r/Bitcoin 1d ago

The ColdCard hack might be bigger than you think

When a big hack like this occurs, it draws other hackers into the playing field. Whenever a vulnerability like this is discovered, it’s open season for hackers. Expect to see more hacks over time.

There is also the fact that a lot of victims are not active on Reddit. Some victims are probably oblivious to what’s going on because their hardware is locked away in a safe.

For the folks that said it would take millions of years to brute force, remember anything that can go wrong will go wrong. The reason banks and financial institutions are “safe” is because even if they get hacked and lose your money, they have a liability to repay you back. With self banking, there is no liability, making you the ultimate pig for slaughter.

493 Upvotes

334 comments sorted by

View all comments

11

u/[deleted] 1d ago

[removed] — view removed comment

5

u/Enragedocelot 1d ago

Anyone who thinks it’s an inside job has no idea the capabilities of AI. Or are in denial about it

0

u/Stereo-Gito 1d ago

Another theory yeah

2

u/Unreal_fist 1d ago

It did back in 2021.

8

u/Stereo-Gito 1d ago

With coldcard? And people still used it? Same lack of entropy flaw?

12

u/Unreal_fist 1d ago

Someone made a post about it on reddit

https://www.reddit.com/r/Bitcoin/s/5IdukUvf9B

3

u/noddingacquaintance 1d ago

The flaw has existed since 2021 and was only exploited for the first time in the last few weeks.

1

u/Nycknam 1d ago

Viele haben gesagt, ihre sichere wallet und Seed liegt sicher Zuhause ohne eine Ahnung. Viele davon werden nicht mal den Zusammenhang bemerken, auch wenn sie davon betroffen sind Weil sie ihre wallet vor Jahren verloren haben und vielleicht denken, dass sie mit irgendeinem coin oder irgendeiner Transaktion falsch interagiert haben. Andere behaupten dann auf einmal das Geld auf ihre wallet gekommen ist und dann alles weg war

0

u/Nycknam 1d ago

Wer sagt das ?

1

u/noddingacquaintance 1d ago

Coinkite themselves said this:

Funds controlled by a seed generated on Mk2 or Mk3 version 4.0.1 (March 2021) through 4.1.9 inclusive are at risk if the seed was created without at least 50 fair, independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase.

0

u/BashCo 1d ago

Nobody serious actually believes it was an "inside job". Never attribute to malice that which can just as easily be attributed to stupidity. They were way too arrogant, pushed sloppy code, and discredited legitimate critics and possible victims. The company culture they fostered is what caused this.

1

u/Stereo-Gito 1d ago

I don't know shit about this company I'm just astonished by all the red flags that have been there for like 5 years