Reddit Posts
Coldcard Users Reported Instant Drains Years Before July 2026. Here Are the Receipts.
Inside Bitcoin's 165 Million UTXOs: Five Surprising Results
Coldcard hacker address receiving several messages via OP_RETURN
COLDCARD Hacker receives money laundering offer via OP_RETURN message
COLDCARD, CLN disclosures, zk proof of reserves - Bitcoin Optech Newsletter #416
I'm building a protocol that lets Bitcoin wallets self-declare "financial" vs "data" transactions -no consensus change needed
A very balanced article about BIP-110 by Jason Hughes - VP, Development and Engineering at Ocean Mining, yes the pool signalling for BIP-110
The 55% Trap: How BIP-110 Threatens to Fracture Bitcoin.
SlowCoin-A fully decentralized currency
Bitcoin's ZK Awakening: The Cryptographic Death of the Altcoin Scaling Narrative.
Bitcoin's ZK Awakening: The Cryptographic Death of the Altcoin Scaling Narrative. Strip away the marketing noise. Here is the uncompromising technical blueprint of how Taproot, BitVM, and OP_CAT are turning the base layer into a natively trustless settlement engine.
shibpost.com (shitposting on dogecoin)
15 Years Ago, Hal Finney Explained Why Bitcoin Could Not Simply Be Replaced
Mentions
Did OP have a brain fart? How can they make the coins untraceable if they just do a 1 to 1 transaction? They are trying to avoid someone reporting the stolen coins.
no one is picking the exact date. People just think around the October/November timeline. No idea why OP said 23 October
*OP quickly sends 0.2 BTC to his other wallet*
OP you helped your friend, you didn’t force him at gunpoint to buy sats!! Everyone makes their own choices
This is what I was thinking as well. To reply below on "OP asked for non-electronic," [this bip39-diceware](https://github.com/taelfrinn/Bip39-diceware) tool says: > After you are finished all 12 words, the last word may need adjustment in order to meet the checksum requirements. Using a bip39 wallet try each of the words in the block of 16 that the last word is found inside; one and only one word will work from the group. So given difficulty of doing your own hash, isn't this a *pretty decent* compromise? - you know the checksum word will be 1 of 8 possibilities based on the 23 words you generated with dice (and presumably trust) - you can use any number of HW or software wallets to check as many other words as you desire *not* in these 8, until you feel convinced it wouldn't slip a fake word in there (Do the above with throwaways, then do the real deal without checking in networked tools.) I admit I don't know what "checksum" means for sure here. Is this about "how do I figure out the correct 24th word" itself, or how do I verify that the checksum itself (a hash I presume?) is correct? If there's a way to do 24th word > hash it using whatever number of independent tools you want > verify you get the same... I'd say finding the 24th word reliably (1 of the expected 8, and *none* any number of non-8 you try) seems like a solid verification approach.
OP gets more engagement by mentioning it.
In order to test the 24th manually you need some sort of an electronic device, which is against what OP asked.
Maybe OP isn’t from America or any other country with a stable economy. They could be living under an authoritarian government with extreme inflation, where holding US stable coin is one of the few ways to protect their savings In some countries, keeping money in the bank is not even safe because corrupt officials can monitor, freeze, or take it
Zero chance OP knows what MC is.
That's actually a really interesting implication... If the effective entropy really was around \~23 bits then collisions wouldn't just be possible, they'd become statistically likely. And only after only a few thousand wallet generations (birthday paradox). What I find fascinating is the reporting bias created from this whole fiasco. Because we only ever hear from people who **lost** coins because they naturally assume they've been hacked but what about the person who generated the same seed years later and suddenly found an existing balance? Would they post about it? Probably not. Most people would either think they got impossibly lucky and/or just quietly move the coins. And even if they did post, I suspect the community would dismiss it as fake because "hardware wallets don't come preloaded with bitcoin". That being said, I don't think there's one single instance of someone mentioning this -- at least not that I've seen. Ironically, a credible report of someone generating a brand new wallet that already contained transaction history would have been a much stronger early indicator of a broken RNG over isolated reports of stolen coins. The latter are easy to write off as user error, phishing, poor seed handling, etc.. The former is much harder to explain away. **If collisions were occurring, the first public "I unexpectedly gained bitcoin" post might have changed the entire narrative years before people started connecting the dots.** Not sure if it would have changed anything because the writing was basically on the wall -- and any attempts to contact people to tell them to regenerate their seeds would have been futile, as they would have also tipped off hackers. Truly fascinating stuff, and we're all here just witnessing history unfold. They'll talk about this for decades, maybe centuries. People might come back to OP's post in a college class. Wild wild times.
It maybe correct now but OP can change this at any time. It is bad practice to open links in posts. As OP stated, there are many fake websites that look like Ian's. Bitcoin security should be taken seriously.
I agree. OP would have done exactly the same if was paid for it
Hi OP. I was a cold card fanboy I admit it, but now I am like you.
That was my first assumption (before we even knew about Switck) but if it was a long-standing inside job, then OP’s questions carry more weight.
can you link this? I dont think you can put that much on OP\_RETURN
OP said not much if any layer 2 which is a weird way to dismiss lightning entirely.
Just curious, how old were you in 2020 OP?
Thanks for posting OP. Casino dice are harder to get you have to order them only specially. I just got some dice here that I already had lying around my house. Any thoughts on putting the dice in a plastic cup then shaking and putting down on the table? Seems like the dice would bounce a lot inside the cup, and also bounce off each other making it even better. If theres any small bias you can remedy it by just rolling more dice. SeedSigner wants 50 dice rolls for a 128 bits, but if I roll 100-150 times that should be more than enough to smooth out any bias.
that's my home you cunt. i bet OP friend queried whois on mempool.space and now is angrily headed to APNIC PO box in Brisbane.
OP was an idiot and got one obviously. Only reason to be this emotionally charged up. If you want to learn a lesson tell this shit to yourself. Grown adults don’t follow the advice of Reddit and then blame Reddit…. And if you didn’t follow the advice, then shut the fuck up dick head. What a mouth breathing loser. Stay poor
OP, did you know about this vulnerability in advance and brought awareness about it? No? Then shut the fuck up with this useless gloating.
The problem comes when you try to actually turn that BTC into something useful, AKA fiat currency. 'Well I'm sure there's some unethical exchange out there in Russia or something who will do it' For $114 sure, not $114 million. Real exchanges can, and do, blacklist wallets. OP is also stupid because he's not a 'noob' for putting it in one wallet, it can be sent to ten thousand and it'll be tracked extremely easily by software. Over 90% of stolen Bitcoin, from every major hacking event or fraud ever, sits dormant right now. Exchanges that have that much liquidity also have zero interest in ruining their business or being pulled into legal battles to reobtain stolen property that they just purchased. The exchanges do not operate anonymously.
Excellent OP and responses. Though I prefer just doing the entropy fully offline for the first 11 or 23 words (pen and paper) and checksum (last word) using a computer. Lastly, adding a 130 - 160bit passphrase to make the final cold-storage. I'd use a public key to make as many "Watch-Only" wallets i want and delete all traces. Cold storage, we'll at least for me, is multigenerational wealth. I dont spend out of it, i just accumulate. I still don't get why people are flabbergasted. Self sovereignty is entirely YOU. Risk mitigation, insight and security measures are ENTIRELY your call. You can make it simple, you can rely on 3rd party. Or you can make it Fort Knox on Pluto levels of secure.
Can we perma ban people who intentionally spread misinformation, like OP?
I bet dude jerks it to these type of OP\_RETURN messages
absolutely. even this was still avoidable, and yet it's triggered a massive security audit as OP said. if you didn't lose your coins in this one because you didn't use a tiny rinky dink company's product and/or you had any form of secondary security, you'll ultimately be better off
Avoid websites unless they're open source and have been for years. And even then, download the code to your own PC. The one OP provides is good. Others are questionable.
I'm sorry OP. I'm sure you're beside yourself and heavily grieved of spirit. Do not be a fool and act foolishly in the moment. This too shall pass and you Will be fine. Keep your head up and give a shout up to the Most High. He'll carry u when u feel like u can't move forward. Sending love to ya my friend
I looked at OP's account, and it doesn't reveal much besides the fact that she's a girl. Did she recently hide her posts ?
The OP on X admitted this is just a joke /meme
OP said he had the money in USDC, it's baffling why he wouldn't just have it in the bank. Unless he was using it to trade or dip into to buy crypto.
I would be very cautious about buying broad market indexes right now. So many smart people and expert investors are pulling back and holding on to cash. For example Warren Buffett has sold off over 50% of its stocks in its portfolio and is holding on to cash or cash equivalents. If the OP wants to invest, I would seriously invest in a diversified portfolio with: - just a small percentage of Bitcoin - a percentage of the broad market index - a good percentage of funds that are not as badly impacted by A.I. and are somewhat recession-proof, things like utilities and natural resources
This is littered with fallacies and misconception. ETFs do HAVE risk, they are NOT insured in this blanketed way that OP implies either. You don't even mention the fees either lol
yup OP just trying to scam - RIP
Ok fine. OP thanks for the post.
Thomas Brazil is a scammer and criminal and probably the OP. Mods, you should delete this post: https://www.wsj.com/articles/ftx-claims-broker-thomas-braziel-stole-1-9-million-from-a-receivership-for-personal-gain-court-says-d3375130?eafs_enabled=false https://www.offshorealert.com/distressed-crypto-investor-thomas-braziel-settles-claims-that-he-misappropriated-5-5m-from-fund-com/?srsltid=AfmBOoqZV1MikCoL9gIlTIohr3ljCFZ60L5AThBM3fIboEggV1Rd9kzn
Read OP. Same problem Rolling dice works but that's not what OP is explaining. They are relying on software. Which is why I stated what I stated. If you're going to rely on software, then you can do better and there's no need for dice If you don't want to trust software, then use dice, but not how OP is explaining it
Normally, you can't have messages that long, because most nodes consider a transaction having more than one OP_RETURN output or having an OP_RETURN carrying more than 80 bytes to be non-standard and won't propagate it. If it doesn't get propagated, miners won't see it, and it will never get mined. For such a transaction to get into the blockchain, a miner has to bypass the network and put it directly into their own mempool. So whoever sent those messages is either a miner themselves or paid one (or more?) to include them.
Whoever sent these messages must have had the help of miners (or *be* a miner). Such OP_RETURN outputs, carrying more than 80 bytes of data, are considered non-standard by most nodes, and therefore are nearly impossible to broadcast. Essentially, a miner must insert such a transaction directly into their own mempool, instead of picking it up from the network.
I gave this explanation in another thread where a different OP asked the same question basically… Bitcoin can be leveraged. You don’t even have to sell any and the hacker could simply just take a loan and then default so the bank repos the stolen coins. Then it will be swept under the rug for years because no bank is going to want to admit they secured stolen collateral. The other option is the new holder could utilize a mixer that shuffles the asset exchanging for other assets that eventually drain to a handful of wallets after thousands of transactions making it very difficult to detect…especially with so many coins having private ledgers that don’t view publicly. This is easier than you think and can be set up by any idiot that can perform a google search
The fact that there was a swap hints that this wasn’t a scripted sweep, OP was targeted. So not a bigger exploit, he leaked his seed or key.
He says as at any money of any day anyone is anywhere on earth and they have caeh In their pocket. It can be lost in countless way. From a mugging to a mudpuddle. Yet currencies were adopted all around the earth by every culture in every country? So what I feel is the actual really HARMFUL to the speed at which just like fiat currency, the speed of crypto currency is more greatly addpoted. Is actually naysayers like yourself whom for God only knows what reason your posting opinions that seem anti crypto in a community that is only about crypto. So? you yourself are in this community . Are you a luddita against technology advancement too. Because in order to make the post you required the use of computer technology. The contradictions continue,? . Or do you just simply have nothing else to say so you say something negative.? Whatever the case may be. Always try to remember the old saying . If you don't have something good to say then shut the F@s% Up!, The OP was ripped off. Take 1 step outside your residence with your physical wallet in hand. Then tell me muggings don't exist.". Or wake up at 4am to find notification from you on your phone from your bank saying- Or you don't check the URL and you order online from a scam website masquerading ad the real one. ALL of these situations are and more represent ways that funds can be lost. But they still are used en mass. "Fraud alert your credit card number was just used online to make a suspicious purchase.". "This is why.....will.never be adopted by the genral public." he says. You remind me of my grandparents who said "Do you really think this internet thing will catch on.? If only the concept of "Think before you speak could be adopted my the masses" . I say.
Sounds like OP was a victim of address poisoning, not seedphrase exposure. Brutal stuff. My condolences OP, Im sorry you are going through this.
People saying this is because the Coldcard hack. No, its´s not. OP´s stats are from the whole month of July. The Coldcard mess started till July 30th: The first public reports of Coldcard being hacked appeared on July 30, 2026, when thousands of wallets were drained in coordinated on‑chain sweeps. > Here’s the precise timeline based on the sources: > > 🗓️ Coldcard Hack — First Reported Date > July 30, 2026 > This is when blockchain analysts first detected the mass draining of Coldcard-generated addresses. Multiple sources confirm this date as the moment the vulnerability was discovered through on‑chain activity. > > 🧵 Timeline Summary > July 30, 2026 (early UTC hours): > The first wave of theft occurred — over 1,196 addresses drained in 41 minutes, stealing ~1,082 BTC. > > July 30, 2026 (later the same day): > Victims began posting online (e.g., Reddit) reporting that their Coldcard wallets were emptied. > > July 31 – August 1, 2026: > Security researchers (Block, Galaxy Research) published analyses confirming the flaw in Coldcard’s firmware. > Coinkite released emergency firmware patches on August 1, 2026. > >
"110 ist eine zwangsweise Änderung an Bitcoin, um seine Flexibilität radikal zu reduzieren – es deaktiviert sogar OP\_IF" Ja, weil es praktisch niemand verwendet und eine andere Funktion dafür gibt. Wer da von "radikal" spricht, scheint hier aus eine Mücke einen Elefanten zu machen. Warum nur?
Damn. This is some really good detective work. The sooner OP files a report the better because Binance won't really care without law enforcement being involved.
This is the best analysis. OP guy tricked into making a mistake while not being thorough. Always use small amounts to test transactions.
Poor dude sending those messages to the hacker doesn't realize the hacker doesn't care and probably never even read the OP_RETURN
More like it reads OP is terrible with money and dumping him is dodging a bullet
Nah it was address verification, probably harder pill to swallow because OP likely wasn’t hacked they did it to themself.
This is a tough one because I don’t think you were actually hacked. The problem looks like it was probably self address verification. Your history is full of lookalike addresses. You sent to 0x9b9Ae2db…b44F62, and there’s also 0x9B9A3299…4F62 and 0x9b9A34b3…4F62 in your history. Same first four, same last four. Those got planted by counterfeit USDC contracts using Unicode lookalike characters (eg. ÚSDС, UṢDC, ՍꓢƊС) plus zero-value real-USDC transfers, so each one shows up looking like a legit past payment. You almost certainly copied one of the wrong ones, and the truncated display made it look right. There was no transferFrom, no drainer contract, no approval. You signed it yourself with your own key. Funds ended up at 0x88F8eCbA… on Aug 1. Your only real shot is if that’s an exchange deposit address. Worth reporting fast with the hashes, though it’s almost certainly already through a bridge or mixer. Sorry OP, that’s a really unfortunate situation. It’s sad but **strong reminder to everyone to always check the full address when sending, not the first and last four, and never copy from transaction history.**
If 10 grand breaks the relationship thats the best 10 grand OP ever spent
OP said he took a photo of his seed and saved on his phone. There you go, people.
What a shitty analogy .... OP didn't get scammed, he got robbed. On a regulated sgit, OP can have protection against that because of regulation.
Sorry this happened to you OP. In the future, keep all money you need in a short amount of time or money that is of importance to you in a HYSA. No idea why you were keeping your wedding funds in crypto. Lesson learned
Really sorry this happened to you OP, I think providing a little bit more information as to how they got your account information would be beneficial instead of making it appear like somebody hacked into your account. I would caution anyone reading this to invest in things like IBIT if you’re attempting to speculate on the price of bitcoin. It’s very easy to keep your money in legitimate banks or places like Fidelity, if you want your money to grow. If you’re trying to spend crypto, you can just deposit the funds and convert it for the individual transactions, which for most people would be almost never.
Because it's LLM spam. OP is too retarded to put his thoughts into words.
Any reputable exchange will, it's a SoF check the Satoshi test they just want to check OP is rightful owner.
OP discovers how taxes have worked since ages and starts by noting their service does not help them avoid taxes anymore
Not using advanced is the Idiot Tax OP is talking about.
Been getting spam, but also a legit email from them discussing the warning OP got.
Funny how everyone is defending Coinkite there and blaming OP.
Maybe you should look more closely at the numbers OP😉 🎶ABC easy as 123.
I’m not reading this. I don’t even think OP read this.
I never said BTC addresses can be frozen. Y'all cannot read. With that said, unless the coins are obfuscated using a system like Monero or Tornado, coins can be tracked and if they're ever onloaded to an exchange, be frozen. But again, I am not saying that happen. I'm literally asking how the OP has concluded there was a "blunder".
OP has no leverage. She's a girlfriend who's asking for wife privileges.
> We are in agreement We are not. Hallucinations are a non-issue at this point, and more of a statistical error. You can manage how likely an LLM is to hallucinate information when asked about stuff outside its training data, but getting it to search the web, use MCP servers, or use some type of RAG database introduces information outside the model's original training data (which is the reason LLMs hallucinate). > The claim of OP was that LLM would have found and fixed the issue on its own before any harm would have been done to customers. Yes, this is true. Our models are very capable, and if anyone had bothered to review the source code with a model like Sonnet 5, Opus 5, or Fable, they would have likely found the same bug. (Once you discover the bug, depending on whether you know what you're looking at, the next step would be to ask the LLM to create an exploit and test it.) > My claim is that you need a deeper knowledge about the whole product and a bug in a code is only the beginning of it. So no, it's not that easy. Agreed. You need to understand what the LLM is telling you to be successful. > That's it. Regarding Mythos it has been debunked multiple times. Beware of marketing, AI companies are not out there for doing good but making cash. The PR around Mythos was that our Frontier models, like Opus 5, would have been able to find the same amount of vulnerabilities if asked. > Since Mythos analyzed Firefox fully already, we should not uncover any new zero-days going forward on those old code paths, Do you think the development of Firefox has stopped? New code and edge cases will exist, and under the right circumstances, a major vulnerability will be found. > Mythos was that useful or not The metric of usefulness is whether people are willing to pay for Mythos for it to work for hours on end scanning their entire codebase, or whether a cheaper model will suffice.
> My claim is LLMs can and are being used to develop software now, today We are in agreement. LLM and all form of AI have been and are still being used. No problem with that. The claim of OP was that LLM would have found and fixed the issue on its own before any harm would have been done to customers. My claim is that you need a deeper knowledge about the whole product and a bug in a code is only the beginning of it. So no, it's not that easy. That's it. Regarding Mythos it has been debunked multiple times. Beware of marketing, AI companies are not out there for doing good but making cash. But let's make a deal right there. Since Mythos analyzed Firefox fully already, we should not uncover any new zero-days going forward on those old code paths, right? If we do, then we will know of Mythos was that useful or not.
I'm not OP, but i'd suggest people with a Trezor One go check on their old device. Mine has sat in a safe for years, not stacked under anything heavy, etc, and I got mine out during the coldcard scare to find that the screen is partially damaged and I can't read everything off of it. I'm upgrading to a new device for that reason, not the coldcard reason, but I can't help but wonder if a number of old Trezor Ones have suffered the same fate as mine, because it was never carried around in pockets, mishandled, etc. It literally just sat in a safe in a little compartment drawer up top - so there was no pressure on it, etc.
I remember when this first happened someone posted here and everyone was like “bet you posted your seed phrase online lol dumbass.” Imagine that but every few months and OP did nothing wrong and nobody believes them 💔💔
Yes, and OP is not talking about coins already stolen. He's talking about coins not yet stolen, and he is right. White hat hackers are already finding vulnerable seeds & setting the coins aside to potentially return to the rightful owners later.
I know and agree, my response was to OP original post.
OP is referring to vulnerable ColdCard BTC that remains to be stolen. A benevolent group could race the attackers to brute-force remaining wallets, empty them, and somehow return the coins to the rightful owners afterwards (as OP's theory goes).
I think OP meant that the receiving wallets would be black listed on exchanges because they would then have coins in their history than can be traced to the coldcard hack target wallets ...
uncle is buried in OP's yard
anytime I've seen this type of "I have free/fixed electricity" post on here, the commenters have always ripped the OP a new asshole
OP thought he would make the hackers full of fear by putting out this rumor 😂
OP you should repost this on Facebook o, or wherever the normal folk connect..because *we all know BTC wasn't hacked, we're literally not the targeted audience for this contributed article*
fuck you OP, you deserve the same kind of cancer you are to society! go eat a d>u<ck! a fat juicy, meaty d>u<ck!
Is it right that that red above OP\_return means he actually sent some money back? I see a few where it legit looks like it refunded
maybe, but have you considered that OP needs to pump his bags
Right??? Like what fucking rally LOL. Just checked price and it’s like ??? OP we’re mid crypto winter, pucker up.
This was the top (ad) link for me when I searched "ledger firmware update" yesterday. I don't know if it was OP's scam, but clearly a scam. [https://sites.google.com](https://sites.google.com) || /view/ledger-downloader/ Go to that page, and tell me honestly, with your two decades of experience in ads and tech, that google shouldn't be able to identify that as a scam.
Some of the OP_RETURN messages people send him are funny
Not sure why you’re getting downvoted-voted here, considering OP‘s post is obviously not authentic.
OP isn’t a real victim. It’s engagement farming.
Used to be the top link was the highest quality choice Google could find. Ad links were visually separated. Those two things would have protected OP and not doing them is a choice. Google is actively choosing profit over customer safety.
yeah OP needs to drop the contract address before anyone can actually help. 9/10 times it's honeypot when swap fails tho
To me this felt like either a trezor shill post or OP not doing the correct analysis. To be fair Trezor still has good security though, but saying it is better than bitbox02 is debatable.
I did read it and there's a post here in reddit claiming that a wallet with a two word passphrase was hacked, you can look it up yourself. I want to read the answer from OP not from some other random user.
Yeah, a lot of these posts end up being fake just to get engagement. Also, seeing that it has 47 views at the time of the screenshot, I wouldn't exclude the possibility that OP is promoting his own account or something
I'm pretty sure the people who are telling you to gamble are joking or just being assholes. Don't do it OP.
I'm not familiar enough with Bitbox, so I can only make a conclusion based on what's presented in this post. OP should've listed that one of the entropy sources is the user's computer
Using dice rolls (99 times, 32 bytes, 256 bits) is just one method to generate external entropy; the attack scenario you mention does not affect or attack this lol You can also use coin flips (binary, 1010101, 256 times/bits, entropy!). The firmware (OS firmware, private firmware in HWWs, etc.) must correctly process and incorporate this entropy to generate a seed. The problem is not external entropy; the problem is the system (firmware) used to convert that entropy into a seed, like the Coldcard entropy bug in its firmware. >I am specifically attacking the process being described by the op The OP's AI-generated image is just describing how to use external entropy on a device like HWWs, nothing more, lol You should use some chatbot (AI) to check if what you believe you know about this is actually correct. lol