Reddit Posts
I was one of the Coldcard wallets. I don't know what to do.
with the Coldcard drain still fresh (Galaxy saying $130M+ possible), how are you actually splitting up storage now? one hardware wallet feels like a single point of failure
Imagine buying a hardware wallet to protect your BTC then boom, its gone lol
I present the Ancient BTC Rain Song in Hope it will Bring us New Rains!
BITCOIN safe but accessible storage - Thoughts?
Coldcard Thief Starts Mixing 64 BTC
What's the cheapest way you've found to buy crypto without getting destroyed by fees?
I've never trusted device-generated entropy. Here's my full offline dice + BIP39 workflow, step by step
Title: The Coldcard Entropy Disaster Is a Wake-Up Call — But ERA Wallet's 5-Source Model Isn't a Magic Bullet Either
trusting hardware wallets: even dices are not enough
Retirement Attack: Many more details pointing straight to the CEO and CTO stealing the coins. This is more than enough evidence of probable cause to charge them and start a prosecution.
What's the next big crypto narrative after memecoins?
Newbie here willing to donate to an open source dev. The main goal is to have the lowest transaction fee possible and the highest privacy possible
Never thought I’d doubt BTC - starting to doubt, diversify
The Coldcard Hack: What Happened, What Actions to Take as a Coldcard Holder, and How U.S. Taxpayers May Claim Their Losses
I've never trusted device-generated entropy. Here's my full offline dice + BIP39 workflow, step by step
The Coldcard hacker is still progressing stolen BTC keeps increasing
The Coldcard hacker is still progressing stolen BTC keeps increasing
Coldcard Users Reported Instant Drains Years Before July 2026. Here Are the Receipts.
I've never trusted device-generated entropy. Here's my full offline dice + BIP39 workflow, step by step
Found the ultimate Easter Egg in BTC puzzles – music that only plays in specific satoshi ranges
$100M+ reportedly lost in the alleged Coldcard hack.
That $75 million cold wallet hack just proved spot vs derivatives risk isn't what we thought
Anyone else scaling back into alts now that BTC dominance seems to be cooling a bit?
Does Fidelity FBTC use MultiSig for it's BTC Cold Storage? I know IBIT does indirectly because their custodian CoinBase uses MultiSig
Lost $36k in Crypto Scam on Fake Ledger Site
I’m having a hard time grasping the risk involved with BTC and self custody
Inside Bitcoin's 165 Million UTXOs: Five Surprising Results
Rare physical Bitcoin with unredeemed crypto sells for $91,500 at auction
Announcing USPS.cash, USPS.music and U.S. Gamer: Paired Digital-Wallet and Competitive-Play Projects
Your keys, not your crypto. A 330K lesson for all.
How to check if your Coldcard seed came from the affected firmware
A forensic question about the Coldcard attacker: how could someone actually cash out hundreds of BTC?
Cold storage wasn’t the problem. The seed was
Strategy sold BTC to pay dividends and buy back stock
Michael Saylor's Strategy sells another 1,638 BTC for $105 million, reducing total holdings to 842,138 BTC
GitHub is worth $20B+. Its agent-native replacement is a $2.4M microcap on Base with a LIVE network. The agent economy is being built on GitLawb, and GitHub has no part in it.
Bitcoin users are turning a the COLDCARD hacker's address into a public message board
October bottom feel plausible to anyone else? How are you playing it?
YSK the most secure wallet is the Bitcoin Core Wallet especially air gapped with Tails OS
How does the BTC devs/community plan to prevent miners from leaving when the block reward goes down?
BTC is testing the 200-week moving average — historically important, but is this cycle different?
What the Coldcard disaster proves about Quantum Computing and the fatal flaw of Bitcoin’s decentralisation
Doesn't it seem like our BIP-39 seed phrases generated by Trezor or Ledger could be guessed?
Is the recent hack a psyop for people to move their BTC to institutional custodians?
The case for spreading out BTC across multiple Instruments
Is anyone considering selling their own BTC for a BTC spot ETF?
I barely avoided getting all my BTC robbed with Coldcard - I don't know if I should consider myself lucky or not
If BlackRock or Fidelity can’t keep your Bitcoin safe, then so be it.
On trusting third parties: Bitcoin core vs hardware wallets vs other software wallets.
A Coldcard firmware flaw let hackers drain $70 million in Bitcoin in 41 minutes, with losses now topping $88 million
How could the Coldcard vulnerability have been disclosed responsibly?
Best non-KYC / no-account crypto swap for BTC, ETH, XMR or USDT in 2026?
Bitcoin Quantum Threat: The Race To Quantum-Proof Crypto
Did all off this years ago to get smoked 😭 f cold card. 11 BTC gone forever…
For the people who think having your BTC on exchanges are better..
With the CC issues, anyone able to offer explanation on how the large exchanges like CoinBase or River hold their BTC?
My 2 sats on the ColdCard failure, and a weakness it reveals about us, the BTC community
Mentions
I think there are funds that trade BTC futures. I got burnt by buying farming futures ETF (soy, coffee, etc) because the tax structure was a nightmare. Tax time was a pooh show.
"what HW did you store you BTC in? hope it wasn't a cold Cardmk3"
Buttcoiners strike again. Do these folks not realize BTC is over $60k?
Public key allows people to send BTC to that wallet, like giving your bank account number to someone so they can deposit in your account. Private key is meant to be had only by the owner. That would be like giving someone the combination to your safe. Now they can get whatever is in it.
Right, but that holds true for all ETFs. A MF would avoid that but I’m not aware of any for BTC?
I forgot one last important point regarding BTC ETF's. If you hold it in a taxable account, you have to report the sale of BTC within the ETF. These BTC ETF's sell a little of their BTC to fund the management of the fund. This is technically a taxable event that you have to report. In practice, most people own so little that the IRS probably won't care. It's simply something to be considered.
Bro thinks $3M home is not extravagant ahahaaaa, yeah cope even harder. IR are going up and BTC is therefore overvalued (or rather nothing because it has no real value) because speculators tend to stay away when IR are going up, hmmmm why would that be?! As long as you can buy a home with 1BTC = BTC price is insane, since that is not possible in US and Europe rn, it is not that insane, but saying it's insanely undervalued when it still, after almost 20 years of existence, does not have a single use case and there are close to 0 real transaction, that is bonkers
> The question then is how the hacker would use the mixed BTC in the real world, without people asking too many questions. Pay and artist to create a bunch of apes in hats. Upload them to an NFT marketplace. Use multiple wallets to bid millions of dollars for some digital monkey art. Duh.
It is entirely possible for them to exchange these BTC for money, don't you worry.
Agreed, and to those who would disagree, watch your value collapse if Coinbase were to lose its holdings. BTC would crash 90%.
Buy it on a safe exchange (coinbase or kraken), buy a ledger or trezor directly from their website (not a retailer) for example ledger.com. Send the BTC to your cold storage device. Hold long term. If you need capital down the line don’t sell the BTC, instead borrow against it as BTC tends to go up in price over time. Thats it GL
Did you really look those over to make sure they don’t have a private key or that they don’t unscrew to reveal a number inside or something? In the earlier days, people did distribute “physical” BTC like that in a variety of similar ways. Imagine actually having 3BTC sitting there and not knowing it bc you thought they were just little trinkets lol.
When you steal 1400+ BTC, they won't tell anyone but there'll be signs!
Millions of dollars get stolen and BTC pumps. Makes sense
it is saying the network would not adjust the difficulty even if all miners went offline. So even if you had an ant miner and it could not find a block at the current difficulty it you would never find any BTC.
When BTC was at 15k people said it was going to sub 10k then it went to like 50k in a couple months. Not buying because you’re trying to exactly time the market is never a good strategy. DCA down, NFA
Perhaps. Though consider the energy cost of Bitcoin (on-chain) network were to match the Visa network in terms of volume. For the 20million vs 20billion transaction difference. (3 orders of magnitude btw) Bitcoin energy cost per transaction was roughly \~1,500 kWh, compared to \~0.0015 kWh which is a difference of \~1,000,000× higher. To put that **1,500 kWh** into perspective, that’s roughly: Enough electricity to run an average U.S. home for about 1.5 to 2 months or drive an EV roughly 5,000–6,000 miles. A Visa payment, by comparison, uses around 2 watt-hour about enough energy to run a 10-watt LED light bulb for six to ten minutes. Kinda nuts when you lay it out like that. Granted, Bitcoin is paying for the excessive security of the network. BTC is like Fort Knox and decentralized whereas Visa is like an incredibly efficient logistics company moving billions of boxes on its network.
Because you say no left or no right wing and then write and entire post about Trump “being the worst thing for crypto” and then gave me a comment proving my point by writing two paragraphs about Trump when I didn’t bring him up. Trump isn’t affecting crypto at all and if you think he is you aren’t informed, you are inflicted with TDS. Also lol. I’m also not a Trumper. I just know the world will continue to go on regardless of who is president and you attributing BTC movement to Trump is as an idiotic take as some Trumper attributing 2022 stock market to Biden.
DM sine BTC and I'll point you on the right direction.
Only place I purchase BTC through. Daily everyday.
Major brokerages now allow you to hold your coins, such as fidelity. Sure, not your keys, not your coins, but with 18T AUM, if Fidelity goes under or gets hacked, the world has larger problems than the BTC you lost. I used to use Ledger but with their recoery schemes I decided I can't trust them.
Saylor said *you* should never sell your BTC. Saylor is busy trying to get MSTR included into the SP500, and to do so, they need to look more like a company and less like a digital asset. On record ≠ old ass interviews? BTC has been going up on the news of his selling, so I'll take it..
If you really want to buy BTC you should DCA over a period of time and not purchase lump sum just my opinion. Put in $1k-$2k max per week for the next 2 years if you want to be aggressive and sounds like you do 👍
I mean you could still use it... As a paper weight. You could use it to snort cocaine off. As a door stop/wedge. Just don't use it to store BTC 😎
How's your BTC stack coming along? 😂
I bet you won’t talk like that if it was you, to lose 1 BTC or even half of that.
You’ll be fine only 18 BTC search up James hawls how lost around 7500 BTC
There’s never a perfect time to buy BTC, but at \~50% off its $126k ATH this is a historically decent entry for a long-term holder, just never risk more than you can afford to lose, and DCA instead of dumping $64k in one go. NFA!
So smart you lose your BTC 😂😂😂
It will be very difficult. All their addresses are already blacklisted on every half decent reputable exchange. People mix anonymity with traceability. BTC is fully transparent and traceable. They can mix all they want. Unless they use massive mixing pools all they'll be doing with their BTC is buy VPN subscriptions
\>if vendors want to be able to take payments in BTC why would they choose to do that if they might accidentally get radioactive BTC? Why would they choose to take payments in dollar/euro/whatever bill if they might accidentally get radioactive bills?
I always thought that one of the underlying principles of BTC was that it was fungible. Tainting of coins goes against that which I think is fundamentally bad for BTC, if vendors want to be able to take payments in BTC why would they choose to do that if they might accidentally get radioactive BTC? Why would I transact with anyone other than a big exchange if there is a risk of getting 2nd class BTC?
broken English seems LIKE INDIAN scammers got there BTC taken 🤣
Good call! It’s been a stressful 10 years or so for me. Lost everything in Voyager, bought back some, and now there are constant daily threats of hackers trying to steal what you have. I still think BTC is a good long term investment and will continue to beat the S&P over time, but I would only recommend investing in one of the ETFs in a brokerage account instead of buying BTC directly
Can you name one place that doesn’t not accept the dirty BTC money?
QQQ up 20% YTD, BTC down 25%. Risk/reward is not worth it anymore
Yes, bear market means cheaper BTC for longer, that’s actually a gift we should cherish and seize.
BTC is not like a physical bank note with a serial number and such. Yes you can track every satoshi on the blockchain, but one whole BTC can be split into many parts, and those parts can be used in multiple transactions where satoshis from other (legit) sources can be combined. If you do that often enough, tracking the stolen BTC will be a lot of work. That is where a mixer comes into play, and that is exactly what the thief/thieves are doing right now.
People saying this is because the Coldcard hack. No, its´s not. OP´s stats are from the whole month of July. The Coldcard mess started till July 30th: The first public reports of Coldcard being hacked appeared on July 30, 2026, when thousands of wallets were drained in coordinated on‑chain sweeps. > Here’s the precise timeline based on the sources: > > 🗓️ Coldcard Hack — First Reported Date > July 30, 2026 > This is when blockchain analysts first detected the mass draining of Coldcard-generated addresses. Multiple sources confirm this date as the moment the vulnerability was discovered through on‑chain activity. > > 🧵 Timeline Summary > July 30, 2026 (early UTC hours): > The first wave of theft occurred — over 1,196 addresses drained in 41 minutes, stealing ~1,082 BTC. > > July 30, 2026 (later the same day): > Victims began posting online (e.g., Reddit) reporting that their Coldcard wallets were emptied. > > July 31 – August 1, 2026: > Security researchers (Block, Galaxy Research) published analyses confirming the flaw in Coldcard’s firmware. > Coinkite released emergency firmware patches on August 1, 2026. > >
There are at least 3 wallets 403 victim wallets got drained into one address: bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0 it took in 594.47 BTC. still holds 32.45. a second collector took 398.48 BTC in a single transaction with 491 inputs: bc1qc779m8gec84k3t0ffvu0pps94zheht7lr7ueyn now empty. a third took 88.85 BTC across 204 inputs: bc1qdaarag7729c2n4l2wnyt3hkhfpcs66n98z7uuh now empty.
Do they own their own BTC or is this the remaining Tesla stack?
It’s a speculative asset (high risk, high reward). You should only invest into BTC if you are willing to lose it. If you don’t really need that money, then you shouldn’t care too much if it underperforms for a long time. If there’s another bull market, you win! This is how gambling works.
CoinJoin itself doesn't care how much BTC there is - it accepts UTXOs of up to 10000 BTC. The question then is how the hacker would use the mixed BTC in the real world, without people asking too many questions.
Their cost basis is around $35k... This reported loss is based on previous highs, not how much they spent on their BTC. [https://finance.yahoo.com/markets/crypto/articles/spacex-reveals-1-billion-bitcoin-031424839.html](https://finance.yahoo.com/markets/crypto/articles/spacex-reveals-1-billion-bitcoin-031424839.html)
So many options. The easiest would be to pass the coins through CoinJoin, totally obfuscating their destination addresses (after a few rounds). They could use non-custodial swap services to swap the coins to XMR, and then the trail disappears. They could sell the coins P2P. They could pass them through lightning. They could buy goods online with the BTC directly, and then sell those. They could rent hashrate and receive mining rewards at a fresh address. Or a combination of all the above.
Anybody with morals would’ve quit that job the second they heard. Also he doesn’t do much helping, people have been saying he has notoriously blocked anybody since 2022 who contacted him about the flawed code and/or their BTC stolen. (This has been happening a while on a much smaller scale)
Here is how you handle the workflow so you don't lock yourself out: 1. Generate your new seed phrase using your chosen method (dice, offline tool, etc.). 2. Derive a receive address from that new seed phrase. If you have a second device or software wallet setup offline, grab it from there. If you used an offline BIP39 tool like Ian Coleman's, copy down 1 or 2 of the generated addresses (and the xpub/zpub if you want a watch-only setup). 3. Connect your Ledger (with your current/old seed) to your wallet software (Ledger Live, Electrum, Sparrow, etc.). 4. Send a small test transaction from your Ledger to the new receive address you generated in step 2. 5. Once confirmed, send the rest of your BTC to the new address. 6. Once everything is safely on-chain under the new address, wipe your Ledger (enter wrong PIN 3 times) and restore it using the new seed phrase. When you open your wallet software again, your funds will be right there. As for your specific questions: Adding a passphrase (25th word) creates a new wallet, but it still derives from the base 12 or 24 words. If the base seed itself lacks proper entropy, an attacker who breaks the base seed only needs to crack your passphrase next. If you genuinely suspect weak initial entropy, migrating to a clean base seed is much safer than just relying on a passphrase over a weak foundation. Should you act? Ledger uses dual hardware TRNGs on the chip and wasn't impacted by the MicroPython PRNG fallback issue that hit Coldcard. If you're paranoid or just want peace of mind, migrating via the steps above is safe. If you trust your current setup, staying put is fine too.
Doubt it. They'd likely be on dark web forums such as Dread (the dark web version of reddit) I used to be in the scene back in 2019-2021, you begin to have niche groups you type in and check daily, not reading generic public reddit comments like the rest of the public. Telegram groups like discord for example, is where the hacker is most likely to be working with people or just talking to people anonymously, figuring out how to clean the BTC and finding services other fellow fraudsters/hackers use. Hackforums, blackhatforums, etc. Definitely not sitting here reading reddit lol.
My suggestion is to stay on BTC only, DCA what you can afford to lose and not a penny more, keep your coins on the exchange (I suggest Strike) and get a cold wallet only when you reach four digits (I suggest Trezor), set up a passphrase (25th word) and treat it as a password, move your funds once a month to the passphrase wallet, and don’t panic over the price - stay for the long game.
After a 30 year career in the tech industry and raising a family in an expensive part of the world I always found myself too scattered and stressed to get into BTC. This often made me feel like I missed a great opportunity. But as I go to sell my house the 146% appreciation over 11 years coupled with the state of crypto now has erased most of that FOMO.
Anyone else find it sus how so many ppl in r/cc lost crazy amounts of BTC? I don’t know anyone who had even heard of cold card before this.
Why would someone burn their BTC? And why there?
What happens when the exploiter sends random amounts of BTC to various legit wallets though? suddenly all of them are bad guys just because they received funds? you see it starts to get messy quickly if the bad actor is savvy enough...
1. Buy when people start saying “Bitcoin is dead” 2. Store your BTC on a Trezor Safe 7 and use a Passphrase 3. Sell when Bitcoin hits an All Time High. Every single time. Rinse and repeat.
The point is, if you hold your crypto long enough without selling,they will end up being 40% of your portfolio.. then 60% 🤣🤷 it's just the way it is.. crypto CAGR are beating pretty much anything else. And I suggest you stay with the 10 biggest ones.. and have at least 50% of your whole crypto fund in BTC.. but that's just me... Do what you want.. When I buy BTC.. I indeed intend to never sell them. I'll borrow against it if something. Not sell.
So whats the workflow if I had a Ledger with a Ledger firmware created seedphrase and wanted to move my BTC to a new truly random seedphrase? If I ‚restore‘ with my new phrase the stuff sits still in my wallet which isn’t accessible anymore and if I want to move the BTC before ‚restoring‘ I don’t have a target address? Or will just creating a second passphrase based wallet with the same seed be enough? I understand that would probably work. Or should I just not act at all?
You don't work in finance do you. >No one actually really wanted to have it. You just take an illiquidity premium. If you've got 80k BTC that won't move, you just sell the rights to it for 60k. That 60k worth of Rights can change hands multiple times as speculation bets on technology being developed in the future that will unlock the 80k (and thus, profit). Happens all the time with stock derivatives and real estate backed loans. The world is more clever than they teach us in school.
Theres no way a location or identity could not be found unless they do something stupid like transfer BTC to a kyc exchange to sell. Which they won't.
From previous history, after the DCA halving, it was the momentum to buy BTC.
This is the best time to DCA, your timing couldn't be better! I have set aside decent amount, and will try to buy close to bottom (assuming it will go lower in Aug-Sep), and after investing that lump sum, continue to DCA every month until BTC reaches 100-120k, or whatever price I'm comfortable buying.
I'm sorry this happened to you. Truly. Was is one of those Cold Wallet hacks? I bought my very first BTC about a week ago so I'm can't give advice here. I wish you the best of luck.
You can get the approval to increase that to $25k, but I also share your concerns about not having full access to your coins. After careful thought, I do not think this platform is right for everyone, but it fits my use case. I'm looking for long-term storage (15 years) that will let me sleep well at night. The 2k withdrawal gives me comfort that if I am hacked, the hacker can only get 2k before I would notice instead of draining my account. If you are an active trader or need to move large sums of BTC, it's probably not the best platform
Imagine if the hacker just sends all the BTC into a Bitcoin eater address lol
I've known NVK for years. The last thing this guy would do is harm the reputation of BTC. That, and he's definitely already mega loaded. I know everyone wants to target a bad guy, but I genuinely don't think NVK is your guy here. I know it's easy to want to publicly hang the dude right now, but I actually feel bad for him, he just ruined the rep and successful company he has worked a huge chunk of his life on and there's no coming back from this IMHO. He should've done a better job, yeah, but I don't think he'd rob normal folks, let alone anyone. All people can hope for really is a major screw up by the bad actor and they get Team America'ed.
There is no bad time to buy BTC
bruh, the hacker could have swapped this for Monero and then for BTC or back to USDC and use on any crypto card out there...
A lot of addresses send BTC into one address. A lot of transactions go out with absolutely different quantities to new addresses. The man in the middle is the only one who knows which BTC belongs to whom. A third party cannot look anymore into the mixer Blackbox.
That’s the state of society right now. Legit looking email? Header right and legible? Legit? Still could be hacked. Loaded old updates that haven’t had hotfixes? Well damn grandma you had six BTC?! Sheeeeeeeet. I HATE blkhat hackers but imo white and grey hats have a purpose. Testing the fences man. Testing the fkn fences
Bitcoin is not crypto. TA is 100% BS. Nobody knows shit about fuck when it comes to market/trading. MACRO is informative but terrible at timing. Prefer owning your own BTC but unless you have specific needs and up until a certain sum, buying an ETF is fine. Just HODL. Ignore influencers. Their interests are not aligned with yours. Bitcoin is disruptive tech. People are afraid of change and will fight it. Spin up a full node if you can. Never invest more than you can afford to lose. BTC is the best form.of money ever, but this does not mean humans are smart enough to realise this and not take advantage of Satoshi Nakamoto gave us. Never advertise how much BTC you have, nothing good ever comes from doing so. Don't push BTC ideology on to others but explain and educate those willing to listen. Hold tight! It's going to be a wild ride.
??? BTC got that popular just because it supports money laundry (and tax evasion)
A few years ago the Canadian government froze the fiat accounts of protestors who protested for the wrong political party. BTC is inherently censorship resistant. Implementing bans on coins of people you don't like breaks that.
Mix thousands and thousands times, then spent. Yeah it all trackable, but NSA wont bother with your 0.1BTC stolen.
This post is horrifying. Imagine following every single opsec rule, using 3 separate air-gapped Coldcards, and still losing 18.25 BTC in 8 minutes because of a device or firmware flaw you had zero control over. This is why pure self-custody is a massive risk for real wealth. Your security can be 100% perfect, but you're still relying on a $150 plastic hardware wallet not having a supply chain or RNG bug. With institutional custody, you get actual multi-sig vault infrastructure, legal recourse, and insurance. "Not your keys, not your coins" sounds great until a single vendor bug wipes out your life savings.
Now and next year is good time to buy Bitcoin. Best to buy every month. You don't need whole BTC or $20000 to buy it. Just buy as much as you can.
Rien que cette inaction qui relève pourtant du bon sens couplée à une démarche de transparence démontre l'opacité entourant le système bitcoin en général. Le BTC c'est le far west du 21eme siècle.
Excuse my complete ignorance but why are there still people vulnerable to this? Wouldn't there have been an enormous run on Coldcard to empty wallets on day one? Like, does everyone have notifications turned off? Lost the keys? Just I don't even own BTC and I know all about this. It's been a week - just a bunch of HODLers out in the Canadian wilderness chopping wood?
They're only "real" addresses in the sense that they meet the checksum requirements. Nobody actually has the private key though, so anything sent there is lost, hence the tiny send amounts. E.g. the address: 1111111111111111111114oLvT2 ...is a popular "burn address", holding 800+ BTC.
> This is still theoretical and nothing to be concerned about. Modern Bitcoin transactions hash the pubkeys. However, millions of BTC are still in these old adresses, not in the modern ones. It's very much something to be concerned about.
What does anything of this have to do with the US? Why would the BTC go to the US?
I mean the cheaper you buy the better. You buy your fav chocolate from the supermarket, next week you see a 50% discount, you’d buy even more than usual, so when the discount is over, you still have cheap chocolate in your fridge. I genuinely enjoy being able to afford more BTC with my regular DCA amount. I remember going crazy when we went down to 20k, I was almost 50% in red, but kept buying to reduce avg. now we are deep in bear market, thanks to that period, I am still in profit with a good margin.
I wouldn't be so sure to make that bet to be honest. FTX, Celsius, MtGox, QuadrigaCX, Cryptopia, BTC-e... the list of exchanges that went under is long.
For most people it will be 18% tax above £3000 profit and fees are negligible. That’s roughly the same as the US where most people will pay 15% on all profit. For a short time you were allowed to hold BTC via ETF in an ISA and pay no tax but that was removed unfortunately. Hopefully it is reinstated.
Poor guy never did the research and thought the minimum buy is 1 BTC 🫠
And people told me to buy that shit when I posted I have BTC at a german regulated broker lul
Wonder what the bad guys are using for storage of the stolen BTC
summary for those of us with adhd brains Researchers now say they've identified the developer responsible for the flawed randomness code behind the ongoing **Coldcard seed-generation vulnerability**. The report claims: * The vulnerable `libngu` code was authored by **Coinkite CTO and co-founder Peter Gray**, based on cryptographic GPG commit signatures. * Bitcoin developer **James O'Beirne** says he warned Coinkite about the randomness issue in **May 2025**, but the warning was allegedly dismissed. * Coinkite has **not publicly responded** to the identity allegations or the claim that it ignored the warning. # The vulnerability * A **single code change in March 2021** accidentally replaced the hardware random number generator with a weaker software source when creating wallet seeds. * The result was **far less entropy** than intended, allowing attackers to regenerate affected wallet seeds offline. * **No phishing, malware, or physical device theft** was required. # Current impact * Approximately **$114 million (≈1,800 BTC)** has reportedly been stolen. * More than **5,200 Bitcoin addresses** have been compromised across four attack waves. * Coinkite says the exploit **is still active**. # Who is affected? **At risk:** * Mk3 wallets initialized on firmware **4.0.1 or later**. * Mk4/Mk5/Q wallets that generated seeds **before** the patched firmware releases. **Not affected (based on current reporting):** * Wallets created using the **dice-roll seed generation** method. * Wallets protected with a **strong BIP-39 passphrase** (risk significantly reduced). * **Multisig** wallets where the affected Coldcard is only one signer. # Bottom line This is becoming one of the **largest hardware wallet security failures** in Bitcoin's history. The immediate risk remains the flawed seed generation—not the hardware itself. If you ever generated a Coldcard seed on affected firmware and haven't migrated, **move your funds to a newly generated wallet immediately.**
You know you don't have to buy whole units, right? It's not a physical coin. Start DCAing with an amount you're comfortable with on STRIKE or something like that and get a Trezor wallet with a strong passphrase to store your BTC.
I'm a banker, so I believed in real money, CDs and low risk assests and I simply did not see a BTC hit over $100k one day, but...It did and I know lots of ppl gaining from that. In fact, my partner has been sitting on 5 btc since 2023 and has no plans on selling it in the near future..If you go to Europe they do real estate transactions in bitcoins.
> A hardware wallet’s most important feature is not its seed phrase creation, it’s just a convenient feature. The 'boom' you hear is the moving goalposts breaking the sound barrier. I've been active in crypto for about 14 years. I have never once heard someone say creating the seed isn't an important part of a hardware wallet until this week, when all the Monday morning quarterbacks came out. In some sense it's the main purpose because all other ancillary purposes, like signing transactions, are contingent on the existence of a wallet. Last week, any person doing due diligence to self custody their coins in a safe way could have reasonably landed on a Coldcard as one of the best solutions, along with the TRNG being sufficient for 256 bit entropy. Dice rolls and passphrases were considered extra security, above and beyond the sufficient amount. For most of the last 5 years, the other highly recommended HW wallets didn't have dice rolls as an option, their on and off device RNGs were also considered sufficient. This is the first time people who didn't do anything 'wrong' in the self custody process have lost BTC. You can argue that they didn't take the maximum conceivable number of elaborate precautions, but no one really does.
if you didn't trust it back then, why do you trust it now, when the coldcard incident just screwed a ton of people? not trying to be rude, I'm just curious what the average people think about BTC's trustworthy now
Ran out of btc. No worries. I paying a lower level thug in ETH to slap that person of yours that slapped my BTC contractor.
Odds are they didn't do it. They would never be able to retrieve and use the BTC without getting caught. Even ceding the point these might not be the smartest people; that's like a cashier stealing from their own register. There are (were) so few people at Coldcard, all the employees are going to be looked at hard. Stupidity and negligence are by far the most likely scenario.
If privacy is your priority, BTC probably isn't the best choice. I'd go with TRX from the options listed, low fees and no need to deal with stablecoin networks.
This is almost certainly what they have. Unsure why more do not go this route along with Tails OS air gapped whenever they move BTC.
No one knows if it's the best time. I'd be more worried about buying 1 BTC on day one than the price itself. Start mall or DCA first
I never said BTC addresses can be frozen. Y'all cannot read. With that said, unless the coins are obfuscated using a system like Monero or Tornado, coins can be tracked and if they're ever onloaded to an exchange, be frozen. But again, I am not saying that happen. I'm literally asking how the OP has concluded there was a "blunder".