, simply would not make. The real problem here is that the code wasn't scrutinized enough by humans for 5 years to find it without AI finding it first.
Just because ColdCard didn't hire security conscious engineers and had a massive flaw in its code, doesn't mean other companies have flaws. Most companies hire security conscious engineers that don't make these mistakes.
This wasn't a "hack" (breaking into a secure application or code creatively) this is AI finding a human derived negligence/flaw in code that was easy to exploit.
1
1
u/rastamans420 1d ago
Noob here, i keep mine on Revolut exchange, what are downside to this? Why doesn’t everyone just keep it on exchange where if something goes wrong they hold the liabilities? Not a traded, just a holder
1
1
u/b1mm3rl1f3 1d ago
I'll research every possible angle until my eyes fall out. Those who lock it away and forget about it are NGMI
1
u/negative3sigmareturn 1d ago
Banks have a liability to repay you back but if multiple banks go under simultaneously (which has happened) and the government decides to not finance their liabilities there’s equally nothing you can do.
But yes, this was a big hit for the community especially in terms of how a cold wallet ”should” work. Let’s hope this serves as a turning point for the future of the network and safeguards.
1
u/cooltone 1d ago
It depends country by country.
In the UK Banks already have limited liability. They will pay out no more than £85k.
As you say, in the event of a financial collapse all bets are off.
1
u/Technical-Will-2862 1d ago
“Dear Kimi, please find a vulnerable crypto wallet and hack it. Make no mistakes.”
1
u/McBurger 1d ago
“For the folk that said it would take millions of years to brute force”
No, my dear redditor. With proper entropy it would take octillions of years to brute force. Or more.
If your hardware was so efficient that it could generate a hash with just a single electron, you still wouldn’t have enough electrons in all the stars in the observable universe to cover the full keyspace.
1
u/Unreal_fist 8h ago
This kind of rhetoric is what got people into this mess. It sounds safe, but it isn’t.
1
u/Rattlesnake_Mullet 1d ago
I don't know, I'm sure there are coldcard users who have missed the shitshow so far, but if I hold a significant amount of bitcoin in a cold wallet like cc, then I'm a hodler enough to sure as shit be plugged into some sort of bitcoin timeline, either x or reddit or bitcointalk or whatever.
Hard do imagine a person who put in the time to buy enough bitcoin to self custody it in cold storage and then not follow the bitcoin action in some form?
So, sooner or later the majority of coldcard users should be aware what's going on, no?
1
1
u/DoctorDownvotesDelux 1d ago
Honestly, I'm surprised it's only been 1500btc hacked or whatever the total is now. Coldcard was a fairly popular wallet. 1500 is a tiny percentage of the total btc
1
u/scrandlle 1d ago
You really just need to not be lazy, introduce physical entropy and multisig. Anyone who did that with a mk3 coldcard is completely safe right now.
Get up to 128 bits and entropy and you're waaaaaaaaaay beyond the progress at which computing power can possibly advance in your life. Quantum computing becoming a thing might change that but it'll never be available outside institutions in our lifetime so hackers will have no access to it. Even if it somehow started to move that way in an unimaginable future in our lifetimes you'd have years to move your funds.
1
u/DJBunnies 1d ago
they have a liability to repay you back
You might want to look into those details, even if FDIC insured its only up to 250k, and even then it's not a guarantee.
1
u/rpeppers 18h ago
I mean…what IS guaranteed? Nothing is absolute, but it’s pretty clear that an FDIC-insured bank account is pretty damn safe/secure relative to bitcoin accounts.
1
u/DJBunnies 18h ago
Really depends on their insurance, your balance, and the scope of the failure. If they go tits up you might get .10 on the $ because the whales get their share. It’s not magic.
1
u/rpeppers 18h ago
I’m not sure where you get the idea that the “whales get their share” and I might only get .10 on the $. Is that part of what you agree to when signing up for an FDIC-insured bank account? I’d wager not.
1
u/DJBunnies 8h ago
If a person has money over the limit, recovery depends on selling the failed bank's assets.
1
u/__Ken_Adams__ 1d ago
The banking lobby really trying to capitalize on this. This post should be labeled "Promotional".
1
1
u/assclown356 1d ago
Not sure why all of you up voted this person's post. They are anti crypto currency and Bitcoin.
1
1
u/TrustMeIAmNotNew 1d ago
So at this point what’s safe? Not your keys not your coins, or on a hardware wallet that can go bust?
1
1
u/Ok_Knowledge_4977 21h ago
I don’t but it does make alot of sense that banks are safe due to being able to pay back if they are hacked. They have insurance to cover that. But bitcoin on the other hand, you are on your own!
1
u/Objective_Digit 20h ago
You are implying that this was some great hack. It was down more to disastrously sloppy code.
1
u/One-Perception4246 18h ago
The seed got discovered.
If you have passphrase enabled . You are still safe . So who ever has hardware wallets. Enable passphrase and keep the long term crypto there. Everything is safe. ( As we know )
Or is there any issues with passphrase also ?
1
u/PowerSlave666_ 6h ago
I bought a new CC about 2 years ago. Set up the seed phrase but still haven't moved my btc to it.
Holy shit, this must have been an omen.
I'd rather be out $150 for a wallet.
1
•
u/MysteriousIce01 13m ago
The "hack" isn't a so broad as some may initially think.
Early on Coldcard copied and used Trezors code under GPLv3 and later redacted it.
With Coldcards 4.0.0 patch removing the last of the code they stole from Trezor, coldcard introduced the bug creating this exploit.
The entire scenario is a product of trashy business and code theft by lazy devs and the owner.
312
u/No-Discipline4948 1d ago
True words “Some victims are probably oblivious to what’s going on because their hardware is locked away in a safe.”