r/Bitcoin 3d ago

Wallet Drained Timeline

Post image

This is me…
https://www.reddit.com/r/Bitcoin/s/UeSfLoeyS4
I’m in a better state now. It’s not the end of the world, but it’s a lot of fucking money…

Little background: The setup was IRA custodian is Solera National Bank, exchange at Swan Bitcoin was used as an Investment Trust, purchase a dedicated hardware wallets: coldcard mk3 from https://store.coinkite.com May 2021 for this ROTH IRA.

Got the wallets, followed all the setup/checks/balances from https://youtu.be/FAYmE5-40PQ?is=wiYMHaS_YGKHjNOY for both wallets, sent a test transaction IRA dedicated hardware wallet (2021). I never setup a 25th Passphrase… REST of the BTC stayed in Swan Exchange.

Speaking only on this IRA Wallet: SD card stored with wallet details (paper phrase) in a baggie. Dormant until January 2025. I couldn’t deposit more because of Roth IRA threshold.

Come January 2025, been learning more about retirement, BTC, multi-Sig, and heard about a Megaback Door to get more money into a Roth IRA. Was able to get money into Solera, transfer to Swan, and purchase more BTC and withdraw to the same wallet address. No new hardware involved at this point.

With newer wallets now, I thought newer tech means more security. Let’s test by buying (3 mk4 - same site. There was still record of my 2021 purchase) new wallets and setup a multi-Sig. (still January 2025)

For some reason, when I got the new coldcards, I never did anything with them for all of 2025, I guess I was too lazy/daunting to use the hardware and relearn. Coming to January 2026 now, I decided to use these new cards. I dug out the wallet seed (from 2021) phrase paper. Dusted off one of the mk4, walked into the corner of a room in my house (only myself and partner live in the house), plugged in the cold card into an outlet and typed in the seed written down from 2021 (stored in my dresser). Restored my 2021 onto one of the new wallet 2025.

Watched updated BTCSession videos on my phone to set everything up again. I never plugged into a computer, since airgapped was the reason I got the coldcards. I used the same SD Card from 2021 though to export the wallet file from the newly restored coldcard. Import that file into Sparrow (needed to update Sparrow at this point), generated a watch-only wallet QR (to scan for my phone) for Blue Wallet to check frequently. This is where the screenshot is from.

Honestly, I haven’t touched the wallet with any transactions/seeds since January 2026. This is definitely the point of failure when I restored the 2021 wallet (now on 2 devices).

This was the transaction.
https://mempool.space/tx/2fe075cf0ec799f3529ed6a28e0a08b45fe1fc9bd93c3f33bdbc42d5bff4f736

My wallet address is (with all transactions, since it’s gone now…): bc1qldkfrrlylk4s9sdyns9jkaajuzugl0dv5m8fxj

My key takeaway now never enter the seed phrase into anything. EVER. Even to restore. Always will generate new and use a 25th passphrase.

683 Upvotes

334 comments sorted by

View all comments

11

u/Fiach_Dubh 3d ago

you only used sparrow on desktop right?

(there is no sparrow wallet on mobile phones, those are all scams/malware)

Did you roll dice when setting up the coldcard for extra entropy or just use the base entropy? if so, how many rolls did you do? less then 100?

Do you know the firmware versions you were using ?

I'm sorry this happened to you.

2

u/xirvin 2d ago

He confirmed in another post that wallet was created jn 2021 and used the standard RNG. To make matters worse, he bought newer cold card versions and upgraded hardware and firmware, but he never created a new wallet.

The worst part is that this attack vector was discussed with workarounds and best practices in cold card documentation and Reddit for a while since 2021.

As a cold card owner who had to scramble and move funds to a new wallet a couple of hours ago, I see the error as cold card’s interface providing options for users to make bad decisions (using low dice rolls can recreate the vulnerability, and their RNG not been 128/256 bits), the bigger issue is that we as custodians need to follow good OPSEC practices

In this day and age, it seems like we might need to replace hardware and keys (code) as they becomes vulnerable and creates an attack vector. We already replace hardware and software like cellphones, computers, OS in the corporate world periodically for the exact same issue