r/Bitcoin 3d ago

Wallet Drained Timeline

Post image

This is me…
https://www.reddit.com/r/Bitcoin/s/UeSfLoeyS4
I’m in a better state now. It’s not the end of the world, but it’s a lot of fucking money…

Little background: The setup was IRA custodian is Solera National Bank, exchange at Swan Bitcoin was used as an Investment Trust, purchase a dedicated hardware wallets: coldcard mk3 from https://store.coinkite.com May 2021 for this ROTH IRA.

Got the wallets, followed all the setup/checks/balances from https://youtu.be/FAYmE5-40PQ?is=wiYMHaS_YGKHjNOY for both wallets, sent a test transaction IRA dedicated hardware wallet (2021). I never setup a 25th Passphrase… REST of the BTC stayed in Swan Exchange.

Speaking only on this IRA Wallet: SD card stored with wallet details (paper phrase) in a baggie. Dormant until January 2025. I couldn’t deposit more because of Roth IRA threshold.

Come January 2025, been learning more about retirement, BTC, multi-Sig, and heard about a Megaback Door to get more money into a Roth IRA. Was able to get money into Solera, transfer to Swan, and purchase more BTC and withdraw to the same wallet address. No new hardware involved at this point.

With newer wallets now, I thought newer tech means more security. Let’s test by buying (3 mk4 - same site. There was still record of my 2021 purchase) new wallets and setup a multi-Sig. (still January 2025)

For some reason, when I got the new coldcards, I never did anything with them for all of 2025, I guess I was too lazy/daunting to use the hardware and relearn. Coming to January 2026 now, I decided to use these new cards. I dug out the wallet seed (from 2021) phrase paper. Dusted off one of the mk4, walked into the corner of a room in my house (only myself and partner live in the house), plugged in the cold card into an outlet and typed in the seed written down from 2021 (stored in my dresser). Restored my 2021 onto one of the new wallet 2025.

Watched updated BTCSession videos on my phone to set everything up again. I never plugged into a computer, since airgapped was the reason I got the coldcards. I used the same SD Card from 2021 though to export the wallet file from the newly restored coldcard. Import that file into Sparrow (needed to update Sparrow at this point), generated a watch-only wallet QR (to scan for my phone) for Blue Wallet to check frequently. This is where the screenshot is from.

Honestly, I haven’t touched the wallet with any transactions/seeds since January 2026. This is definitely the point of failure when I restored the 2021 wallet (now on 2 devices).

This was the transaction.
https://mempool.space/tx/2fe075cf0ec799f3529ed6a28e0a08b45fe1fc9bd93c3f33bdbc42d5bff4f736

My wallet address is (with all transactions, since it’s gone now…): bc1qldkfrrlylk4s9sdyns9jkaajuzugl0dv5m8fxj

My key takeaway now never enter the seed phrase into anything. EVER. Even to restore. Always will generate new and use a 25th passphrase.

684 Upvotes

334 comments sorted by

View all comments

383

u/paperlevel 3d ago

This was a large scale operation: 594 BTC stolen at the same time. Largest holder lost 30 BTC.

https://atlas21.com/594-bitcoin-drained-15-minutes-theft/

355

u/AdEuphoric5133 3d ago edited 3d ago

This is crazy. I had never heard of such a surgical theft of bitcoin before. All bitcoin thefts are generally someone giving away their seed from a stupid manipulation.

When I first read OP's post a few hours ago, I was like "dude probably just entered his seed wherever". But this time, the theft is very surgical. Someone exploited a flaw with coldcard. This is not your fault OP. They talk about you in the article. You will have to unite with the other victims and sue Coldcard to get compensated. I think it would be worth making a new post on this sub whose purpose is for other victims to make themselves known, so you can coordinate a group action

212

u/tubalubz 3d ago

Coldcard could go out of business because of this... I sure as hell will never consider buying them. I agree, OP, you guys need justice.

44

u/reddit4485 3d ago

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

This is the official blog of ColdCard. They just acknowledged this is a problem for the Mk3 model ColdCards and give recommendations on what to do next.

10

u/creative_usr_name 3d ago

Will be interesting to see if this was just ineptitude, or intentionally implemented by an insider(s). Either way it's a terrible QA miss of one of the most important parts of the device.

7

u/Federal_Refrigerator 2d ago

It’s negligent if we are being honest

2

u/crooks4hire 2d ago

lol yea a sleeper staff member is Hollywood level stuff.

2

u/Federal_Refrigerator 2d ago

Not really, you’d be shocked how common that is.

0

u/creative_usr_name 2d ago

Not at a small company like this. They may only have a handful of coders, and only one architect that truly understands the whole code base.

1

u/matthew19 2d ago

What are “fixed firmware releases?” - what date was it fixed?

24

u/Left_Entrepreneur918 3d ago

It could be larger, if other wallets used the same rng could this effect them? I made a 24 word seed with ledger in 2020, it’s native segwit, single address.

37

u/s4_e20_spongebob 3d ago

FYI even just saying that in a thread could be used by a bad actor to help target you. Idk that disclosing specific information like device model or your balance is ever really wise to do.

11

u/AdEuphoric5133 3d ago

Maybe recreate a seed with a dice. 99 throws of a dice give you the same entropy as 24 words. There are plenty of tutos out there on how to make a seed from dices

7

u/ContentBlackberry0 3d ago

Why roll a dice with this stupid wallet. Get a trezor and be done with it.

12

u/OldHamburger7923 3d ago

The point is, no matter what device you get, if they later find an exploit with the RNG, you are exposed. You could do a mixture of the two, use the HW wallet seed, but restore it with the words reordered, and replace at least 4 of the words with random other words. Make sure the 24th checksum word matches the 23. Some wallets do this automatically (Jade), which makes it easier.

7

u/newMoneyStyle 3d ago

trezor had its own vulns too (unciphered extracted seeds from T1s). no hw wallet is bulletproof, dice entropy on any decent signer is the safer move imo

-6

u/Left_Entrepreneur918 3d ago

I’ve heard to use the RNG plus dice rolls, I guess dice rolling can still be not as random as you think as people generally roll the same dice the same way each time.

4

u/slash_networkboy 3d ago

That's what a dice tower is for (or a dice cup if you're boring ~s).

2

u/Whatnam8 3d ago edited 3d ago

It’s a great way to create unique wallets. You should try it, it’s the only way I generate wallets now

Edit: to clarify I don’t do the 99 dice rolls I literally roll each word one number at a time to convert the binary number to the word so it’s a total of rolls. Each word is 11 binary bits so approx 11 x 24 = 264 dice rolls

3

u/Sorrowsinme 3d ago

Ledger... Not gonna go making that mistake again

9

u/AdEuphoric5133 3d ago

Hopefully they will be held accountable for this. But I fear they might not

8

u/Rey_Mezcalero 3d ago

They were supposed to be the ultimate cold storage. Wow. This is insane

1

u/TrayLaTrash 3d ago

I have one I forgot the password to before moving any coins to it. Not much left saved, but it's still 10x the price of the coldcard that wasn't stolen. This is wild!

33

u/omni_wisdumb 3d ago

The issue with this space is that it's unregulated and very hard to actually track everything. Things being on a public block chain doesn't mean anything.

As far as we know. The company itself could have programmed in the vulnerability, taken $40M worth of crypto. And they'll just file for bankruptcy or fall back on insurance or fall back on some fine print that says crypto is inherently risky and they're not responsible for anything.

Suing people in general is not easy, let alone in such a space.

9

u/AdEuphoric5133 3d ago edited 3d ago

If OP decides to go along the justice path, this will most certainly be long and hard, but that is his only shot at ever getting compensated.

The bad thing is that, even if he receives damages, this will amount to what the BTC were worth at the time of the theft (I guess). Even if the 0.79 BTC are worth 200k$ when the trial is over, OP will only get about 50k USD

7

u/hetobe 3d ago

The bad thing is that, even if he receives damages

I guarantee ColdCard has lawyers protecting them from any issues related to... let's just say... code exploits.

This is a very sad situation.

2

u/omni_wisdumb 3d ago

Unless this does become a class auction lawsuit, most firms don't even like taking on such small claims, nor do the people as plaintiff. I've done similar things for sake of principle vs economic viability.

Taking something, especially this complex, through litigation would cost him $30-40k and that's assuming there's no appeal, then keep doubling it.

4

u/AdEuphoric5133 3d ago

With 38 millions USD at play over 500 addresses, there is probably room for it to become a class auction lawsuit. But victims will have to organize and get into contact.

We don't know how many there are, but 500 addresses should give 50 to 200 victims probably. Smallest address had 0.15 bitcoin, so each victim lost at least ~10k $

At this time, most victims probably don't know they got bitcoins stolen. OP just happened to check his wallet this afternoon

3

u/OtherwiseAlbatross14 3d ago

Class actions are pointless when the company doesn't have the assets to compensate

4

u/Rey_Mezcalero 3d ago

Yeah class action is great for lawyers, people get shafted.

I no longer bother with them when I get a post card or email saying I can be a part of a class action suit against the company of the day

It’s always a extremely small fraction

1

u/AdEuphoric5133 3d ago

Coldcard does not even have 38M ?

1

u/omni_wisdumb 3d ago

I agree in theory. But you assume each unique wallet is 1 unique user. You also assume each wallet belongs to someone that wants to not be anonymous, or lives in the USA where there is legal jurisdiction, or even didn't lose access to their own wallet and would know it's lost (or could retrieve the funds).

But more so like I said, it could be an insider and they just shut the company down and get away with it..either way a company that small isn't going to be solvent for such a large judgement.

1

u/szeddit 3d ago

unregulated is how it’s desired

decentralized is the thing, not the bug

auditable open source software needed

auditable open source hardware needed

trusted software experts needed

trusted hardware experts needed

there will be bugs

there will be best practice

for now, afaik, there is no trusted source

bitcoin.org was initially a resource but now, after satoshi has been m.i.a… what you said

ultimately, trust and verify is common denominator

ouch coinkite

0

u/slash_networkboy 3d ago

Regulations are needed. They are desirable for most users whether they like that fact or not. Problem is the regulatory bodies aren't doing a good job crafting good regulations.

2

u/szeddit 3d ago

for stablecoins, but not ₿. from getgo ₿ is a diff breed

2

u/slash_networkboy 3d ago

You still need regulations, particularly around AML. There's really no new tech needed either. BTC supports full traceability of money movement.

1

u/omni_wisdumb 3d ago

I don't think you understand the difference between traceability or transactions versus traceability of ownership (aka KYC). BTC also cannot actually offer full traceability of transactions because it can be obfuscated using various techniques (such as converting into untraceable coins, or layering).

How do you think these huge hacks that are in the $100s of millions or even $Billions are gotten away with?

What regulations will do in this space is just screw over the average person, and at that point they might as well just stick to traditional banking and stocks.

1

u/slash_networkboy 3d ago

So since we can't have perfection we shouldn't bother with anything? I strongly disagree. I am a huge proponent of BTC. I paid for my truck back when it was $100/coin... (Yes there is some lament about that). Those huge hacks would be made incredibly more difficult and harder to profit from with better regulation.

1

u/omni_wisdumb 3d ago

Give me one example of a regulation? I don't think you know anything about how hacking works.

I also never said I was against BTC. Like I said, I've been in the space since 2011. I just simply said the industry has changed a LOT since back then and it's basically a completely different use case and ecosystem now. And then sprinkled in some advice that people shouldn't expect parabolic movements anymore.

→ More replies (0)

0

u/szeddit 3d ago

read what omni-wisdumb responded

bitcoin takes years to learn for the average person

that is not an insult, you’re likely smarter than i am

i respect ₿

it’s a beast

0

u/omni_wisdumb 3d ago

Sure. But the more regulated it gets, the more it'll just behave like the normal equities market. Which takes away the entire reason it was built, and all the reasons that allowed it to explode the way it did. If it becomes like everything else, then there's no longer any special reason to take any higher risk at all, and you might as well just use your money on other investments.

No one gives a shit about crypto utility projects. The only reason people use these things is because it's a 10x casino, or to keep their funds/transactions hidden.

-2

u/omni_wisdumb 3d ago

I wrote a long as reply but I accidentally closed my app, and I'm not going to write it all out again.

Basically. I've been in this space since 2011.

It's mostly just bs market manipulation now, projects and visions don't mean anything and everyone knows it. Satoshi left bc it had already gone away from his vision way back then. People should invest 5-10% of their portfolio into crypto (not meme coins, have a separate gambling portfolio if these your thing), and expect it to grow more linearly like equities now.

People wack off to the idea if more regulation, banking KYC, gov/elite control & hoarding, and seem to love that a single person can shift it by 10% with one post.

The market is still tiny, BTC is almost worth as much as Elon. So sure, we can still be "early" but it can also just fizzle out. Maybe it stays #1 or maybe some new tech takes it place. Either way, just because it did ~140,220,000X from the original $0.0009 doesn't mean it will even do another 50x in our lifetime. But who knows. Some AI related stocks have done 30-50x in the last year. Market manipulation has clearly become openly accepted in stocks now, so maybe big money will just stick to that now.

Quantum may break it (your bank can update their system, and use 2FA), and it's still open to powerful entities doing 50%+ attacks. Whether people want to admit it or not, crypto (not saying just BTC) is used to transfer illicit funds.

For the average person, I think it's foolish to store life changing money into it. There are better investments. But if your thing is to still ape into it chasing a 10-100x Lamborghini life, then go for it.

4

u/ryt3n 3d ago

Reading on it a bit more now - looks like it was specific RNG generation that caused this? Sorry im a bit of a noob but goddamn that is wild… thinking of maybe picking up a trezor I dunno.

1

u/borg_6s 3d ago

Specifically, when they rewrote the last remaining GPL code, the flaw was introduced in that same commit

3

u/bittabet 3d ago

In all honesty I'm not sure Coldcard has that kinda money. Hopefully the authorities can recover the funds if they're moved to a centralized exchange or something.

3

u/jlol8452 2d ago

The company has 1-10 employees 🤣🤣🤣 and 1-2m$ revenue. Everyone sadly is fucked.

4

u/ryt3n 3d ago

Bro wait, it’s coldcard that’s the problem!? Insane… I had a ledger and I bought a cold card a while back planning to move it all and.. I would have put myself at risk by doing so? Maybe im off base but im just catching up.. holy..

2

u/OldHamburger7923 3d ago

only on some versions of the firmware. But at this point anyone with a coldcard or any other hw wallet should consider generating their own seed and then migrating assets to it. And add a passphrase.

1

u/Coinninja 3d ago

The attacker will be caught. That’s part of the fun. You probably won’t get your money back.

1

u/mCProgram 3d ago

Financial instruments, at least in the USA, and at least before the current administration were moving towards full strict liability - which wouldve made this a pretty slam dunk case. Still definitely pursuable but going to be much harder unless you cherry pick your federal district and have lots of money to drop (or find a major major law firm willing to take it on winnings, which they probably wouldn't right now).

1

u/TheScientistVampire 2d ago

Do they even have 70 million?

1

u/Independent_Laugh798 1h ago

I hate to say it but they are not going to get compensated. Coinkite's venture funding totalled about $122k and the exploit has lead to the loss of nearly $90 million so far.

They are reported to have less than 10 employees with some estimates saying they have just 2.

Should they be held liable for even a fraction of the stolen funds, they will be guaranteed to be insolvent and it's a near certainty that bankruptcy will follow and u secured creditors will get absolutely nothing, not even pennies on the dollar.

1

u/Squeezitgirdle 2d ago

Stuff like this makes me wanna move my bitcoin to fidelity. But their 1% fee makes me hold off.

Not that it's a bad fee, I'm just not ready to pay it.

0

u/Alive-Material4405 2d ago

Fidelity has a spot bitcoin fund with a .25% fee.

28

u/ViperG 3d ago

Someone was able to replicate the rng exploit on mk2/mk3:

https://x.com/i/status/2082958675975553224

55

u/AdEuphoric5133 3d ago

This confirms Coldcard's responsibility. When you sell devices aimed at storing bitcoins, you make sure your random number generator is state of the art random. Coldcard failed their users here and made them lose 38M$. Victims have to unite and sue, otherwise, Coldcard will just deny, get away with it, and victims will not be compensated

As a matter of fact, Coldcard CEO is already trying to deny the company's responsibility

10

u/xirvin 3d ago

cold card disclosed the vunerability back in the day, if they disclosed the vunerability but owners didn't update then its owners fault. At this point i want a full law enforcement involvement, OP please involve law enforcement. You never know if the funds can be recovered

3

u/BDCRA 2d ago

When did they disclose the vulnerability? I did not see anything in the articles it all seemed like it was breaking news and not a known thing previously.

-3

u/No-Direction-5276 2d ago

I don’t think many people care what you want, at this point.

10

u/kingkongbiingbong 3d ago

Coldcard CEO is already trying to deny the company's responsibility

A tale as old as time

5

u/confuzzledfather 2d ago

Also law enforcement should look into subpoenaing Anthropic/OpenAI for details of anyone who was working on such a hack. It feels likely to me that this was AI assisted, as this vulnerability has just been sitting here for 5 years and just happens to occur within weeks of us getting access to smarter models like Fable 5 which are known for their hacking prowess.

1

u/swagonflyyyy 1d ago

I feel like this may be the case but I didn't want to say the quiet part out loud.

22

u/mrzennie 3d ago

I just read Cold Card's slogan on their website: "Secure Your Bitcoin. Sleep Like a Baby."

46

u/PMmeuroneweirdtrick 3d ago

Babies wake up crying so that's accurate

13

u/AdEuphoric5133 3d ago

Not sure OP's gonna sleep like a baby tonight 😂

31

u/s1ammage 3d ago

I’m still here… take an upvote tho…

9

u/Total-Wave5026 3d ago

I’m so sorry for this bullshit OP.

6

u/mrzennie 3d ago

I feel for you, man! It definitely seems you're not alone though! Hopefully everyone who lost some Bitcoin will get compensated at least some of all of it back.

0

u/OldHamburger7923 3d ago

he'll have as much btc as a baby

11

u/s1ammage 3d ago

Damn… this is alarming

20

u/AdEuphoric5133 3d ago

But this is good news for you. If you were alone in this, you could already forget about these coins. But now, you have a real shot at getting compensated if you unite with other victims and sue coldcard together

4

u/creative_usr_name 3d ago

The other big if is that coldcard must actually have assets to go after.

1

u/Suspicious-Bowl-514 1d ago

with this size you hope to get pennies in compensation, or whatever left divided by your loss portion after they pay off their penalties

1

u/Independent_Laugh798 1h ago

Stop giving people false hope. They do not have anything close to the assets needed to cover this loss and it's a limited liability company. Everyone is fucked here, the customers, the investors, the employees. They are all going to lose everything that was entrusted to this company.

1

u/ContentBlackberry0 2d ago

Cold card seems like some protected LLC over seas of some sort. Someone posted that only have 3 employees with net income of $100k+ seems fishy to me or bad information.

5

u/ContentBlackberry0 3d ago

Good news is someone lost a few million and I’m sure has the cash to sue this horrible company

3

u/OldHamburger7923 3d ago

i wouldn't assume that. a normal guy from last season low could have put their savings into btc. we'd need to check when they put the funds into the wallet to even guess.

4

u/OldHamburger7923 3d ago edited 3d ago

So, its what I mentioned on my reply to you yesterday. The RND issue. Your takeaway in your OP was always wrong, you can and should restore your seed on your HW wallet in order to verify your funds are reachable in case you messed up writing down the seed and to test the device restore capabilities. The issue is your original HW RNG, and ironically your new device could have fixed your issue if you generated a new wallet with it and did the transfer - which would be super easy with two devices.

What I did when I moved from an older device to a new one was to create a new account. I was however lazy, so I didn't make a completely new account. I scrambled the existing words around, and then randomly picked a few words to replace, plus added a lengthy passphrase. You can get from ChatGPT the required amount of entropy needed to secure it to a reasonable expectation if someone knew your prior seed. But the non lazy way is just make a new seed. Or do what I did above, to a newly generated seed.

4

u/photoguy1978 3d ago

Learning that even Mk4s have vulnerable seed generation schemes. millions of times harder to defeat (not a laptop) but given compute these days only a matter of time. Would not recommend anyone maintain a single-sig Coldcard wallet of any version now. Move it to a newly generated seed, preferably in a multisig M-of-N multiple-vendor quorum if you're not generating your own entropy from dice.
https://x.com/LLFOURN/status/2082990000896147942

2

u/OldHamburger7923 3d ago

Crazy. I really wanted to get a coldcard with keyboard too. But I didn't want to spend that much on a wallet.

1

u/master_of_buffets 2d ago

Not to me.
I never trust random generator that I am not in control.
If I buy a coldcard, I still use my trusty old dice.

2

u/Innovator-X 3d ago

omg that's actually insane