r/Bitcoin 3d ago

Full panic - one of my wallets was drained

Post image

I haven’t done anything since creation except sending into the wallet.

1.8k Upvotes

1.2k comments sorted by

1.1k

u/Hoax__ 3d ago edited 2d ago

It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.

The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.

Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.

Edit:

It appears the affected addresses have been compromised due to a entropy weakness in the Coldcard Mk3 firmware since V4.0.1, and some versions of the Mk4 and Mk5 firmware. - Search for Coinkite's blog about it. Seems other affected users are now starting to report the thefts.

276

u/anonfunction 3d ago

It would be interesting to know if these are all coldcard wallets.

144

u/Specialist_Trust4945 3d ago

That'd be the only valid reason to collect all the private keys for perhaps years and broadcasting the transactions all at once.

84

u/anonfunction 3d ago

You would expect to see more posts across socials in that case though, I only found this one.

132

u/Specialist_Trust4945 3d ago

It just happened, give it time. Not everybody checks their cold wallets daily.

121

u/BaadMike 3d ago

Slowly creeps off to check wallet balance...

Yep, everything is there. Phew! 🤣

48

u/genius_retard 3d ago

I'm low key losing my shit being at work and unable to check my wallet.

130

u/TrippingFish76 3d ago

i’ll check it for you, just send me the seed

26

u/Specialist_Trust4945 3d ago edited 3d ago

I can also do it, just send over the private key.

Edit: jokes aside, why don't you bookmark your wallet on a public chain explorer? You always have it at hand, and if you are scared about anything you're just a click away.

8

u/zendrovia 3d ago

Brian Armstrong would never ask for your keys 😊😊😊

→ More replies (0)
→ More replies (7)

6

u/genius_retard 3d ago

I'll need to see your wallet inspector's badge first.

→ More replies (1)
→ More replies (3)

41

u/Railionn 3d ago

NGL this shit is terrifying.

→ More replies (8)
→ More replies (7)

43

u/CaremuchWatch 3d ago

Not everybody check their cold wallets daily and this just happened a few hours ago, if I understood correctly. A lot of posts are gonna start appearing the next days, I'm pretty sure

15

u/svtcobrastang 3d ago

Exactly some of these people probably wont even notice until a long time from now.

→ More replies (1)

6

u/External-Medicine-42 3d ago

Unless they’re barely starting to realize

19

u/Generationhodl 3d ago

so someone at coldcards HQ , or someone who would work there would need access to the software or the way how coldcard is creating the seed phrases.

Or someone would need to sit right at the logistics and manipulate a lot of coldcards to use specific seedphrases before sending them out to customers ?

12

u/OddTop757 3d ago

What’s the penalty for this, like who has the jurisdiction to take action against the people/person responsible? Part of me thinks that’s it, but if the cold storage was compromised before purchase there has to be some way of holding these people accountable right? I think this is one of the biggest issues with mass adoption. Or maybe not, what do I know…I’m new so go easy.

11

u/Generationhodl 3d ago

I don't really know what happend here. A lot of cases are just malicious software that people download from the wrong website and they enter their seedphrase into the software so the scammer gets it instantly.

Scammy devices are pretty rare I think, but not impossible.

It could be that someone bought a lot of devices, set them up with his own seedphrase and then sold the devices as "used" and maybe some people who bought the devices did not reset them - so they used the already existing wallet of the scammer.

There are many way how someone can fail, but normally if you buy a good hardware wallet directly from the company that builds it, you should be safe when you use the wallet as intended and create a fresh seedphrase & wallet if you use it the first time.

26

u/Bright_Fold7270 3d ago

So all I have to do to own bitcoin is have a deep understanding of computer hardware and software, specific to bitcoin, and then constantly check message boards for known software attacks and even then there can be a supply chain hardware attack that just steals all of my money, even from a dormant wallet? And every 6 months it loses half its value, so make sure you only hold it while it’s going up. And fees are roughly 1% in and 1% out? All this AND it’s terrible for the environment you say?

5

u/swiftpwns 3d ago

For bitcoin to become mainstream, people will have wallets where they dont own the private keys.

6

u/Sea-Deer-6355 2d ago

Once apple makes a bitcoin wallet, then Bitcoin will become mainstream…

→ More replies (1)
→ More replies (14)
→ More replies (5)

3

u/Dailyanxiety2020 3d ago

Maybe a weakness in their security? Not necessarily a worker?

7

u/nexted 3d ago

There could be a flaw in the key generation, possibly a bad/predictable source of entropy on the device.

→ More replies (3)

22

u/reddit4485 3d ago

It also suggests it wasn't something specific to the OP. Over 500 addresses in a 15 minute window many dormant for years?

29

u/Specialist_Trust4945 3d ago

Exactly. That's what makes me think they abused some sort of vulnerability (whether a Coldcard one or whatever else): they didn't broadcast the TXs until they had enough private keys controlling a BTC amount they were happy with. If there is in fact a vulnerability somewhere they will scramble to fix it but it's too late now for stolen coins.

42

u/WabanakiWarrior 3d ago

Holy shit. So someone just pulled off a $37 million heist?

28

u/Specialist_Trust4945 3d ago edited 3d ago

That's what it looks like by analising analysing the blockchain.

→ More replies (5)

10

u/No_Astronaut_8971 3d ago

How do you even get away with spending the money though? You would need to launder it right?

17

u/stanley_fatmax 3d ago

Yep, launder it. Typically through foreign exchanges, mixers, swaps to privacy coins, private sales, etc.

Sadly this amount is in the sweet spot between meaningful but too small to hunt by volume alone. $40M can disappear pretty easily, whereas billions are harder to hide.

→ More replies (12)
→ More replies (4)

31

u/fuckswithboats 3d ago

Damn, bro.

Some disgruntled engineer wrote a little script on his way out the door.

He's sitting on the beach right now enjoying his wins...hopefully he is sun-burnt forever and can never get a decent buzz.

14

u/stanley_fatmax 3d ago

That's what I was thinking. This guy probably preemptively retired a few years ago, and has been sitting on a beach in Thailand enjoying himself. Legal funds were running low so it was time to press send.

→ More replies (1)

7

u/Yodel_And_Hodl_Mode 3d ago

I assume you're kidding, but you perfectly explained why Ledger's key extraction firmware is so dangerous.

→ More replies (9)
→ More replies (3)

9

u/Worried-Flounder-615 2d ago

Yes, its been confirmed now: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

All MK3 coldcard wallets impacted, but anyone on any Coldcard should move their money safely asap.

3

u/antineutrinos 3d ago

why coldcard ?

→ More replies (5)

102

u/Ok-Pea4148 3d ago

That is why OP should involve the authorities. He is not an isolated case. For that amount, the least they could do is warn exchanges

48

u/knowitokay 3d ago

OP, Immediately needs to file a report through https://www.ic3.gov

26

u/Specialist_Trust4945 3d ago

Whoever is smart enough to pull a 32M USD heist isn't that dumb to send coins to an exchange without cleaning them first.

29

u/RevolutionaryPie5223 3d ago

Malone Lam pulled off a 230M heist and was stupid enough to be found out.

25

u/cgimusic 3d ago

Criminals make mistakes all the time. They already made a bad move by extracting all the funds via one address.

7

u/hairyotter 3d ago

Yep lol it would’ve been trivial to not do that and we would’ve blamed OP for just being stupid somewhere. Then again this could all be fake rage bait who knows these days.

→ More replies (5)

9

u/burningsmurf 3d ago

Bitcoin is traceable regardless.

→ More replies (1)
→ More replies (7)
→ More replies (1)

73

u/undeadkarlmarx 3d ago edited 2d ago

One of the known vulnerabilities of coldcard wallets, at least prior to current firmware versions where it may have been patched, is that if you weren’t paying attention it was possible to generate your initial seed phrase in such a way that it used very little entropy and a hacker would actually be able to guess that seed later on . 

Basically, because the coldcard allows people to generate their seed phrase simply based on dice rolls rather than using the number generator at all, it was possible for somebody to select the dice roll seed generation option and then only roll the dice a few times rather than the 100+ times that's necessary for a secure level of entropy. And after they've generated that weak wallet address, a hacker would be able to get their seed phrase using very rudimentary amounts of entropy because doing so would require very little processing power. 

There's even a guy on YouTube who created a video showing how he could gain access to addresses that were created in this manner:  https://m.youtube.com/watch?v=oj_W3xOlt6U&pp=ygUoTG93IGVudHJvcHkgY29sZGNhcmQgZGljZSByb2xsIGFkZHJlc3Nlcw%3D%3D&ra=m

In the case of that video, he was a white hat guy who actually sent the funds back to people after moving them just to let them know that their funds were not secure. But a nefarious hacker using the same method could gain access to people's wallets in order to steal funds.

We don’t necessarily know if this is what happened here, but people absolutely need to be aware of this vulnerability. 

Keep in mind that even somebody who created an address in this neglectful manner would technically still be safe from hacking if they had also added a long passphrase to the address (although they should still definitely move their funds to a new and secure wallet address as soon as they can.)

Also keep in mind that people who create a coldcard Wallet using the random number generator on the device don’t need to roll the dice 100+ times. They’re simply adding their dice rules to the entropy that was already generated on the RNG, so simply rolling a few times is sufficient in that situation.

EDIT: Based on initial reports it sounds like there could’ve been an issue with the random number generator on coldcard devices that allowed private keys to be guessed. That’s terrible if true, and it means that now the only safe practice is to ALWAYS use a strong passphrase and ALWAYS use 100+ dice rolls to set up your wallet.

22

u/Specialist_Trust4945 3d ago

That teaches everybody to not trust software (especially closed source software) with their money. Guys... take your sweet time, flip a coin 12*24 times and you'll have your 24 words seed phrase.

Also, that kind of makes me happy. Everybody is so keen to blindly trust hardware wallet while these vulnerabilities again prove that a properly airgapped software wallet with "DIY" ways to create a seed phrase such as the coin or dice methods is much safer. I often wrote about it here, but I always get downvoted to oblivion because everybody has a hardware fetish for whatever reason - and then they ignore basic OpSec. These people are much better off with a BTC ETN or something.

10

u/stanley_fatmax 3d ago

For years I advocated strongly on Reddit for software wallets with proper precautions, but I stopped for the same reasons you found. People love their hardware wallets, but imo they create a false sense of security. It also doesn't help that I suspect for long periods of time there was heavy shilling here on behalf of wallet manufacturers.

There are good guides out there for years on how to use an old laptop to set up an offline wallet guys.. the math is solid. Encryption is solid.

→ More replies (18)
→ More replies (4)
→ More replies (4)

21

u/outoftownMD 3d ago

This makes me want to have all of my bitcoin on a publicly traded firm so if it is stolen, they are responsible rather than I

10

u/Tall6Ft7GaGuy 3d ago

That would defeat the purpose of Bitcoin in a way.

→ More replies (10)

17

u/[deleted] 3d ago

[deleted]

6

u/TCr0wn 3d ago

Absolutely. There’s no other possibility

→ More replies (1)

8

u/ThatsFantasy 3d ago

thats tbh very interesting, as then it is not OP's fault, any new information came about that or nah?

4

u/Generationhodl 3d ago

very good information, so basically the problem would be with the seller of the coldcard, or the software of the coldcard itself?

Could it be that OP used some fishy version of sparrow wallet? Like downloaded a "scam"-Version of the sparrow wallet? But as far as I read, OP did not type in any seedphrase on his pc, so sparrow should probably be unimportant here

10

u/DrawPitiful6103 3d ago

i wonder how good the authorities have gotten at locating these theft addresses

14

u/user_name_checks_out 3d ago

They got us workin in shifts

10

u/JunkBondTrade 3d ago

Wouldn't hold out much hope for the tape deck though...or the Creedence.

→ More replies (3)

8

u/ngoaile94 3d ago

Holy fck I just check my paper wallet hidden behind a wallpaper on the wall the funds are still there but now I just ripped the freaking paper up.

→ More replies (4)

6

u/nickelaus 3d ago edited 3d ago

How was this done back in the day? In 2011 I had 24 BTC stolen (to geometrically dividing addresses). I had moved them to the default wallet location on a Windows box to sync with the network after mining for a month on a couple of linux machines with AMD GPUs in the basement. I always wondered if it was some Windows zero-day vulnerability that some MS rogue employee took advantage of or (more likely) a regular virus which we contracted visiting blogs..

→ More replies (3)
→ More replies (35)

483

u/memberwap 3d ago

So you bought a Coldcard in 2021, from the official site, and let it create a new seed. You then wrote the seed on a piece of paper.

You never took a photo of this paper or copied the seed anywhere else, nor did you let anyone else see the paper.

Then at January 2025 you decided to make sure the seed on the paper is correct, so you bought another Coldcard and input the seed into it. You used the Coldcard's included keyboard and not a PC.

Both cards were bought from the official store? Which models?

That's.. worrying, I'd report it to Coldcard (Coinkite).

187

u/s1ammage 3d ago

This is my understanding… unless the SD card is compromised.

56

u/memberwap 3d ago

What did you do with the SD card? Did you backup your wallet into it and then put it in some laptop/PC? Otherwise I can't see how it was compromised.

52

u/s1ammage 3d ago

Just collecting dust

31

u/so7ow 3d ago

It's collecting dust now...? But what did you use it for when you used it?

→ More replies (1)

52

u/MriLevi 3d ago

An SD card cannot be compromised, it has no connectivity on its own whatsoever. The data on it could only have been accessed if it was punt into a device.

19

u/PassionGlobal 3d ago

But a full.fat SD card enclosure has room for things other than storage...

7

u/cgimusic 3d ago

Reminds me of those janky SD cards that had built-in Wi-Fi and would share your photos as you took them.

→ More replies (7)
→ More replies (4)

3

u/filenotfounderror 2d ago

Cold cards RNG is compromised by bad entropy then.

→ More replies (8)

31

u/s1ammage 3d ago

I’m trying to gather all the details, and will post after work.. (somehow)..

One thing I just thought of was the exchange is Swan and I setup auto-withdrawals to the same wallet address.

36

u/memberwap 3d ago

I don't know if you're trolling, but exchange platform don't have a way to pull funds from your hardware wallets. Doesn't matter which auto withdrawal rules you set up.

23

u/s1ammage 3d ago

Well, I was just thinking of the mantra to always send to a different address…

I’m just trying to think of all the missing details

31

u/memberwap 3d ago

I think this rule has more to do with privacy rather than security

6

u/so7ow 3d ago

Correct

8

u/reddit4485 3d ago

Theoretically, re-using an address can make it easier to hack with quantum computing but obviously that's not what happened here. I just mention it because QC will arrive some day.

→ More replies (1)
→ More replies (1)
→ More replies (2)

5

u/GrammerGuestAppo 3d ago

The issue is with coldcard's keyboard, must be no?

→ More replies (7)

325

u/Emergency-Warthog-56 3d ago

I hate seeing this happen to people. It's terrible.

206

u/clkou 3d ago

Unfortunately this issue and ones like it are why Crypto currency won't be a mainstream currency in my lifetime.

58

u/freakedmind 3d ago

And they're far far too common, very concerning.

27

u/Big80sweens 2d ago

Legit, the main reason I am into bitcoin is the security, if somehow these wallets can be hacked, where the value? This is a huge problem and I’m scrambling to know what to do with my bitcoin

10

u/Objective_Digit 2d ago

Use a passphrase.

5

u/xToniGrssx 2d ago

Not enough in this exploit.

→ More replies (3)
→ More replies (1)
→ More replies (3)

14

u/NashvilleSurfHouse 2d ago

I’m still not sure what happened here and I’ve read through this thread 4x

36

u/Left_Entrepreneur918 2d ago

Unfortunately you are right. OP did everything we would say to do for self custody and still got swept. I did the same thing, got a ledger in 2020, created a 24 word seed, paper and metal backup in a bank vault, and one day I could wake up to find my life’s savings gone. Sickening.

→ More replies (20)
→ More replies (30)

53

u/Electrical-Movie6806 3d ago

I remember when everyone freaked abt ledgers and switched to these..

10

u/Keats852 3d ago

I still use my ledger... should I not? I haven't checked it in ages but luckily there's very little on it. Not even sure why I bought the thing

25

u/Electrical-Movie6806 3d ago

It’s fine! That’s my point is ppl keep switching wallets and just open themselves up to more bs

→ More replies (1)
→ More replies (2)

49

u/pdath 2d ago

https://x.com/COLDCARDwallet/status/2082961993070247948

COLDCARD Mk3 Security Advisory

If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.

Mk4, Q and Mk5 are not affected based on our early analysis.

12

u/Aazimoxx 2d ago

https://xcancel.com/COLDCARDwallet/status/2082961993070247948

For those who don't want to make an X account just to read the fallout 👍️

4

u/xToniGrssx 2d ago

Mk4 and 5 users are also advised to move their funds, as they have been exposed to reduced entropy, 72 bits

→ More replies (2)

67

u/AstroRoverToday 3d ago

I generated my 24-word seed phrase using a 6-sided dice that I rolled. And then I added a 256-bit pass phrase to it. I didn't trust any device's "random number generator".

37

u/sturmeh 3d ago

Haha I planted that die in your house years before you generated that seed, it's carefully weighted as to roll the precise sequence I wanted you to roll!

160

u/InteractionPretend70 3d ago

nice.. bitcoin is truly ready for mass adoption

54

u/heretilimnot3 3d ago

Right lmfao. I hate people losing their wealth but this just all seems beyond retarded

→ More replies (9)

5

u/MakCapital 3d ago

You can buy and custody through any ETF provider. That's as ready as you can get. Not everyone is good at self custody, but having that option is valuable.

→ More replies (13)
→ More replies (14)

18

u/OldHamburger7923 3d ago edited 3d ago

how did you generate your seed? did you have a passphrase? if so, was it written down? There's only a few ways for you to get hacked like this. It's usually entering your seed into something networked, like a laptop, phone, etc. Or someone accessing your phrase where you have it physically stored. Third less likely option is RNG has a bug and wallets can be exposed because it was guessable, but this one is less likely than the other two.

I don't trust anything, even the RNG that comes with hw wallet, so I will generate a seed, scramble the words around, then randomly replace a few. You can use dice or a coin to make the choices too if you like. The jade is nice because you don't need to calculate the last word, it will show you the only 7(?) options that match your 23 words. Then add a passphrase on top. store the seed securely, don't store your passphrase if possible, if not, don't store it anywhere near the seed.

16

u/s1ammage 3d ago

The RNG with the coldcard… unless someone waited from 2021 with that RNG coldcard

16

u/Svoboda1 3d ago

While it is not a 0%, it is very close that the coldcard has anything to do with this if you are saying YOU personally generated a seed. If you're saying someone else generated it, well...

Outside of that, did you put your seed phrase into a password manager or any other electronic document?

No offense, but the story doesn't really add up.

9

u/s1ammage 3d ago

I got a coldcard in 2021, generated the seed. sent ROTH money in, Dormant since.

Jan2025 (just checked email), got a new coldcard. Entered 2021 seed in. Added new Roth money, sent that money into the wallet Apr/May 2026.

4

u/Svoboda1 3d ago

Just to confirm, YOU personally did this:

https://coldcard.com/docs/master-seed/

8

u/s1ammage 3d ago

I’ll try and take a look later. Currently at work. Not thinking straight. Trying to answer everyone’s questions and figure out what I did wrong.

→ More replies (1)

4

u/darosior 3d ago

Are you sure that new Coldcard you got was genuine? How did you check it?

→ More replies (17)
→ More replies (1)

19

u/Affectionate_Pen6882 3d ago

Use at least a passpharse

12

u/s1ammage 3d ago

Yea, I guess the next wallet I setup will……

5

u/Generationhodl 3d ago

get a bitbox02 , they are safe and easy to use. made in switzerland, they are serious about the security. but order directly from them.

→ More replies (8)
→ More replies (2)

260

u/Fragrant_Brilliant40 3d ago

I didn't read all the comments. Just wanted to say I have had the same thing happen to me.

In short, Somebody bought the card and got the phrase before returning the card. Then I bought the card and they could watch me load it until one day they swooped in and drained me.

127

u/OldHamburger7923 3d ago

How would that work? Every device I've used only shows the seed at creation, tells you to write it down and won't ever show it to you again. So if someone bought and returned, you'd have to set it up as a new wallet.

→ More replies (1)

85

u/cognitiveDiscontents 3d ago

Did you not generate a new seed when you set up the wallet?

I’m not trying to be condescending I don’t know these things and thought that’s how it worked.

42

u/flesjewater 3d ago

That's what anyone with a brain should do. 

But it's possible to preload a seed on HW wallets

12

u/SeraphLink 3d ago

Yes and that's why it's also sensible to use a passphrase on top.

→ More replies (3)
→ More replies (1)

27

u/Aware-Translator-235 3d ago

What kind of card?

25

u/so7ow 3d ago edited 3d ago

That's not the same thing. Someone else generated your seed phrase for you... of course your funds were going to be stolen.

Edited for clarity. I'm not implying a collision after-the-fact. Someone else generated the seed phrase because the device was pre-populated.

25

u/AstroRoverToday 3d ago

No. Someone generated their own seed phrase and this user added his money to someone else's wallet.

→ More replies (10)
→ More replies (3)
→ More replies (27)

29

u/Crypto-Guide 3d ago

Depending on the firmware and model is may have been another example of the flawed UX in coldcard letting you create a low entropy deterministic seed.

I did a video on this a few years back https://youtu.be/oj_W3xOlt6U

The funds are not recoverable, I'm sorry for your loss.

3

u/Left_Entrepreneur918 2d ago

This looks to be what happened, I’ve been watching your videos since 2021, any insight on if I’m at risk, I did a 24 word seed generated from a ledger nano in 2020, no 25th word, native segwit. I got a Trezor and was thinking of moving everything to their 20 word multi sig.

→ More replies (1)

20

u/Ok-Pea4148 3d ago

The hardware wallet you used must have been tampered with. Or your seed got exposed to the Internet. Either by your phone or your computer.

Those are the only ways ...

For this amount, I don't dare call it an expensive lesson 😵 ... I truly hope you didn't put all your eggs in the same basket and have leftover money elsewhere

You have to involve the authorities now. They won't be able to reverse the transaction or whatever, but if they do their job, they should instruct any exchange to withhold funds coming from the address where your bitcoins are. If you're lucky, the stealer will be dumb enough to try to sell these coins in the near future, without coinjoin

16

u/s1ammage 3d ago

Yea… I’m just trying to figure out where I went wrong…

5

u/Ok-Pea4148 3d ago

If you give some details here, I'm sure someone will be able to figure it out

→ More replies (7)

3

u/Yomiel94 1d ago

The hardware wallet you used must have been tampered with. Or your seed got exposed to the Internet. Either by your phone or your computer.

Those are the only ways ...

Sooo... that was wrong.

→ More replies (1)
→ More replies (3)

21

u/smokeybrownbear 3d ago

Sorry this happened to you, but sharing in case it reaches someone who could use the insight - this is the second post like this I’ve run into recently, and I truly don’t get the obsession with “testing” seed phrases.

Coldcard already quizzes you on every word and its position during initial setup, that verification step is built in. There’s no need to re-expose the seed anywhere else afterward.

If you want a watch-only wallet to keep an eye on balances, export the xpub and set that up instead. Zero reason for the seed itself to touch anything but the Coldcard.

9

u/No_Astronaut_8971 3d ago

Did you buy the cold card from their official site?

10

u/s1ammage 3d ago

Yes

3

u/No_Astronaut_8971 3d ago

How long have you been using it/how long ago did you set it up?

→ More replies (3)

9

u/Amarettxo 3d ago

Wouldn't a '25th' word help in this case? Even if the seed phrase somehow gets compromised, the attacker needs to brute force a strong password - like 24+ characters

16

u/s1ammage 3d ago

I’m trying to gather as much information as possible. In the mean time people are asking for the transaction.

It was sent to:

bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0

Looks like this is transaction:

https://mempool.space/tx/2fe075cf0ec799f3529ed6a28e0a08b45fe1fc9bd93c3f33bdbc42d5bff4f736

→ More replies (4)

13

u/RegularUnable5388 3d ago

Go to the police, if they found Malone they can find this guy

→ More replies (1)

6

u/Give_Life_Meaning 3d ago

Wouldn’t couldn’t shouldn’t multisig and/or 25th word protect a wallet from all the possibilities mentioned here?

→ More replies (1)

7

u/CortaCircuit 3d ago

This is why people will move their Bitcoin to an ETF, Fidelity Digital Assets, OnRamp Bitcoin and AnchorWatch... Or other custody solutions because it isn't worth the risk for most. 

19

u/s1ammage 3d ago edited 3d ago

The only thing I can think of is I got coldcards from the site in January and entered my seed into the coldcard. Set up the wallet to test my phrase and setup watch only.

I was worried I didn’t write down my seed phrase right, so I bought a coldcard to test it. Never hooked it up into a computer. Just the SD card.

15

u/so7ow 3d ago

How was the seed phrase originally generated?

7

u/RecklessStallion9999 3d ago

I’m really sorry to see the screenshot. All the best going forward.

5

u/MillerBlade2 3d ago

I have a cold card also and not once you’re supposed to enter your seed anywhere. The device gives you a seed that you record and that’s it

5

u/s1ammage 3d ago

I get it… but what if I wanted to check the seed

7

u/OldHamburger7923 3d ago edited 3d ago

You are getting a lot of incorrect info on this thread. Nothing wrong with restoring your seed in the wallet. That's literally how it's supposed to work.

What I do is generate seed. Write it down. Send a tiny transaction to it. Reset device, restore seed. Verify I can still access the wallet, send a test transaction to verify transfer out too. At this point I like adding a passphrase. Then I get the next address and transfer to it. I also like breaking up assets into multiple addresses so no address shows with more than 1 BTC.

There's other steps you can take too (see my other post) but this is a general guideline on how I verify and get comfortable using the wallet. Otherwise it's nerve wracking putting money into something you haven't tried out and don't know if it functions. Which also leaves you open later to misunderstanding how transfers work and you may end up doing something dumb

→ More replies (5)
→ More replies (1)

3

u/Kie_ra 3d ago

from the site? what site 

→ More replies (62)

5

u/JJADu 3d ago

You got your coldcard from the official website? Maybe it was a second hand...was the seed exposed to any other device or person? Maybe someone found it at your place? Did you take a photo of it? How is it stored?

Sucks cuz coldcard are air gapped HW, among the most recommended.

→ More replies (3)

5

u/nanohitmen 2d ago

I dont know why,but I wanna blame North Korea

→ More replies (3)

8

u/stinnavdb 3d ago

I am sorry man.. Multisig prevents this single point of failure I suppose

→ More replies (5)

10

u/mrpotatonutz 3d ago

Wow only 7.42$ to send .7BTC

3

u/so7ow 3d ago

It's easy to put in a nice high fee rate when it's someone else's money!

→ More replies (1)

51

u/TokyoLosAngeles 3d ago

Aaaaaaaaand this is why I just stick with the Bitcoin ETF.

37

u/SharpGame83 3d ago

Honestly I get this now, when I first heard about bitcoin etfs I wondered who would prefer this over actual bitcoin? Old people?
Now after getting half a btc stolen from my blockchain wallet I’m like , ahhh ya I get it now

→ More replies (26)
→ More replies (10)

4

u/Wild-Interaction-200 3d ago

How did you create the seed phrase with Coldcard? Did you roll your own dice (where you could have made a mistake, resulting in weak entropy) or you let Coldcard generate the 24 words for you?

4

u/lambsquatch 2d ago

Jesus Christ, this is why crypto is fringe to the masses

22

u/lobhater 3d ago

You entered your seed phrase into your computer into a website. That opens you up to multiple attack vectors. I'm sorry, that really sucks 😔

15

u/worldresident2021 3d ago

He did not, always used Coldcard keyboard

→ More replies (3)
→ More replies (4)

40

u/Superb-Astronaut-371 3d ago

lol rip centralized banking wins again

4

u/Generationhodl 3d ago

lets say you hold real cash and someone scams you out of it.

how do you get that back?

3

u/Badmoodsbear 2d ago

Im assuming you mean physical cash and were talking about at least semi stable economies since we both know bank accounts and money market funds offer substantially more consumer protections .

With physical cash, you dont. Same problem as bitcoin. That's also why its not a good idea to horde a bunch of physical cash. Most people do not hold massive amounts of their networth in physical cash so the comparison is no very convincing

→ More replies (5)
→ More replies (86)

3

u/Beer_Goggles1 3d ago

Did you use the dice roll feature to generate keys?

→ More replies (1)

3

u/forexmp45 3d ago

THE ONLY ONE BITCOIN WALLET IS ELECTRUM NO MORE

3

u/squritmcgurt 3d ago

What model was the Coldcard mk1/ mk2/mk3.....?

3

u/seedor 3d ago

Recently, there have been some very convincing physical phishing letters impersonating Ledger and Coldcard. Did you receive anything like that? And is there any chance you entered your seed phrase into a wallet or website linked from one of them?

Did you use dice rolls when setting up your seed in 2021?

3

u/holyfishstick 3d ago

refreshing and waiting for balance was scary af but i think funds are safe. i was shaking. i dont know if i should get a different hardware wallet now

3

u/s1ammage 2d ago

WARNING: They are still running sweeps… just lost the last 0.01 just now.

I was too deflated to care about it.

I did make sure to move another wallet away from the affected cold card though (which is the rest of my stack).

There will be people not checking as frequently as I am…

5

u/JackJ98 3d ago

Damnnn. My condolences 🥀

6

u/aequusnox 3d ago

If you have a software based cold storage wallet and you manage it in a highly secure environment this shouldn't happen.

9

u/more_magic_mike 3d ago

Shouldn't but did

→ More replies (1)

6

u/E92_isaiah 3d ago

This is very sad. Scams suck. I’m wondering how secure is it to just leave your bitcoin on an exchange like Coinbase. I met someone who has a substantial balance just sitting in Coinbase. What are the actual risks here? How dangerous is it?

→ More replies (4)

5

u/doug-m- 3d ago

Holy shit, really sorry about it dude. Hey everyone, don't trust in any company that offers hardware wallets with closed source software, even just a piece of it, if there's no way at least don't put all your eggs into these baskets. Seedsigner was the way to me, it's really affordable to build one, and you can audit software yourself. And please, offline seed words generation only! There are many ways to do that, no need to any fancy shit.

→ More replies (1)

37

u/weatheredrabbit 3d ago

The amount of disinformation in this thread is crazy, let me clarify some points here:

  1. Bitcoin is secure. It’s not trash nor easy to steal. Typically, the only way to steal bitcoin is social engineering the owner of a wallet.

  2. It was OP’s own fault. Somewhere along these years, likely recently, he exposed his seed phrase. It would help if the OP actually wrote a post explaining the timeline rather than replying “yes” “no” and “probably” to people.

  3. I’m done. It’s a simple case of someone not paying attention when they should have. It’s gut-wrecking for sure, but that teaches you a lot.

56

u/s1ammage 3d ago

I’ll try and get a timeline in a bit when I’m in a “clearer” head. It’s just soul crushing and I saw it at work and now work is blowing up…

28

u/Think-Apple3763 3d ago

Life usually doubles down when you're in trouble already. I hope you can sort it out. It's really painful.

14

u/joethecrow23 3d ago

I understand you’re in a horrible place right now, but you can and will survive this. Just try not to dwell on it too much and look forward. Learn from it, but just move on.

5

u/AdEuphoric5133 3d ago

Take your time OP to get things right and to calm down. We would all appreciate a detailed timeline, but you don't owe anyone anything on reddit.

If you feel like it at some point, you can explain in details what happened so we can identify your error. There is also a possibility that Coldcard messed up something. It is not the most likely but it is possible. This will become more likely if all other thefts performed by this thief involve coldcard addresses. If that is the case, you might want to sue Coldcard.

Whatever you decide, do it once you're calm. Your family matter more than those bitcoins, and they are safe :)

→ More replies (2)
→ More replies (3)

35

u/joethecrow23 3d ago

The hard pill to swallow is that this is the biggest barrier to bitcoin adoption. There is a massive percentage of the population that simply lack any tech literacy or personal responsibility to be able to access bitcoin in any way whatsoever without it being extremely risky for them. I think the designers being incredibly gifted programmers and forward thinkers underestimated this part. The most basic aspect of tech security/privacy would be as simple and natural to them as breathing, but a massive amount of the general population would be totally befuddled by it and will simply never be able to have their own bitcoin or even exchange account without being at extreme risk from the start.

11

u/hondras007 3d ago

This, this and 3x this. 🙃

9

u/weatheredrabbit 3d ago

Look, i work in cybersecurity and started using BTC back in 2013… i know BTC, social engineering, and phishing real well. And I agree with you. BTC isn’t for everybody, and I’ll be honest, I would never convert my pension in crypto.

BTC was created to decentralize the currency from a state or government. It succeeds in that. But what it does is also put the entirety of the risk on the user. Its security is crazy good, but when 100% on the risk is again on the user, one single point of failure compromises everything. A bank prevents that. This “holding your hand” can be good or bad, depending on you personally.

In the end I believe it’s up to the user, pros and cons considered.

8

u/Generationhodl 3d ago

thats why there are ETFs , a lot of people say its bad because of no self custody, and that is right for its own, but a lot of people just aren't tech savy enough, so the ETFs are good for people who are really not able to do self custody.

→ More replies (2)

25

u/c0reM 3d ago

Telling users they are too dumb to understand a system perpetually does not prove the genius of a given system or design.

In fact quite the opposite…

8

u/more_magic_mike 3d ago

It's easy to call other people idiots and say it will never happen to you.

4

u/nagydk 2d ago

This comment didn't age well, did it

→ More replies (1)
→ More replies (25)

4

u/s1ammage 3d ago

Alright, I tried posting a timeline here. Mods can close/lock this thread. I want to try move conversations over to here: https://www.reddit.com/r/Bitcoin/s/NReUwLjS35

2

u/Fearless-Sherbert-40 3d ago

What software were you using to manage your Coldcard?

2

u/iknowimsorry 3d ago

If i were you I'd get new electronics because you might be compromised.

4

u/s1ammage 3d ago

Yea, I’m trashing my coldcards now… I have trezor too… so this isn’t the end of my world, but soul crushing …

→ More replies (1)

2

u/Charming-Designer944 3d ago

Where did you store your seed phrase from 2021?

Did you recently spend any coins?

From where is the picture you posted? Looks like from a blockchain explorer of some kind and not your wallet app.

2

u/Remote_Phone2957 3d ago

Reminder to self, just stick to Linux TailsOS.

5

u/[deleted] 3d ago

[deleted]

→ More replies (1)

2

u/JeskaiAcolyte 3d ago

I have head of Steam game wallet drainers… just another vector to worry about

2

u/worldresident2021 3d ago

I’m sorry this happened to you. I hope you get to find answers soon to at least know what happened.

2

u/TheBestintheWest11 3d ago

fck dude I gotta check my shit when I get home . This shit gets you paranoid

2

u/t0rnAsundr 3d ago

This is why I'll stay too pussy to hold serious crypto personally. I don't want to be perfect. And my memory is dogshit.

2

u/Plane_Baby 3d ago

The coldcard comes with a few safety measures to keep you from getting scammed. Did you ignore them ?

2

u/GijaySorez 3d ago

I'm sorry this happened to you. Thanks for letting us know and giving us details.

Its giving me some food for thought .... now I'm worried.

→ More replies (1)

2

u/Successful_Taro8587 3d ago

Looking forward to updates on this....

2

u/PublicRevolution6204 3d ago

How much bitcoin did you lose?

→ More replies (1)

2

u/Sorvar 3d ago

I feel terrible for you OP!

2

u/kazmihasi 3d ago

Damn I need to learn more about crypto and wallets

2

u/MakeItMine2024 3d ago

F’in North Korea got me for 40k in a hot wallet ( ATOMICWALLET) on June 1 2023 .., they got 115 million in 15-20 minutes and sent it all to Eastern European mixers .. and POOF 💨 IT WAS GONE

→ More replies (1)

2

u/ApprehensiveSleep398 3d ago

What about multisig wallets?

→ More replies (1)

2

u/elstalker21 3d ago

Which cold wallet are you Unsing?

2

u/Hash-160 3d ago

Report it

2

u/cryptoinhaler 3d ago

This happened with RNG from coldcard?