Reddit Posts
That $75 million cold wallet hack just proved spot vs derivatives risk isn't what we thought
Anyone else scaling back into alts now that BTC dominance seems to be cooling a bit?
Does Fidelity FBTC use MultiSig for it's BTC Cold Storage? I know IBIT does indirectly because their custodian CoinBase uses MultiSig
Lost $36k in Crypto Scam on Fake Ledger Site
I’m having a hard time grasping the risk involved with BTC and self custody
Inside Bitcoin's 165 Million UTXOs: Five Surprising Results
Rare physical Bitcoin with unredeemed crypto sells for $91,500 at auction
Announcing USPS.cash, USPS.music and U.S. Gamer: Paired Digital-Wallet and Competitive-Play Projects
Your keys, not your crypto. A 330K lesson for all.
How to check if your Coldcard seed came from the affected firmware
A forensic question about the Coldcard attacker: how could someone actually cash out hundreds of BTC?
Cold storage wasn’t the problem. The seed was
Strategy sold BTC to pay dividends and buy back stock
Michael Saylor's Strategy sells another 1,638 BTC for $105 million, reducing total holdings to 842,138 BTC
GitHub is worth $20B+. Its agent-native replacement is a $2.4M microcap on Base with a LIVE network. The agent economy is being built on GitLawb, and GitHub has no part in it.
Bitcoin users are turning a the COLDCARD hacker's address into a public message board
October bottom feel plausible to anyone else? How are you playing it?
YSK the most secure wallet is the Bitcoin Core Wallet especially air gapped with Tails OS
How does the BTC devs/community plan to prevent miners from leaving when the block reward goes down?
BTC is testing the 200-week moving average — historically important, but is this cycle different?
What the Coldcard disaster proves about Quantum Computing and the fatal flaw of Bitcoin’s decentralisation
Doesn't it seem like our BIP-39 seed phrases generated by Trezor or Ledger could be guessed?
Is the recent hack a psyop for people to move their BTC to institutional custodians?
The case for spreading out BTC across multiple Instruments
Is anyone considering selling their own BTC for a BTC spot ETF?
I barely avoided getting all my BTC robbed with Coldcard - I don't know if I should consider myself lucky or not
If BlackRock or Fidelity can’t keep your Bitcoin safe, then so be it.
On trusting third parties: Bitcoin core vs hardware wallets vs other software wallets.
A Coldcard firmware flaw let hackers drain $70 million in Bitcoin in 41 minutes, with losses now topping $88 million
How could the Coldcard vulnerability have been disclosed responsibly?
Best non-KYC / no-account crypto swap for BTC, ETH, XMR or USDT in 2026?
Bitcoin Quantum Threat: The Race To Quantum-Proof Crypto
Did all off this years ago to get smoked 😭 f cold card. 11 BTC gone forever…
For the people who think having your BTC on exchanges are better..
With the CC issues, anyone able to offer explanation on how the large exchanges like CoinBase or River hold their BTC?
My 2 sats on the ColdCard failure, and a weakness it reveals about us, the BTC community
I lost my one Bitcoin in the Coldcard exploit.
is my cold card balance safe if its single sig with strong passphrase?
After 10 years,its time to put my BTC into ETF and hopefully sell soon. I dont' believe in BTC anymore
The Coldcard case fundamentally challenges the future of Bitcoin
Best way to Sell 4 BTC from cold storage and buy FBTC on WealthSimple (Canada)
Was the Coldcard exploit staged to kill self-custody?
List of all points in BTC transactions/operations relying on software or trust?
My condolences to ColdCard victims - spurs a paper wallet question.
I am so glad I moved all my BTC to exchanges years ago, after a nearly a decade of stress with cold storage.
I am so glad I moved all my BTC to exchanges years ago, after a nearly a decade of stress with cold storage.
PSA: the Coldcard exploit is likely tax deductible
Victim of the Coldcard. Years of DCA Bitcoin gone overnight
Is holding BTC in cold wallet like trezor or ledger still okay?
Do you guys see now why maybe it’s never been such a bad idea to hold your BTC thru Robinhood after all?
A third ColdCard hack has been reported. Another 207 BTC stolen. 1,367 BTC total, and climbing.
Mentions
The question is irrelevant. If people want to use BTC, they will. I am ok either way.
You’re just an idiot if you’re going to use that wallet. After so many people lost their life savings, you’re still going to use Coldcard? No way, never again. The only way I would ever use this crap is if I saw them send all the BTC they lost back to their customers — which will never happen.
I'd probably keep it sealed. The collectible value could be worth more than redeeming the BTC.
Yes, it even has a feature to recover your BTC if you forget the key
It means people eating up the BTC of mstr
Indeed. Even the first years mine pools with mined BTC disappeared with the account holding something that today is more valuable
why not move 6 BTC to 6 different wallets? 1 BTC per wallet. I don't have all my money on the same bank account. and with BTC where you are 50% sure one day someone steals it from you, better split. No need if you have another 60 BTC on other wallets.
Maybe storing money in ‘centralised’ banks with 15k+ employees and actual security practices makes more sense than storing your money on some device created by coders that think they’re literal wizards. Who would’ve thought? As an engineer, I checked out of BTC being legit after checking out some of the code repos lmao. It is, hands down, some of the worst code I have ever read.
Generally speaking, people with large holdings like to only keep the BTC they are going to sell soon on exchange.
I don’t think CC matters for price movement. BTC is already an institutional asset. People with money don’t even think about thinking about self custody. It’s not a thesis killer for them. It might be a little for our community, but I still think it’s not “dead”…it just strengthens from now on in my opinion.
At the time it was a joke. 50 BTC on a gold coin, the gold was worth so much more than the BTC. Hilarious.
Bitcoin changed the way I think about diversification in one specific way: asset count and diversification are not the same. Five coins that all move with BTC can still be one risk factor, while BTC plus broad equities and cash may be fewer holdings but more genuinely diversified. The practical checks are concentration, correlation during drawdowns, and whether one position now dictates the whole portfolio.
That is allocation drift. Before deciding to sell or hold, define the maximum percentage you can live with and model what happens if BTC falls 50% or 75% while your other assets are flat—or fall too. Then compare rebalancing through new contributions, fixed percentage bands, or trimming after considering taxes. The decision should come from a risk budget, not the current market narrative.
Saylor's been trimming a bit lately - probably smart to take some profits at these levels rather than just hodling everything. Still got over 800k BTC though so he's clearly not panicking or anything.
You’re trying to convince others or yourself? In terms of security there’s no comparison between crypto and BTC.
The result of events like this is that people realize the problem isn’t Bitcoin, it’s the products surrounding Bitcoin. If the hackers had only stolen Ethereum, would that mean the death of ETH? No. It means BTC is scarce, valuable, and requires defense. Thus the price reflects that and if anything it will go up.
eh, bear markets have been getting less devastating over time when it comes to BTC. 50-55% feels right for this one.
Dumb take, it was a faulty product that was not secure. Nothing to do with Crypto or BTC
At each stage of the BTC market, different exchanges and wallets become favored and are not supposed to be like the trash from previous stages, but it takes time to know if that's true or if the problems just haven't been exposed yet.
I believe the total tally of all BTC hacked as of now is 2,000? So if this is real 650BTC total is like 35% of it? Is that really true?
Mstr could get hacked though. They never disclosed how they store their BTC.
I’ve been anti-BTC from the get go. But I would never wish this on anyone and am sorry this happened to you.
my take is something else: I dont believe anybody now! Buying a Trezor and believe them and their RNG? No way… I trust them as little as I trust Coinkite. I am for the first time glad I have been so paranoid, like I have always been paranoid and bothering my family and friends with my weirdo attitude - so this time it worked out and for the sake of BTC I will stick to it. Does rolling dice suck? yes….a little…..but trusting human beings and being recked for that trust sucks so much more. I dont believe in companies, I dont believe what anybody tells me. I try to verify as much as I can, gather knowledge as much as I can. I dontstick to my Q because of I trust Coinkite, i dont trust them. But i paid for that stupid device and now the marketing guys from other companies want again money from me? No way. I wait until CK is done and there will be no updates. Or I built myself a signing device and not giving anybody my money any more….
> I will know my BTC is secure. But will its value be secure? If everyone is too afraid to hold Bitcoin themselves, then what value does it even hold? It's not decentralized money anymore.
> I will know my BTC is secure. But will it's value be secure? If everyone is too afraid to hold Bitcoin themselves, then what value does it even hold? It's not decentralized money anymore.
I've been echoing this since the ETFs launched: Self-custody is not wise for the majority of holders anymore than self-banking is. If you want to store your cash under the mattress, fine, but the vast majority do not have the resources to properly manage a physical cash pile. The only cash you should keep at your house is the cash your willing to lose. Personally, I keep about $2000 cash in a fireproof lockbox. I would never keep anything like $250k in a lockbox - nor should anyone keep $250k worth of BTC in a self-custodial wallet. Banks/ETFs have much more secure systems than I could develop on my own in the name of "self-custody". The right to self-custody is essential to bitcoin, but why anyone would actually exercise that right with a substantial amount is beyond me
Other than actual fear of societal collapse and then believing BTC would be the chosen post apocalyptic currency there is no reason to self custody!
The infrastructure isn't even cheaper than existing systems. BTC costs an insane amount of money and energy to run and the only reason people are paying that cost is that they're making tons of money off of the people using it All that crypto accomplished is creating a new way to scam and steal from people
Fidelity stores actual BTC. Institutional safety is the way
Don't forget about when the feds seized exchanges, like Coin.mx, BTC-e, Bitzlato, Cryptex, PM2BTC, and a number of smaller ones.
LifeLock is a scam, and this is different anyway. A BTC address should not be privileged information. It’s what you hand out to conduct transactions with others. If sharing it leads to a breach of that wallet, that’s worth knowing.
you gotta understand for mass adoption, this is not going to fly on any level. you have to be passionate about the tech to take it this far, the VAST majority of people will never buy BTC if they get hit with all of this.
Yea I wish he lost more than his measly .7 BTC too. Fucking moron
Oh and hey bud. Who in their right mind would not take insurance on BTC with coinbase under 4 coins. You sir are a retard. AND you sir also deserve to LOSE IT ALL Fuck out of my face. T R A D E R
I’m stacking for my kid too, this just broke my heart. BTC cannot scale all get wider adoption if every individual is expected to be a power user. A lot of our assumptions have been shattered anyone saying you should have done x, hold on to that thought…. You don’t know the tech that will exists tomorrow and no vulnerabilities we don’t know off yet.
So how does this third party know he is receiving stolen BTC? Just as your corner store has no way of knowing whether you are using stolen cash to buy a pack of cigarettes from them.
You got to 1 BTC. That took years of discipline and losing it this way isn’t a reflection on you. Drop the embarrassment, the vendor failed here. Anyone else reading, go check now rather than tonight.
The arithmetic error isn’t in the dice rolls themselves—it’s in trying to manually compute the **public key** from the private key. If you accidentally record one die roll incorrectly, you don’t get a “bad” key. You just get a **different random key**. As long as you record that same sequence consistently in your backup, it’s perfectly valid. The risky part is everything *after* the private key. Computing the public key requires elliptic curve scalar multiplication over 256-bit integers. A single mistake in that math gives you the wrong public key and therefore the wrong Bitcoin address. You could end up sending BTC to an address that **doesn’t actually correspond to the private key you wrote down**. That’s why I recommend generating the entropy yourself with dice, then letting a well-audited offline tool perform the deterministic math. You’re still choosing the secret—the software isn’t generating your key, it’s just calculating Q = dG. If you’re especially paranoid, verify the output with a second independent offline implementation. If both produce the same public key and address from your dice-generated private key, you have very high confidence the math is correct.
There's going to be nothing left very shortly. I would take a deep discount on their BTC ticker display tho.
My biggest gripe, is that some individuals are acting disgusted with coinkite (rightfully), and basically saying they fucked up the ONE thing they couldn’t fuck up and that’s proper entropy. Which yes, agreed. But then when it comes to themselves I haven’t even seen an apology after shilling for the company for years. They literally have an EDUCATIONAL channel teaching people the do’s and the do nots of wallets and how to self custody. This is some people’s life savings. If you have an educational channel for such important products about security and sovereignty it’s pretty important you don’t fuck up talking about the one thing that keeps them safe. It’s obviously not their fault and they aren’t to blame. But publicly apologizing to those you let down goes a long way. People put trust in your education and you sure as shjt sold people on the idea. The bare minimum needs to be an apology for those who lost there BTC.
Never go all in on one thing. I have BTC and continue to hold it but my investment portfolio also has precious metals, equity, and real estate.
The entire world financial system would be in trouble long before BTC
10000x was an analogy for "a lot more". I will change my wording to "don't we need a crap ton more holders?" The underlying theme remains unchanged, which was this incident could cause delays in more individuals buying in to BTC.
Damn. That was before my involvement in BTC. Well, maybe I'm wrong.
For someone who lost BTC from incident, this is something that they could read. Well said and wishing you and your dad some strength too! This might sound to cliche or repetitive, but you'll definitely get back stronger! Cheers!
Step 9: watch over your shoulder your entire life, because some of the stolen wallets had significant amounts of BTC and may belong to people you don’t want to steal from…
Percentage wise, I think about 2% to 4% of people own BTC in some form or fashion. I don't count that as a "large" percentage of people.
Wasn't BTC at like $500 when that happened? Sure, the % of the network was 10%. But the $ magnitude was likely much lower. I'm not a mathematician, but the dollar magnitude was likely less. If it wasn't, I stand corrected.
It was a scam from the beginning. Scammers have many ways to salt wallets with fake crypto in order to deceive you. And remember, just because something is received in your wallet, you need to be very careful what you interact with. A drainer contract will take everything in your wallet. If you’re not using a hot wallet/cold wallet strategy, and u do 1-1 private tx, you’re gonna get fucked, eventually. I don’t now how they spoofed a BTC contract, but these are sophisticated scammers. Good job on not giving into the pressure campaign! That’s their number one social weapon of choice. Unless you can successfully move a crypto to a cold wallet with a documented full transaction path from whatever chain you’re on, it’s a scam and you haven’t been paid. Learn how to use the blockchain navigators to track any tx.
I feel so badly for you and others that lost their stacked. Truly awful As a Trezor user, what can I learn from this to be better protected (other than selling all my BTC). I have one of their newer models and it’s the “BTC only one.” I’ve heard to split stacks among different wallets but to me that advice is doubling the chance you lose 50% vs halving the chance to lose 100%. What else can I reasonably do as a cold wallet user to help protect against a hack like this? Thanks and again sorry to coldcard users affected. You get back in your feet soon enough
I get the analogy. But I would argue that driving a car is pretty much a necessity in this day and age. People need to drive cars to get to and from work, purchase groceries, etc.. Investing in BTC is a choice, not a necessity. Thanks for the perspective!
Never gonna happen. As a normal investor (ETF’s) I see crypto as pure gambling. It’s not being used for its intended purpose, i.e peer to peer money transfers. The only things it’s being used for is ‘investments’ and scammers. The terminology alone is going to put off the general public, i’ve got a tech background and just shake my head at the gobbledegook that crypto users have to know and understand. Even now i’ve been reading comments from supposed crypto experts who think their BTC was physically in their Cold wallet. Add in no regulation, sketchy crypto companies, no customer service and no fund insurance, mass adoption is never gonna happen. Crypto is the wild west of gambling. The cool kid on the block is no more.
Completely agree. But an astute investor will likely also think, "if it happened with ColdCard, what's to prevent it from happening with Ledger, Trezor, etc...?" That's what I'm trying to articulate here. BTC is trustless. The provider one chooses to secure one's BTC is not trustless.
Its a blip in the radar. No one gives a shit except the people who had their BTC stolen.
FWIW, I see the two as completely different. FTX and other exchanges were predominantly due to fraud. The Coldcard instance was due to incompetence. Anyway, general question was will this set us back? To be clear, I'm long-term bullish on BTC. Just sharing my inner thought.
Um, yes. Isn't that the core value prop? People buy and hold as a store of value. Isn't that one of the pillars of BTC?
Until this day Bitcoin has never failed. It has all been user error or third party error. This recent issue probably isn’t even going to make the main stream media. We have seen so much the past 5 years. Exchanges collapsing, BTC companies going bankrupt, people getting scammed/hacked out of their crypto, and recently a major seed generation bug for an open source hardware wallet. It recovers every time. I’m sorry but your logic is way off.
Yes, I do understand what happened. I fully understand it has nothing to do with BTC or its underlying infrastructure itself. But, people looking for a "more secure" way to store their holdings are going to pause. They will pause because they don't understand what happened. People these days have the attention span of a mosquito. All it takes is one or two of these third-party failures to set things back. That was my point. Please don't make assumptions about what I do or do not know or did or did not research. I'm not looking for a personal argument.
I don't live in a bubble. I'm not a BTC maxi. My goal is a certain percentage of my overall portfolio. I just pay attention to what is going on. Regarding the LARPing, I believe Coinkite was held in pretty high regard until this happened, no? What's going to happen if there is a similar issue with another HW wallet vendor? The media are fear mongers. They only report on sensational events with little factual basis behind their stories.
I don't trust any company that says "your funds are safe". Burned twice stacking BTC. IBIT for me.
Totally understand it isn't a reflection on BTC security. It is a reflection on companies who supposedly provide a more secure way to store your crypto than keeping them on exchanges.
The optics are terrible though. BTC is supposedly "trustless". But there is some inherent level of trust in the HW wallet manufacturers and exchanges. I guarantee you anyone thinking of dipping their toe into BTC will pause now. I use Ledger (sure, tell me I'm dumb) but after I heard about this exploit, I decided to stay on CB as I start to DCA again until the dust settles. Sure, CB customer service is supposedly terrible (I've not experienced any issues), but I don't think they've had a major security incident resulting in stolen coins. If they have, I'm not aware of it.
If anything, I am somewhat surprised that BTC price moved so little, these past few days.
Things generally become more regulated over time because events force regulations into place, not because people are clamoring for them. I imagine plenty of BTC holders would be fine with more regulation if it means more safety.
So sorry you were robbed. While I never personally got into BTC a co-worker of mine just lost their life savings and they invested ALL extra money plus some into BTC. I am doing research to try and help but it sounds like there is no answer and it’s gone. He felt so strongly about Coldcard. I know it’s hard to find those responsible if not impossible but I truly hope someone pays big time for ruining peoples lives and stealing their hard earned money.
They are not competent to produce a hardware wallet. Lose all my BTC once , shame on you. Lose all my BTC twice, shame on me.
Exchanges have blacklisted hacker wallets before. Finding an exchange that is willing and able to deal with $150M from stolen funds might difficult. Everyone will know the exchange bought the stolen BTC so they could get into trouble with regulators.
Create a new wallet and roll dice for each word of your BIP39 seed phrase and then move your BTC to the new wallet
Really only the 2013 silver variants have a meaningful premium these days. The brass ones don't go for much more than face value and anything 5+BTC is hard to move due to the large underlying value.
Buy both. BITO & BTCI pay dividends (not much when BTC price is falling but hey it adds up).
Sad part is Ledger is one of the most n00b wallets you can use. Can’t even air gap it. I would still use Coldcard to store my BTC over Ledger, even after this issue.
Yeah I sold mine at auction a while back and it was… basically slightly over BTC value at the time (granted it was not mint grade lol)
They could potentially send the BTC to a trusted third party who can distribute to coldcard holders
Looks like you are a migrant to the US from India and have a career in tech. how many friends do you have back home who are unable to earn even $500? You are lucky, have already won in life. Consider the positive aspect. if you try again, you can make that 5 BTC again. Good luck!
It’s funny because in another thread a few months ago I mentioned to never load more than 0.15-0.25 BTC on a single wallet, and use different brands for each. I was downvoted to hell for saying that. Now after this ColdCard fiasco, I would say I was correct
First look into the mathematical definition of entropy. Entropy is basically a measure of a probability distribution’s uncertainty. For a random variable Z with possible values z, its entropy is \- sum\_z \[Pr(z) log(Pr(z))\] This quantity is the expected uncertainty of the events z when sampling from Z. That is, the uncertainty of event z is -log(Pr(z)) = log(1/Pr(z)). This quantity measures the amount of information we gain from the knowledge that z occurred. Notice how if z is guaranteed to occur, we get log1=0 (no information gained) and for highly unlikely events the resulting information gets smaller and smaller. In the BTC world, the random variable Z generates a seed phrase, and it must have high entropy to not be reverse engineered.
Can anyone explain why you wouldn't store your BTC elsewhere on shit that isn't constantly being hacked?
No, you would gain some time to move your funds to another wallet. BTC Sessions already published on X about they hacking one of these seeds with passphrase yesterday.
Done, as in got all the BTC they need now?
That would make sense if Saylor was buying back ordinary shares with the proceeds of the BTC sales, which he isn't afaik
My thoughts? Never store more than a 0.25 or 1/4 of BTC by each cold wallet. Once one is "filled" store it away "for ever" . This is the only thing that helps with such situations.. and to you to decide what is your own "filled" amount is .
We the retail's.. have 240 Millions in recent drops buying.. fighting against 780millions mids sized whales.. and 840 millions $ for heavy institutions and nations size entities that actually either short or are selling spot BTC.. the book's tell the story. No wonder the price ain't going up yet.
I imagine during low volume you can use 10-15 BTC to move the float.
Gutting to hear. So sorry for your loss and all affected. Indeed, these are dark days for BTC. Spend time with your dad and daughter. That’s time you will never get back. Stay strong. You will survive. Sending positive vibes and thoughts!
Start your own exchange. Name it BTC-E 2.0.
Sounds complicated, I’ll keep seducing it, I think. Maybe I’ll even get some really great virtual children out of the deal who can inherit my BTC fortune!
I get that. I think that's also why people have started exploring different ways of using native BTC instead of only thinking about spending it.. like native staking....
They also produced disclaimers and warning material over use of their products and never claimed "100% secure." So sure, you can try to sue them for negligence, fight for years and then try to claim in civil court the lost funds. Ask everyone that held at MtGox how well that payout is going. How do you expect them to recover the funds? Full chain custody isnt for everyone and this is just another example to responsible BTC holders as why we dont trust 3rd party companies with our keys. Period.
Your cousin got your money back from a phantom scam and you immediately went all in on BTC, that's the kind of chaotic energy I respect. Binance Earn is basically just lending your coins out for interest, you lock them up for a set period and they pay you a percentage. Since you're not touching it anyway, flexible savings gives you less but lets you pull out anytime, locked staking pays more but you can't touch it for a month or three.
I went on their website today just to see what was up. They are still claiming it is super duper fucking secure and cutting edge. But at the top is a link about the issues. And they say to update blah, blah, blah... As if anyone is trusting them with their BTC again. GTFOH 😂
How could you ever verify original ownership? I could go buy a cold card, use the same method to find affected wallets and restore it to the cold card and write down my recovery phrase then beg a whitehat for my 3 BTC.
except every BTC owner will get waxed if Anthropic is successful, not just the individual making the challenge
To be fair, while it's a lot to you or me, that's 0.19% of their holdings, it's not a lot of BTC... to them.
If they got in early enough that could be like 30-50 dollars they spent and just held... Mind you if I got hacked back in my youth and lost my wallet under much less silly circumstances, it is pretty impressive that *this guy* could have held 6 BTC this long lol.
The maker doesn't have that ability. You're making stuff up. On Thorchain you're trusting the majority of node operators act honestly. On BasicSwap or Eigenwallet you don't have to trust anyone besides the developer if you can't read code and are too poor for Claude. https://markets.basicswapdex.com It's not cex liquidity but on XMR/BTC it's 2% spread not 5%.
A tradeoff? They found a real wallet, found a used address, but spent. Is it really a tradeoff to continue checking until they find an actually unused address? Instead of abandoning the search midway through that wallet and continuing to check random seeds, where they find a wallet 1 in a million? They will have a higher chance of finding some BTC in the next millisecond when they go through that wallet's addresses until they find an actually unused one, than finding another used wallet seed in the next minutes/hours.