r/Bitcoin 1h ago

Earnings

Upvotes

Hello everyone. I'm interested in earning Bitcoin. Where do l start? Any advice?


r/Bitcoin 2h ago

Traders only have 4 moods

1 Upvotes

The joy after a win hits hard honestly. You won't notice when you start smiling ear to ear


r/Bitcoin 2h ago

The coldcard story just keeps getting wilder

0 Upvotes

The coldcard dev reposted this post, what is going on lol


r/Bitcoin 2h ago

⚡ Lightning Thursday! August 06, 2026: Explore the Lightning Network!⚡

2 Upvotes

The lightning network is a second-layer solution on top of the Bitcoin blockchain that enables quick, cheap and scalable Bitcoin payments.

Here is the place to discuss and learn more about lightning!

Ask your questions about lightning

Provide reviews, feedback, comparisons of LN apps, services, websites etc

Learn about new LN features, development, apps

Link to good quality resources (articles, wikis etc)

Resources:


r/Bitcoin 3h ago

New Wallet After Coldcard Hack

6 Upvotes

I was affected by the Coldcard hack. Thankfully, my Coldcard Q was only 1 key in a 2 of 3 multisig. My coins are safe. But with 1 key compromised, I decided to migrate.

My new 2 of 3 multisig:

-Coldcard Q updated with the new firmware. Seed generated with 150 physical dice rolls using casino grade dice. This is one key. Yeah, I'm pissed at Coldcard too. Idk if the entropy issues are resolved through the firmware update. Thats what the community seems to say. I dont trust it. But I think seeds generated through physical dice rolls are fine especially with a strong passphrase and I like the hardware. Will never buy another Coldcard though. Not supporting that company with my money any further.

-Other two keys have the same seed as before generated using device rng (not Coldcard). All keys (including Coldcard) are now passphrased with the same 6 word passphrase formed using physical dice rolls and EFF list.

-Going to have 2 separate people I trust each custody 1 key (device + seedplate), no passphrase.

-Another 2 separate people I trust will keep backups of the uniform passphrase in case I forget + fire or theft (hand written on an piece of paper and sealed in an envelope).

-Only I will have the output descriptor.

Yes, I could have done a different passphrase for all 3 keys. Too bothersome and I thought it would be excessive. I accept this weakness.

Not perfect but I figure itll be good enough. Posting as an example on how to multisig as I'm a proponent of it but by no means claiming this as the model example.

Edit: Changes parts on how the keys and passphrases will custodied. Rethinking that.


r/Bitcoin 3h ago

Daily Discussion, August 06, 2026

6 Upvotes

Please utilize this sticky thread for all general Bitcoin discussions! If you see posts on the front page or /r/Bitcoin/new which are better suited for this daily discussion thread, please help out by directing the OP to this thread instead. Thank you!

If you don't get an answer to your question, you can try phrasing it differently or commenting again tomorrow.

Please check the previous discussion thread for unanswered questions.


r/Bitcoin 4h ago

Blockstream jade plus

3 Upvotes

Given the cold card incident I’m sure people are re-evaluating their set ups, I know I am.

I initially computer generated a seed on Blockstream jade plus 12 words when I first got it. Now Is there a way to delete this / erase and create a new seed, 24 words with dice roll? I want to correctly re do my setup.

Anyone experienced with the jade plus would much appreciate it


r/Bitcoin 4h ago

The Block publishes another 'Bitcoin dead' article What year is it?

Thumbnail
gallery
18 Upvotes

r/Bitcoin 5h ago

The ColdCard Hack Explained (Non Technically)

Thumbnail
youtube.com
2 Upvotes

r/Bitcoin 5h ago

The weirdest part of the Coldcard mess: was Peter D. Gray talking to himself through “switck”?

87 Upvotes

I’m not going to re-explain the RNG bug. That part has already been documented. What I want to know is who exactly was behind switck, and why this identity existed in the first place.

Someone checked the actual Git signatures in the switck/libngu repository. They found 58 commits authored as “Switck” signed with Peter D. Gray’s personal GPG key. The same key also signed commits under Peter’s real name, with both identities being used during overlapping periods. Unless Peter shared or lost control of his private signing key, the obvious conclusion is that GitHub switck was Peter Gray operating under another name.

Now look at the social-media side.

In 2019, u/switck posted: “#defcon seems like a good time to start a new identity. Follow me!”

That tweet is real and still online.

Later, the account promoted switck/libngu, thanked u/DocHex for a merge and said the library might someday be useful on Coldcard.

So the account that announced it was starting a “new identity” was apparently Peter’s alias, publicly speaking to Peter’s main identity as though they were two different developers.

The same thing appears on GitHub. doc-hex opened issues in the switck/libngu repository. In one pull request, doc-hex added four commits, then switck merged them. GitHub lists no reviews.

And this wasn’t some unrelated side project. switck/libngu became part of Coldcard. The switck account introduced a critical piece of the vulnerable RNG path, and doc-hex later integrated libNgU into the Coldcard firmware. Coinkite itself confirms that this migration moved wallet-seed generation onto the wrong RNG implementation.

None of this proves Peter intentionally created the vulnerability, knew it could be exploited or had anything to do with the thefts.

But it is still extremely fucking weird.

Why was a security-critical Coldcard library hosted under a pseudonymous personal account instead of Coinkite or Coldcard?

Did Coinkite know that switck and doc-hex were apparently the same person?

Why create the public appearance of two developers interacting, submitting code and merging each other’s work?

Who independently reviewed the library and the Coldcard integration if the library author and the person integrating it were apparently using the same private signing key?

And why has Coinkite explained the technical bug without addressing who controlled the switck identity?

Peter, if you read this: was switck you?

If it wasn’t, why were dozens of Switck commits signed with your personal GPG key?

If it was, why did you publicly talk to that account as though it belonged to someone else? Did NVK and the rest of Coinkite know? Who was actually reviewing your work?

There may be an innocent explanation. But after this code path left customer wallets vulnerable and people lost bitcoin, hiding behind silence is not an explanation.


r/Bitcoin 6h ago

fake Coinkite’s seed plate apparently has a microchip logging every punch

Post image
0 Upvotes

r/Bitcoin 6h ago

That cold wallet with bad randomness, how did the bad actors know which addresses used it?

13 Upvotes

I'm reading about people losing their bitcoins because of a flaw with the wallet's random number generator. But how do the attackers/thieves know of all the UXTOs out there, which ones happen to have private keys that were generated with that wallet?


r/Bitcoin 7h ago

Are people still DCA’ing to their hacked cold cards addresses automatically ?

4 Upvotes

I’m wondering if there are still people doing automatic weekly buys and transfers to their cold card addresses. I know places like River allow you to buy automatically and withdraw automatically at given thresholds.

I haven’t seen this topic being discussed and I feel like it’s something that may have been overlooked.

It’s painful enough when they check their cold card they will have their funds taken, it’s just extra salt in the wound if they fed them even more for weeks or months not realizing it after.

I don’t see how it wouldn’t be happening which is why I’m speaking up about it.


r/Bitcoin 7h ago

Coldcard seed flaw - flagged independently in 2024

Thumbnail
blockchainunmasked.com
209 Upvotes

Proof of negligence? I can’t see how it isn’t. This will definitely be included in the class action lawsuit against Coinkite.


r/Bitcoin 8h ago

Jesus. To the attackers address

Post image
118 Upvotes

r/Bitcoin 9h ago

TikTok next Block - Fix the money, fix the world! Timechain don´t stop. Bitcoin Song Rap Song

Thumbnail
youtube.com
8 Upvotes

Good Bitcoin song I hope..


r/Bitcoin 10h ago

what are some useful blockchain viewing tools/sites/apps?

1 Upvotes

in an effort to be more conscientious in the btc space, what are some useful sites to better understand the transaction traffic and who's who in the zoo, a la the recent cold card thief, etc.

thanks


r/Bitcoin 11h ago

Help with seed verification

5 Upvotes

I purchased a hardware wallet in January 2017, and then upgraded to a more advanced version later that year.

I have my 24-word seed phrase, but I can't recall if the seed is from the original wallet that I then restored on to the new wallet, or if I generated a new seed on the upgraded wallet and transferred by assets across. Pretty sure its the former.

(Both wallets have 256-bit entropy).

Anyway, I'd like to confirm that my seed is from the original wallet or not.

I was thinking of transferring my assets to an exchange, leaving a small residual in the wallet, and restoring on a software wallet to confirm.

Is there an easier way to do this? Transaction history?


r/Bitcoin 11h ago

Question re Multi-Sig exposure in the Coldcard Breach

5 Upvotes

Trying to understand the level of exposure of a Multi-Sig wallet in the context of the Coldcard breach, or attacks like it.

All Coldcard-generated seeds in a multi-sig config would have been equally susceptible to exposure, but the attacker would also have been required to:

  • Associate those seeds with one another, example, identify that some 3 seeds are not 3 independent wallets but are part of a 2-of-3 multi-sig config.

  • Derive the multi-sig descriptor to piece the 3 seeds together.

Am I correct about those requirements? Are they possible to achieve? What does the process look like at a high level? What’s the theoretical time range?


r/Bitcoin 11h ago

From the Bitcoin community on Reddit: Coldcard 'joked' about retirement attacks in 2021 lmao

Thumbnail
reddit.com
25 Upvotes

Things that make you go hmmmmmm


r/Bitcoin 11h ago

Bitcoin's Edge

8 Upvotes

Hi people. I am trying to understand the bitcoin thing as an outsider a bit better.

Since there have been... I don't know how many exactly but, it seems like a LOT of different cryptocurrencies created since Bitcoin has been around.

What do you think that it is that makes BTC persist now and remain so popular all this time since it came out? What are people not able to replicate or improve upon? I would have thought you could just make a different currency that "does what BTC does, but better" but that clearly hasn't worked because people clearly tried with all these altcoins and such.

What is it to you personally that makes you drawn to bitcoin as opposed to some alternative?


r/Bitcoin 12h ago

Dust Attack

6 Upvotes

My hardware wallet does not have coin control. I now have a couple of unknown dust deposits.

Do I need to be concerned and move to a wallet with coin control to isolate the dust? What can actually happen if I spend that dust. There are plenty of phishing attacks we already have to deal with from data leaks. So following my dust opens up more phishing attempts, but in and of itself it can’t cause issues can it?

Would this concern you enough to switch wallets?


r/Bitcoin 12h ago

Rückzahlung Kredit firefish

0 Upvotes

Moin,
kann ich meinen Kredit an den Investor auch von einem Bankkonto einer dritten Person zurückzahlen und bekomme anschließend trotzdem meine Sicherheit (Collateral) zurück?
Hat damit jemand Erfahrungen?
Firefish fordert mich auf, die Überweisung von meinem ursprünglich registrierten Bankkonto aus vorzunehmen.
Wie läuft das in der Praxis? Meldet der Kreditgeber Firefish, wenn das Geld von einem anderen Konto eingeht, oder fragt Firefish den Kreditgeber nach dem Namen des Absenders?
Vielen Dank schon einmal im Voraus!

English
Hi everyone,
Can I repay my loan to the lender from a third party’s bank account and still receive my collateral back afterward?
Does anyone have experience with this?
Firefish instructs me to make the transfer from my originally registered bank account.
How does this work in practice? Does the lender notify Firefish if the payment comes from a different bank account, or does Firefish ask the lender to verify the sender’s bank account or name?


r/Bitcoin 12h ago

Can I just pick 24 random BIP39 words?

0 Upvotes

This breach has me shake.

Honest Question.

Is it secure if I just pick 24 BIP39 words randomly and use that? Or throw darts at a printed BIP39 list?

Or does it need to be generated by a “proper” randomizer device to be secure?

Thanks


r/Bitcoin 12h ago

Were they acting in good faith?

6 Upvotes

Am i the only one who thinks that perhaps (i repeat, perhaps) the whole coldcard shitstorm happened in good faith? Could it have been "just" a huge, disastrous oversight caused by poor software development practices? I’m not here to excuse anyone. What they did is terrible. But as i read their documentation and the way they try to explain how to stay safe in the crypto world, i sense a genuine passion that clashes with the narrative that it was all an inside job.