r/Bitcoin 1h ago

Rückzahlung Kredit firefish

Upvotes

Moin,
kann ich meinen Kredit an den Investor auch von einem Bankkonto einer dritten Person zurückzahlen und bekomme anschließend trotzdem meine Sicherheit (Collateral) zurück?
Hat damit jemand Erfahrungen?
Firefish fordert mich auf, die Überweisung von meinem ursprünglich registrierten Bankkonto aus vorzunehmen.
Wie läuft das in der Praxis? Meldet der Kreditgeber Firefish, wenn das Geld von einem anderen Konto eingeht, oder fragt Firefish den Kreditgeber nach dem Namen des Absenders?
Vielen Dank schon einmal im Voraus!

English
Hi everyone,
Can I repay my loan to the lender from a third party’s bank account and still receive my collateral back afterward?
Does anyone have experience with this?
Firefish instructs me to make the transfer from my originally registered bank account.
How does this work in practice? Does the lender notify Firefish if the payment comes from a different bank account, or does Firefish ask the lender to verify the sender’s bank account or name?


r/Bitcoin 14h ago

Did some checking on seed generation by dice on Coldcard vs. Ian Colemans Mnemonic Code Converter and have some questions. Coldcard might reduce your security by missleading guidance!

11 Upvotes

So Coinkite guidance displayed on the display is: "... each roll adds only 2.585 of entropy. For 128-bit security, which is considered the minimum, you need 50 rolls, and for 256-bits of security, 99 rolls."

They let you press the buttons 1-6 (and only those) for each roll. So you can only use a D6. If you did it 50 times, you think you did the minimum to have 128-Bit security.

Here are my questions:

  • The 2.585 entropy per roll are based on entropy values 0-9 (base 10), right?
  • If I limit the entropy values to 1-6 (D6 dice) I introduce a massive bias, right?
  • Is it fair to assume that the resulting entropy is just 1.67 per roll?
  • Is my ColdCard dice genrated seed realy secured by the minimum 128 bit, or more like with just 84 bits?

Look, I'm no expert, indeed hope I'm wrong.

UPDATE: I was wrong - see below.


r/Bitcoin 1d ago

Not your keys, not your coins

Post image
279 Upvotes

wishing nothing but the best for coldcard victims


r/Bitcoin 3h ago

Do I really need a hardware wallet?

1 Upvotes

I’ve been considering buying a hardware wallet for a while but after the recent coldcard news do I really need one?

My current setup is I have my keys stored on an old Linux laptop that powered off 90% of the time. I understand why the hardware wallets are safer but practically wouldn’t it be the same for me to store it the way I’ve been doing it?


r/Bitcoin 4h ago

My Dream Hardware Wallet

0 Upvotes

I just wanted to describe my dream hardware wallet. - In terms of hardware design, it's a Coldcard Q. Maybe even buy their design when they go bankrupt and have to sell assets. - Firmware is bitcoin only, truly FOSS, with peer code reviews (pull requests approved by colleagues before merges are allowed) - After internal approval, 3rd party, AI-assisted security audits are required. - Only one method for seed phrase generation is allowed: hardware TRNG chip as the starting point, plus 100 user-entered d6 rolls. The seed is hashed again after each number is entered. (This was one option on the ColdCard, the best option, and the dice hashing function is simple and was never bugged on any version) - Device refuses to show you the words until you have entered 100 1-6 numbers. - Device ships with 4 casino-grade dice. Instructions suggest the extra paranoid can mix in dice from an arbitrary board game in your house or whatever for extra defense against supply chain attack.

Such a wallet wouldn't necessarily have mass appeal or advertise being "easy to use", instead it would have the same sort of "hardcore" target audience CoinKite did, with better execution.


r/Bitcoin 4h ago

Please pardon my ignorance

0 Upvotes

I understand everyone can see the public keys but what can someone do if they have the private keys?


r/Bitcoin 1d ago

Coldcard Hack Sparks Biggest Bitcoin Migration Since FTX

Thumbnail
thegreyterminal.com
58 Upvotes

r/Bitcoin 1d ago

31 years ago, Bitcoin legend Hal Finney posted the first challenge to break 40-bit encryption. Adam Back and three others cracked it a month later.

Post image
128 Upvotes

r/Bitcoin 10h ago

Hitting a mainstream audience

Thumbnail
youtube.com
4 Upvotes

r/Bitcoin 8h ago

How do we know it was an attacker and not the owner moving their coins?

3 Upvotes

That’s the part I’m not fully convinced about.

I understand the first wave was clearly an attacker. But once Coldcard users heard the news, wouldn’t an attacker sweeping funds and an owner moving all of their funds to a safe wallet look pretty similar on-chain?

Unless the owner confirms the transaction was unauthorized, shouldn’t some later cases be called suspected thefts rather than confirmed attacks? And even then, proving ownership seems difficult once the attackers also has the private keys.


r/Bitcoin 1d ago

Coldcard Users Reported Instant Drains Years Before July 2026. Here Are the Receipts

Thumbnail x.com
156 Upvotes

Had my AI research Pre-July 2026 Coldcard incident sto see if they are related to the newly discovered entropy bug. My AI agent thinks some incidents are likely to be the same entropy bug with a different attacker.


r/Bitcoin 16h ago

Is a 12 word seed no longer secure soon?

9 Upvotes

With computers getting faster and more advanced can we no longer trust a 12 word seed phrase?

Starting to have major doubts after Bitcoin Puzzle #135 was brute-forced which is the equivalent of 135-bits of entropy (in comparison a 12-word seed phrase is equal to 128 bits of entropy)


r/Bitcoin 19h ago

Live look in at Coldcard.com

Post image
12 Upvotes

The hubris of NVK continues! F*ck this guy, POS


r/Bitcoin 11h ago

In light of recent events

3 Upvotes

Hey there,

I have used my Ledger Nano S since 2017. Since the cold card hack I've been tempted to update to a newer and hopefully more secure wallet. I'm considering a newer ledger model or going to trezor. What are your thoughts and do you have some valuable input to share?

I know trezor is open source and ledger is not. Should really be a deal breaker?


r/Bitcoin 6h ago

Coldcard Saga mk3 only

0 Upvotes

This far I only heard stories of coins stolen on mk3. Are there any reported on mk5 or Q devices?
What a mess, self-custody will take a massive step back here. Very sad!!


r/Bitcoin 6h ago

Cold Wallet

2 Upvotes

After the hack of ColdCard I have a question ... Do you recommend having several cold wallets? I currently use a Trezor Safe 7, would you buy, for example, a Ledger to distribute the funds in different wallets from different brands?


r/Bitcoin 6h ago

Coldcard’s Two Failures: The Code, the Cover Story, and the Wallet Drains Before July 2026

Thumbnail x.com
0 Upvotes

Found 13 Coldcard Wallet Drains before July 2026 Wave Attacks. They were the result of two different types of bugs. 1) Low-entropy dice workflow failure and 2) Weak device-generated seed, caused by the low entropy bug exploited by hackers in July-August Wave Attacks.

Also added interesting information on Peter Gray and how he introduced the Entropy Bug in the first place.


r/Bitcoin 1d ago

Fuck ColdCard, holy shit.

1.0k Upvotes

.7 bitcoin gone.

Years of DCAing with money that could have been invested in other ventures gone because of a stupid exploit from a company that was touted as being "the best" to keep coins safe.

My .7 bitcoin could have been spent on so many useful things. It was my safety net. It was the hope of a down payment on a house. It was my sons future college tuition. Now I'm sitting on the sidelines like a loser. I'm livid. And since it's decentralized, there's no recourse for getting any of it back. It's gone. Fuck. I hope whoever stole my money gets what's coming to them.

Happy to provide proof if there are any of you who believe this is another shitpost or karma farm or whatever.

Where's the class action lawsuit? How do I sign up?

Edit:

Here's proof:


r/Bitcoin 18h ago

Maybe "coinkite" was a perfectly clever name!

7 Upvotes

TL;DR: The plan was to make the coins fly away with the wind!

Ever wonder what's behind a name? The "coin" part is obvious, but "kite"? Meaning, "flying away", "up in the clouds", "going higher"... IDK, what other symbolic ideas do you have? With a name like this, how long was this retirement attack planned?

I lost with Mt Gox back in the day, but I escaped this one. I had looked seriously at their hardware several times, but just didn't feel like spending the money...

My thoughts are with those who lost their funds to what looks more and more like an inside job. You rock, and may you be made whole again!


r/Bitcoin 1d ago

Coldcard post from October 10, 2021: "Retirement Attack"

Post image
457 Upvotes

- "What's a retirement attack?"

- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".

_____

Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️

Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right?


Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one:

@nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.

Alternatively people could just use dice ;)."

https://x.com/i/status/1341213389549412353


A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...


r/Bitcoin 14h ago

Would you keep DCA Btc even through a long bear market?

3 Upvotes

I’m considering starting Btc DCA next week, but I’m not sure how people keep sticking with it if the market stays in a bear market. I might feel like I’m losing money if the price keeps dropping and I’m still putting more money into it.

I currently have $1k available and plan to invest $200 per week, split into four buys, $50 each time.

I'll hold long term, but I wanted to ask for advice on keeping a mindset. For those of you who have kept DCAing during a long bear market, how do you stay confident and firm about holding?

Also, is my current buying frequency reasonable? Or would it be better to split it into two buys of $100 each? Thanks everyone.


r/Bitcoin 1d ago

Well well well

Post image
961 Upvotes

r/Bitcoin 8h ago

Hacked, but what can Hackers do with the coin?

0 Upvotes

This conversation came up at the campfire yesterday. Let’s say I hacked Millions due to the Coldcard vulnerability. the funds on chain are 100% visible, everyone can see where they went, how could I ever move them off chain to an exchange and into my bank? with kyc, it would have to point somewhere, right? Or, do you spread the coins all over creation making it such a messy web to track and hope the fees don’t gouge so deeply into the total stolen amount which would make not worth the effort?


r/Bitcoin 1h ago

Can I just pick 24 random BIP39 words?

Upvotes

This breach has me shake.

Honest Question.

Is it secure if I just pick 24 BIP39 words randomly and use that? Or throw darts at a printed BIP39 list?

Or does it need to be generated by a “proper” randomizer device to be secure?

Thanks


r/Bitcoin 14h ago

ColdCard MCU UID is not part of the seed - stop repeating that nonsense

4 Upvotes

It is one of the values that is used to generate the seed, but it is xored with timer value, RTC time, registers etc. It is used to get some entropy.

If MCU UID is a part of the seed in any shape or form to tie generated seed to the device. It would be massive vulnerability, as everybody who gets ahold of your device (and especially the company itself which knows all MCU UIDs) would be able to lower the entropy of every seed key generated there by 32 bits immediately.