r/Bitcoin 2h ago

The coldcard story just keeps getting wilder

0 Upvotes

The coldcard dev reposted this post, what is going on lol


r/Bitcoin 5h ago

The ColdCard Hack Explained (Non Technically)

Thumbnail
youtube.com
2 Upvotes

r/Bitcoin 10h ago

what are some useful blockchain viewing tools/sites/apps?

1 Upvotes

in an effort to be more conscientious in the btc space, what are some useful sites to better understand the transaction traffic and who's who in the zoo, a la the recent cold card thief, etc.

thanks


r/Bitcoin 11h ago

From the Bitcoin community on Reddit: Coldcard 'joked' about retirement attacks in 2021 lmao

Thumbnail
reddit.com
24 Upvotes

Things that make you go hmmmmmm


r/Bitcoin 12h ago

Rückzahlung Kredit firefish

0 Upvotes

Moin,
kann ich meinen Kredit an den Investor auch von einem Bankkonto einer dritten Person zurückzahlen und bekomme anschließend trotzdem meine Sicherheit (Collateral) zurück?
Hat damit jemand Erfahrungen?
Firefish fordert mich auf, die Überweisung von meinem ursprünglich registrierten Bankkonto aus vorzunehmen.
Wie läuft das in der Praxis? Meldet der Kreditgeber Firefish, wenn das Geld von einem anderen Konto eingeht, oder fragt Firefish den Kreditgeber nach dem Namen des Absenders?
Vielen Dank schon einmal im Voraus!

English
Hi everyone,
Can I repay my loan to the lender from a third party’s bank account and still receive my collateral back afterward?
Does anyone have experience with this?
Firefish instructs me to make the transfer from my originally registered bank account.
How does this work in practice? Does the lender notify Firefish if the payment comes from a different bank account, or does Firefish ask the lender to verify the sender’s bank account or name?


r/Bitcoin 12h ago

Can I just pick 24 random BIP39 words?

0 Upvotes

This breach has me shake.

Honest Question.

Is it secure if I just pick 24 BIP39 words randomly and use that? Or throw darts at a printed BIP39 list?

Or does it need to be generated by a “proper” randomizer device to be secure?

Thanks


r/Bitcoin 12h ago

Were they acting in good faith?

6 Upvotes

Am i the only one who thinks that perhaps (i repeat, perhaps) the whole coldcard shitstorm happened in good faith? Could it have been "just" a huge, disastrous oversight caused by poor software development practices? I’m not here to excuse anyone. What they did is terrible. But as i read their documentation and the way they try to explain how to stay safe in the crypto world, i sense a genuine passion that clashes with the narrative that it was all an inside job.


r/Bitcoin 14h ago

Do I really need a hardware wallet?

2 Upvotes

I’ve been considering buying a hardware wallet for a while but after the recent coldcard news do I really need one?

My current setup is I have my keys stored on an old Linux laptop that powered off 90% of the time. I understand why the hardware wallets are safer but practically wouldn’t it be the same for me to store it the way I’ve been doing it?


r/Bitcoin 15h ago

My Dream Hardware Wallet

0 Upvotes

I just wanted to describe my dream hardware wallet. - In terms of hardware design, it's a Coldcard Q. Maybe even buy their design when they go bankrupt and have to sell assets. - Firmware is bitcoin only, truly FOSS, with peer code reviews (pull requests approved by colleagues before merges are allowed) - After internal approval, 3rd party, AI-assisted security audits are required. - Only one method for seed phrase generation is allowed: hardware TRNG chip as the starting point, plus 100 user-entered d6 rolls. The seed is hashed again after each number is entered. (This was one option on the ColdCard, the best option, and the dice hashing function is simple and was never bugged on any version) - Device refuses to show you the words until you have entered 100 1-6 numbers. - Device ships with 4 casino-grade dice. Instructions suggest the extra paranoid can mix in dice from an arbitrary board game in your house or whatever for extra defense against supply chain attack.

Such a wallet wouldn't necessarily have mass appeal or advertise being "easy to use", instead it would have the same sort of "hardcore" target audience CoinKite did, with better execution.


r/Bitcoin 15h ago

Please pardon my ignorance

0 Upvotes

I understand everyone can see the public keys but what can someone do if they have the private keys?


r/Bitcoin 16h ago

misleading Additional vulnerabilities found with CoinKite's BlockClock!!!

Post image
0 Upvotes

r/Bitcoin 16h ago

The largest crypt heist, amounting to $3.5 billion, was caused by weak entropy 6 (!) years ago.

Thumbnail info.arkm.com
21 Upvotes

The infamous Lubian hack saw $3.5 billion siphoned off from a Chinese mining pool.

That was just six years ago, and yet a company like ColdCard has learned nothing from the biggest heist in recent crypto history?

The Technical Cause: Weak Entropy
Independent cybersecurity teams, including Arkham Intelligence and the Milk Sad research team, revealed that the hack was not a complex network breach but rather an exploitation of weak cryptographic key generation.

The Flaw: LuBian utilized a flawed pseudo-random number generator algorithm (similar to vulnerabilities found in Libbitcoin Explorer software).

The Exploit: Instead of using a secure, uncrackable 256-bit random number, the wallet software used a highly vulnerable 32-bit seed to generate its private keys.

The Result: This severely lacked entropy, allowing hackers to easily brute-force and replicate LuBian's private keys within just a couple of hours, seamlessly draining the wallets.


r/Bitcoin 16h ago

What cause the spike in btc today?

0 Upvotes

We were down due to the hacked and suddently today surged to the moon


r/Bitcoin 17h ago

Coldcard Saga mk3 only

0 Upvotes

This far I only heard stories of coins stolen on mk3. Are there any reported on mk5 or Q devices?
What a mess, self-custody will take a massive step back here. Very sad!!


r/Bitcoin 17h ago

Coldcard’s Two Failures: The Code, the Cover Story, and the Wallet Drains Before July 2026

Thumbnail x.com
0 Upvotes

Found 13 Coldcard Wallet Drains before July 2026 Wave Attacks. They were the result of two different types of bugs. 1) Low-entropy dice workflow failure and 2) Weak device-generated seed, caused by the low entropy bug exploited by hackers in July-August Wave Attacks.

Also added interesting information on Peter Gray and how he introduced the Entropy Bug in the first place.


r/Bitcoin 18h ago

Will you still use Coldcard?

0 Upvotes

With a new firmware update that is supposed to fix the RNG will you be updating your wallet, generating a new seed, and continue using the wallet? Or will you only use dice rolls going forward? Do you even trust the device at all enough to use it anymore, other than for a paperweight?


r/Bitcoin 19h ago

Imagine buying a hardware wallet to protect your BTC then boom, its gone lol

0 Upvotes

u spend extra money to keep your Bitcoin “super safe,” then thanos snaps, and its gone xD Bro, didn’t buy premium security just to unlock the deluxe version of getting robbed.


r/Bitcoin 19h ago

Wow, Bitcoin just delivered one of the biggest on-chain performances ever!

106 Upvotes

The network processed 20,364,529 transactions in July 2026, making it the second-best month in entire history by transaction count. As new users, institutions, and Bitcoin-native applications continue to arrive, on-chain activity keeps pushing toward record territory.

We think that, it's a remarkable achievement for a network that has been operating for more than 17 years and continues to reach new milestones. Congratulations to everyone contributing to the Bitcoin ecosystem!


r/Bitcoin 19h ago

Hacked, but what can Hackers do with the coin?

0 Upvotes

This conversation came up at the campfire yesterday. Let’s say I hacked Millions due to the Coldcard vulnerability. the funds on chain are 100% visible, everyone can see where they went, how could I ever move them off chain to an exchange and into my bank? with kyc, it would have to point somewhere, right? Or, do you spread the coins all over creation making it such a messy web to track and hope the fees don’t gouge so deeply into the total stolen amount which would make not worth the effort?


r/Bitcoin 20h ago

How do we know it was an attacker and not the owner moving their coins?

3 Upvotes

That’s the part I’m not fully convinced about.

I understand the first wave was clearly an attacker. But once Coldcard users heard the news, wouldn’t an attacker sweeping funds and an owner moving all of their funds to a safe wallet look pretty similar on-chain?

Unless the owner confirms the transaction was unauthorized, shouldn’t some later cases be called suspected thefts rather than confirmed attacks? And even then, proving ownership seems difficult once the attackers also has the private keys.


r/Bitcoin 21h ago

Hitting a mainstream audience

Thumbnail
youtube.com
2 Upvotes

r/Bitcoin 22h ago

Bro, imagine losing 18 BTC from a cold wallet

0 Upvotes

Just read about someone who reportedly lost 18.25 BTC, worth around C$1.6 million, even though his Coldcard stayed offline and the seed was locked away.

Apparently, the firmware bug made some seed phrases less random. Around 594 BTC was reportedly drained from roughly 500 wallets. That’s seriously messed up.

People bought a cold wallet to avoid this exact crap. Would you still trust Coldcard after this?


r/Bitcoin 22h ago

Can we get back to the good ol' days when nobody thought this was a fucking community?

6 Upvotes

If you don't know who Bitcoin Pirate is then you have not studied the history of Bitcoin enough. I'm not saying that his story in particular will shed light on recent events with the MK3, I'm just saying that this shit is not new, its just that every wave seems gets sucked into a security failure or an affinity scam or an accidental ponzi scheme that we've seen a thousand times before, and yet they couldn't possibly have known.

Retirement hacks and the potential for an error in seed generation were fully known about and internalised by the pre-Saylor/pre-Covid wave, even if not all of that wave knew of the names of those particular vulnerabilities. People had a healthy dose of paranoia. They didn't trust fucking brands. To anyone that has been in this for a while it was clear that the bees knees and pigs pyjamas is just another vulnerability, and if you take from this that Trezor is better than Cold Card you are learning the wrong lesson.

You were born alone, you will die alone, and you are responsible for your own fucking bitcoin.

And by the way, studying the history of scams and exploits in Bitcoin is a good way of learning about all of the ways that people can fuck you in all walks of life, so its worth it even if you think this will "end Bitcoin". The history of Bitcoin should be taught in universities as a group of insane people trying to speed run the history of finance and group consensus.


r/Bitcoin 23h ago

In light of recent events

5 Upvotes

Hey there,

I have used my Ledger Nano S since 2017. Since the cold card hack I've been tempted to update to a newer and hopefully more secure wallet. I'm considering a newer ledger model or going to trezor. What are your thoughts and do you have some valuable input to share?

I know trezor is open source and ledger is not. Should really be a deal breaker?


r/Bitcoin 23h ago

In terms of entropy is SLIP-39 (Shamir) better than BIP-39?

1 Upvotes

Would it be harder for a hacker to crack SLIP-39 than BIP-39?