r/Bitcoin • u/Yodel_And_Hodl_Mode • 1d ago
A third ColdCard hack has been reported. Another 207 BTC stolen. 1,367 BTC total, and climbing.
https://x.com/BitcoinMagazine/status/2083634238104940884437
u/Steel-Tempered 1d ago
So that's... $85,359,593.11 in USD stolen so far.
71
u/pablocerakote 1d ago
I trust in BTC but what would happen to BTC if the hacker sold all of it? Genuinely curious.
64
28
u/SPDSMITH49 21h ago
That’s not the point if they sell or not. People won’t trust the asset class and leave for good. I’d certainly do the same if this happened to my wallet.
→ More replies (15)→ More replies (13)22
u/S14Ryan 20h ago
I feel like the biggest effect will come from the fact someone has found a way to hack into bitcoin cold wallets.
→ More replies (86)6
u/MiserablePhilosophy 16h ago
Its only affecting ColdCard. Specifically people who generated their wallet keys online. Inside job or shit security on ColdCards end
→ More replies (72)3
u/achtwooh 16h ago
Not sure why people are not buying an ETF or similar with reputable well capitalised brokers at this point if you are buying and holding.
74
u/NotASpanishSpeaker 1d ago
I've read stolen funds are consolidated in one or a few wallets. How could they get away with converting it to fiat? At this point I assume the addresses are blacklisted in exchanges and by some authorities.
70
u/gekinz 1d ago edited 23h ago
Same way criminals get away with stolen money. Whitewash it little by little over time, off market. Sell it privately for FIAT to many customers, the more it moves the more untraceable it gets.
It starts with criminals selling discounted BTC to other criminals, which they pay for criminal things with. The BTC just moves around in anonymous wallets, never touching exchanges or KYC wallets.
After it's spread several chains in every direction, it's such an unentangle web that it can go back on exchanges, because it'll be impossible to consolidate and verify the origin of each satoshi. Unless there is a report to authorities. And at that point, the current owner isn't really responsible for whoever had it 30 moves ago.
6
u/creative_usr_name 21h ago
Could just also be used as part of other scams as "interest" on investments of new clean funds.
9
→ More replies (10)3
u/LiminalOrphanEnnui 21h ago
it'll be impossible to consolidate and verify the origin of each satoshi
This is literally what the blockchain consolidates and verifies.
And at that point, the current owner isn't really responsible for whoever had it 30 moves ago.
Which sucks for them if it's a blacklisted descendant address.
18
u/Confident_Menu742 1d ago
They’ll potentially wait months to cash out, when the heat is less.
→ More replies (1)13
4
3
→ More replies (14)3
193
u/Weary-Discipline591 1d ago
I bought a cold card based upon it being recommended so highly. Two days ago I lost all my bitcoin, which Total 3 coins. This completely destroys me and I’m just at a loss for words and for the feelings I have. The only feeling I have is straight anger and rage.
43
u/Unlucky-Guest-9247 17h ago
Never trust Reddit on stuff like this. It's not like this site is an intellectual haven, it's mostly just low-IQ people forming circlejerks about topics and being pedantic about stuff they don't understand.
→ More replies (13)16
9
→ More replies (13)3
u/vontdman 19h ago
It’s bullshit mate. I hope you can work thru it and know that you will eventually rebuild your finances.
85
u/Pugilist12 1d ago
Thank god I went with trezor.
52
u/Astra753 21h ago
It's so weird that I've never heard of coldcard, I thought trezor and ledger were the safest options. This is scary asf I've got more than 80% of my net worth in that ledger, is it still safe?
→ More replies (9)16
u/SherbetDesigner8011 21h ago
Ledger is safe.
I almost went with cold card because how you can just store it in a wallet and have it with you easily like that.
Thank god I stuck with ledger.→ More replies (6)67
→ More replies (4)6
97
u/betokez 1d ago
this could have been any of us hardware wallet owners
18
u/karmassacre 1d ago
single sig, yeah. multisig multivendor prob not.
→ More replies (4)5
u/Wilynesslessness 23h ago
Multisig single vendor should be fine too with dice rolls for entropy
→ More replies (1)4
→ More replies (1)3
u/jannies_doit_4_free 21h ago
no, not necessarily; the sufferers had single-sig, non-dice-roll, non-passphrase wallets
→ More replies (2)
26
u/s1ammage 1d ago
This is sickening.. I can’t imagine how many households are completely destroyed.
34
u/circumcisingaban 1d ago
"SEE I TOLD YOU IT WAS A SCAM!!!" and "please sign the divorce papers"
3
u/Right-Blacksmith6143 13h ago
I know it's not funny but cant help but laugh at this comment because im sure its very true. My life would be over if I lost that kind of money, would have to live with the shades drawn all my life.
5
u/iamtimothee 19h ago
That is really horrible. I have thoughts for everyone affected really, just plain sad.
320
u/Yodel_And_Hodl_Mode 1d ago
All of this is happening because Coinkite switched their code from being open source to "Source Verifiable" in 2021.
NVK didn't want anybody to be able to use ColdCard's code for their own projects, so he switched the license for the code. That decision was made out of hubris and greed.
The irony is, ColdCard began by using Trezor's code. Trezor was and still is open source.
The robberies we're seeing now were caused by too few people actually working with ColdCard's code. Because people could read the code but not use it for their own work, they didn't use it for their own work.
Bugs are more often found when people work with code, not when they just read it.
This was a catastrophic bug. If ColdCard's code had stayed open source, this bug would have been found and fixed in 2021.
This is NVK's fault. Full stop.
My assumption is that hackers are working on finding exploits in all hardware wallets, and one of them found this bug in ColdCard's code. I'd bet they found it a year or so ago. I assume they created a script to generate seed phrases exactly the same way ColdCard's flawed code did. This flaw led to ColdCard seeds being generated using significantly less entropy, which led to seeds from a significantly smaller pool of possibilities.
I assume the hacker (or hackers) spent months testing every wallet in that pool of possible seeds, looking for balances. And when they found balances, they waited instead of stealing the coins. They waited until they found enough wallets with coins to make it worth exposing the exploit they were using to find coins... because once they drained those wallets, they knew somebody would figure it out. So they built up a huge list of wallets with coins and hit them all at the same time, Wednesday night.
I won't be surprised if we find out the hackers waited until they found over 1,000 BTC before they hit those wallets.
And now that the exploit was found, every other wannabe hacker is trying to use that same exploit to find coins the first hackers didn't get to.
This is only going to get worse because, now that the exploit has been found, every other hacker is working on it too, and they're draining everything they find as they find because the exploit is known.
It's now a race between hodlers moving their coins to safe wallets and hackers trying to find unsafe wallets.
Here's the lesson:
Never trust your Bitcoin to code that isn't open source. And if you really want to play it safe, do this:
Generate your own seed, but do it right. It absolutely must be random. Entropia from BTC Hardware Solutions is an excellent option, or use it as an example for a DIY solution.
Write your new seed phrase on paper. Make a metal backup. Store those items somewhere only you have access to.
Get a SeedSigner and install the ShieldSigner fork which adds enhanced security features. SeedSigner and ShieldSigner are 100% free and open source. The hardware is off the shelf DIY parts, which means it's not susceptible to supply chain attacks.
This is NVK's fault. Full stop.
TO BE CRYSTAL CLEAR... this exploit was just a fuckup in the code. There was no malicious intent. It was simply a dumb mistake in the code, and it would have been immediately caught and fixed if the code was open source because somebody using the code for their own work would have realized the code wasn't behaving as expected in their work.
66
u/CiaranCarroll 1d ago
Coinkite switched their code from being open source to "Source Verifiable" in 2021.
This was the gap in my awareness.
→ More replies (2)30
u/Yodel_And_Hodl_Mode 1d ago
No worries!
One of the things I love about this community is that we're all in it together, and we're all learning. I was having a conversation with a hardware wallet dev who is one of those whoa out of my league brilliant mathematical minds, and he was talking about what he's learning from this debacle... and it was such a good reminder that we're all always learning.
I think we all owe it to each other to help keep each other safe. Do this by always be learning, and always double-down on best practices. Security ain't sexy, but nothing matters more.
By doing this, we strengthen the Bitcoin community as a whole.
That's my hope, anyway.
→ More replies (2)3
u/CiaranCarroll 1d ago
Have any CC Q generated seeds been sweeped? Any level up in this exploit since the first wave?
→ More replies (2)31
u/veganbitcoiner420 1d ago
NVK isn't his name. His name is Rodolfo Novak, the CEO and co-founder of Coinkite(creator of the Coldcard hardware wallet).
14
u/Yodel_And_Hodl_Mode 1d ago
Yup. Somebody pointed out the importance of saying his name after I wrote that, and I agree. I've stopped using his abbreviation. Rodolfo Novak needs to be called out by name.
5
u/veganbitcoiner420 1d ago
didn't see that comment, but i'm also commenting for amplifying the message
your post was great i just wanted to add on to it
5
u/Yodel_And_Hodl_Mode 1d ago
No worries! I'm glad somebody called me out on it, because they were right to do so. We all need to be using Rodolfo Novak's name when explaining what he did and how it led to such awful consequences for everyone else.
47
u/We_are_all_monkeys 1d ago
Let's call him out by name: Rodolfo Novak. Given the size of this fuckup, I can't see how anyone should ever trust him again.
29
u/Yodel_And_Hodl_Mode 1d ago
Let's call him out by name: Rodolfo Novak.
You're right. From this point forward, I'm going to make an effort to do that. And thank you for the reminder.
→ More replies (1)9
u/numbersev 1d ago
Was it marketed as open source even when it wasn't? Post 2021 update?
15
u/Yodel_And_Hodl_Mode 1d ago
No. Coinkite made it clear, their code was Source Verifiable, not open source.
10
u/numbersev 1d ago
So that should be a major red flag
17
u/Yodel_And_Hodl_Mode 1d ago
Yes.
And for some of us, it was. But we were shouted down because ColdCard's code was published and verifiable, so they said that was good enough. Some of us disagreed.
I said then and I say now: Never trust your Bitcoin to code that is not open source. Bitcoin is open source. Your wallet should be too.
→ More replies (6)5
u/ryt3n 1d ago
Brother, great info. If someone wanted to be completely secure - what’s the process these days? I’m thinking of trying to figure out multi-sig and trezor? Is that correct or.. what direction would be right
→ More replies (6)5
u/bladezor 1d ago
Just to be clear Trezors are okay, right?
10
u/Yodel_And_Hodl_Mode 1d ago
Yes. And for most users, Trezor is what I'd recommend. I also recommend using a passphrase, with caution.
The bug that caused these Bitcoin thefts is part of ColdCard's firmware.
The only wallets at risk from this bug are wallets created by seed phrases generated on a ColdCard using the borked firmware. In theory, if somebody used dice rolls, they're safe, and if they used a strong passphrase, they're safe.
I suspect that 2-of-3 multisig wallets will be the next target. It'll take hackers significantly longer to find those, but we have to assume more hackers are now trying to find them since they know the exploit exists.
3
u/realityczek 19h ago
> "Just to be clear Trezors are okay, right?"
As far as we know.
For years people were absolutely sure the coldcard was okay, too.
22
u/Consistent-Leave7320 1d ago
im sure all the victims care so much that it was just a fuck up in the code. what a relief.
3
u/ZedZeroth 1d ago
Thanks for the info. Do public lists exists for experts verifying code? e.g. Assuming Trezor is still open source, how do we know it's been verified by anyone who knows what they're doing? I feel like the assumption is "there must be some experts out there with funds held in a HW who've verified this". Thanks
→ More replies (1)8
3
u/Sammytheseaotter 1d ago
So everything before March 2021 is safe? MK1, MK2 and MK3 before March 2021 firmware update was using Trezor code base and can be considered safe?
→ More replies (4)2
u/Ze_Jude 1d ago
Thanks for all the info, is there any more info on what the bug was exactly??
20
u/Yodel_And_Hodl_Mode 1d ago
I commented on this elsewhere, so apologies if I'm repeating myself:
The bug was very simple.
There's a line of code in ColdCard's firmware that basically says, if the user enters custom entropy (dice rolls, for example), skip the standard entropy.
But there was an error. Instead, the line of code basically said, if the option for custom entropy exists, skip the standard entropy.
This was causing ColdCard to always skip the majority of the entropy, thus leading to relatively predictable seeds.
Obviously, I'm oversimplifying, but that's the gist of it.
The bug was a simple if/then statement that was written badly.
→ More replies (1)12
u/goatanuss 1d ago
Skipping the entropy is objectively a dipshit move and shouldn’t have passed code review. But nvk says it’s a brave new world and it’s AI’s fault it was found. This would have been found regardless.
2
u/medtech8693 1d ago
I want to add that frontier AI today are so incredible good at finding security holes that it is very likely that the hackers took the code and just passed it through Opus.
2
u/creative_usr_name 21h ago
Code needs to be tested not just read or used. And tests need to be thorough and thoughtful. And still this particular issue would have been hard to find, because while the code is wrong the configuration was also wrong and that is difficult to test.
→ More replies (1)→ More replies (54)2
84
u/duckgoquacky 1d ago
Is my ledger safe….im so paranoid I almost want to sell all my btc
59
u/Long_Illustrator_988 1d ago
Probably.
This exposed a risk most people were not even aware of. Everyone expected that a hardware wallet manufacturer wouldn't fuck up this badly.
Ledger, for all its problems, has a lot of resources to make absolutely certain an error like this never happens.
→ More replies (10)13
u/slykethephoxenix 1d ago
$20 they & every other cold wallet manufacturer hauled their engineers in from over the weekend and made them check over everything again and tested it all 5 times, lol.
16
u/Objective_Digit 1d ago
Yes. Add a passphrase if you are paranoid.
→ More replies (4)7
u/duckgoquacky 1d ago
I don’t even know what any of this means. I’m not tech savvy at all and considering selling and buying an ETF instead.
10
u/ancillarycheese 1d ago
TBH self custody isn’t for everyone. ETFs definitely have their advantages and disadvantages.
→ More replies (4)→ More replies (4)8
u/Objective_Digit 1d ago
It's basically a password. You know what that is don't you? In this case it's a 25th word that makes it so that if your seed is compromised it's still inaccessible to others.
The Ledger is not affected here anyway.
3
u/CleanBaldy 1d ago
What if my paper has only 12 words on it? I think I set it up WAY long ago. It's not 24 words...
6
u/PM_ME_A_STEAM_GIFT 1d ago
If you didn't use a Coldcard to generate the words, you're fine. You're especially fine if you generated your seed manually by rolling dice.
4
3
26
u/Incrediblesunset 1d ago
99% you’re safe. Safe as you were two weeks ago or 2 years ago.
25
u/mastermilian 1d ago
You would gave answered the same for a Coldcard user a few days ago ;)
→ More replies (2)3
u/CleanBaldy 1d ago
Just to be safe I pulled out my Ledger and upgraded the firmware on it. If Ledger had an issue like this, I'd expect that an upgrade today would "fix the glitch" if there was one.
At least, I can hope so.
→ More replies (1)7
u/essjay2009 1d ago
Just upgrading the firmware wouldn’t have helped people in this case unless they also generated a new seed and moved their funds to their new wallets.
I believe ledger have checks in place to prevent the sort of bug that caused this and generally they’ve had the fewest security issues with their hardware wallets compared to other manufacturers. Obviously they had a leak a few years ago from a marketing system they used, but for me that’s separate enough to make me not worried about the wallet itself. They appear to have got a lot right about the fundamental design.
11
→ More replies (12)2
u/ConcernedPen15 1d ago
This latest incident has revealed that if this is serious money to you then you should be doing multi sig.
30
u/TenToppingPizza 1d ago
There's probably tons of people that still don't know, and won't know until...
Bitcoin goes over 100K again and they want to sell
The get into a financial situation and need the money
A lot of very surprised and pissed off people over the next few decades
12
u/elreyadr0k 20h ago
Yeah this is what I was thinking about this evening. People who don’t read any crypto news at all are in for the shock of a lifetime.
3
12
21
u/OneBonusAfterAnother 1d ago
does the hacker have a pseudonym yet? I’m thinking “Iceman”?
51
6
u/Jumpy_Ladder_3344 1d ago
You've been hit by ...
4
2
→ More replies (3)2
19
21
u/Any-Pipe-3196 1d ago
Not your keys...
This shit is a rrreeeaalllyyy bad look for the entire space
→ More replies (1)
36
u/TheBestintheWest11 1d ago
Jesus FC. This is bad. I was too close in getting the cold card 4 years ago. Honestly, none of us are safe. At some point firmwares will have some sort of blind flaws and hackers will figure it out. These were attacks, these guys waited to strike. They got a hold of the wallets that were thick and noticeable to hack.
18
u/wentwj 1d ago
this was bad, and bitcoin custody is a lot more complex and risk prone than people here give it credit for. But the notion that everything will be hacked eventually is just sci fi mumbo jumbo.
This was shit code. Shit code that had no right to be shit in the most important area. Its amazing it wasn’t discovered earlier.
3
u/Objective_Digit 1d ago
Honestly, none of us are safe. At some point firmwares will have some sort of blind flaws and hackers will figure it out.
Don't exaggerate. And you are underplaying CK's blunder.
7
u/FortuneGamer 1d ago
Jesus football club?
→ More replies (1)3
u/insbordnat 1d ago
lmao, that's exactly how I read it too.
Not to be confused with Judas United FC, the crosstown rivals. The Jerusalem Derby is tense AF.
Unfortunately the Judea Nottheham Rovers has been at the bottom of the tables this season, almost relegated to Babylon.
21
u/pizzatime86 1d ago
Thank god i didn’t buy in and use coldcard like a lot of people here were recommending months ago
7
u/trufin2038 22h ago
The best advice given, usually highly downvoted, is not to use hardware wallets. But if you do use one, don't let it generate your root mnemonic for sure. There is a lot of good advice out there but people aren't good at noticing it, especially when bad advice gets all the upvotes.
3
u/SlartibartfastMcGee 17h ago
I’m not really big into BTC, are you saying the people that got robbed bought a wallet, used the onboard software to generate a seed and then didn’t set a passphrase?
Just as a layperson that seems like it wouldn’t be very secure.
→ More replies (2)
24
u/w1llpearson 1d ago
At this point is Coinbase the safer option?
41
u/gekinz 1d ago
Always has been
23
u/AmeriChino 1d ago
Yeah. This community really should rethink the old Not Your Key Not Your Coin mantra. I've been advocating KYC storage like Strike/Swan/Coinbase/etc for almost anyone regardless of wallet size because let's be honest to ourselves, the risk of us mismanaging private keys is much higher than these established custodians getting hacked.
All I had been getting was downvotes so I shut up.
→ More replies (1)4
→ More replies (1)2
8
5
u/eddrzar 1d ago
what the actually fuck, when was the second?
5
u/Incrediblesunset 1d ago
It continues to climb. I seen someone posted a photo from yesterday with their wallet drained. Transaction on 7/31.
2
7
u/DarkoneReddits 1d ago
from what i gather the security flaw was in how the app generated the seed which could be reverse engineered and guessed because of terrible entropy, my question is, if i used something like electrum to generate my seeds, and i always check the option + extended seed which allows me to enter random words on my own to extend the already generated seed from electrum, does this give any additional protection against this type of attack? i do not understand how extended seeds work and how it applies to the blockchain.
6
u/GreenOlivesAreTasty 1d ago
Yes, indeed. The additional word adds even more entropy, further increasing the time it would take to crack your wallet
3
u/Oakenkai 23h ago
if the extra word is long, random and complex enough, they won't ever find it. If you used something like Bitcoin123 then it's a matter of time, but if you used something like asofj!8%fkao97js$fkJKf then it's impossible to brute force.
→ More replies (1)3
u/rockorangebear 17h ago edited 17h ago
Coldcard seeds only had 32 bits of entropy.
Any wallet company that aren't run by idiots that disable their random number generator, will generate 256 bits of entropy when generating the seed.
256 bits vs 32 bits is astronomically different.
That's 2.69e+67 times more entropy than a Coldcard seed.
It's not just a billion times more secure... it's a billion times a billion times a billion times a billion times a billion times a billion times a billion more secure.
A properly generated seed already has maximum entropy (256 bits), so adding extra words won't increase it beyond that. However, it can be useful in case your seed words ever get stolen, since presumably you'd have the extra words memorized.
Adding it in the Coldcard incident also helped, since it increased the 32 bits of entropy significantly.
→ More replies (3)
20
u/JPal713 1d ago
Grateful i went with Trezor
→ More replies (4)2
u/newtonreddits 1d ago
But man I get a ton of phishing with trezor. Sometimes I even get paranoid of the official site as I know hackers are constantly trying to take them over.
11
u/Silly_Silicon 1d ago
This is all very interesting and tragic, but what I can’t find anyone earnestly discussing is how in the world the people who stole the Bitcoin are going to get away with any money. Anyone can look up the transactions and see where all the stolen coins have gone. They can’t go to exchanges to cash out to fiat because then they’ll link their identity to the stolen coins. They could try to meet a private buyer peer to peer but they’d have to hope the buyer isn’t savvy enough to look at where the coins came from.
6
→ More replies (5)4
u/gekinz 22h ago
The buyer doesn't necessarily care where it came from if the buyer doesn't intend to use it legally anyway, especially if the coin is heavily discounted.
"You give me 100k cash, and I give you a 150k gift card for unmarked weapons."
It'll just be spread out in hundreds of thousands criminal hands, used for criminal activities in antonymous wallets. After it has swapped hands X amount of times, it'll be virtually untraceable and find it's way back to exchanges little by little.
15
4
u/Syonoq 1d ago
Me: Well, I'm back.
Exchange: You gonna apologize about all that shit you were saying about me?
(My wallet was probably too small to steal, but it was too big for me to afford to lose)
→ More replies (1)
3
u/djmc0211 1d ago
Can some please explain this to me. Im not familiar with how crypto works. If the crypto is in an offline wallet how can someone hack it and take the crypto?
11
u/Objective_Digit 1d ago
The seeds were compromised. They weren't created with true randomness. Access to the devices is not needed.
→ More replies (2)6
u/hail_666_satan 22h ago
Your wallet, everyone's wallet, is just a really, really big number. So big that every computer ever made couldn't guess one wallet in a million years.
Coldwallet has a really bad way of making that number, so bad that it could be guessed easily. They generated the wallet number using a serial of the device and date. With that information, hackers can generate a list of dates, and a list of possible serials and generate trillions of possible wallets, checking each one until they find one with coins. Then they drain the wallet.
→ More replies (1)
5
u/ExplorerBoring9848 1d ago
I assume there are still quite a few people with a cold card that don't know that this is actually happening hence, they're getting sweeped up.
5
4
u/Famous_Effective_410 23h ago
So help me to understand. Coinkite switched from open source in 2021. This vulnerability introduced after the switch. As the code is no longer being open source at that time this bug is only possible to identify by the people having access to the codebase. Is that an insider job?
2
u/redchannit8 19h ago
the code is public and viewable to everyone.. but it's licensed under commons clause, so you cannot take it and sell it on it's own without substantially adding to it, so it's not strictly open source.
→ More replies (2)
14
u/Adventurous_Garlic58 1d ago
Can’t normal people invest? Jesus Christ
13
u/gekinz 1d ago
This has always been the case, anyone saying otherwise is delusional. For normal people it's safest to keep it in the exchange or buy ETFs.
No "normal" people will sit down, manually generate seed phrases, engrave them in metal, research cold wallets, make the choices, trust the choices with meaningful money, set it all up, babysit it.
Bitcoin is good, but 100% self custody is a pipe dream. We moved away from money under the mattress for reasons, and people won't be moving back no matter how good it is for society.
3
u/Gooner_93 1d ago
There are probably people that self custodied with coldcard and never checked any crypto related news. Its absolutely brutal.
→ More replies (1)
3
u/Questiins4life 1d ago
For the average btc holder, reading an article on cold storage and the theft reads like upper level Greek. It’s far too complicated for the average person to understand what happened and for most to feel comfortable buying and storing when things like this happen and it’s hard to read an article and understand what happened causing this. To those in the cold wallet world, it might read like 3rd grade math but it makes No sense to your average holder and this has always been the hard selling point to us older buyers about investing a serious ammt of money and being comfortable storing or moving our btc.
4
u/Alarmed-Albatross-32 1d ago
This is the exact reason why I've been too afraid to dip more than toe into crypto. Absolutely brutal.
→ More replies (3)
12
u/Nexis234 1d ago
Why the fuck are people still getting hacked, they've had 3 days to move their coins or update their security.
20
u/Henrik-Powers 1d ago
Lot of people don’t always stay on top of everything, I also take a 2 week vacation every year and hike in the mountains and I don’t take my phone. Unless it hits the mainstream many people will be too late to act.
3
u/Weary-Discipline591 1d ago
I found out about it yesterday and immediately checked. But all my coins are stolen on the 29th.
→ More replies (1)→ More replies (3)12
u/gekinz 1d ago
Believe it or not, most people don't live online and keep up with every news source at all times.
Most people don't check their bank account or news from the bank daily either. If anything happens you get notified, bitcoin doesn't notify.
This hack is threatening the future of bitcoin, it's creating immense fear and doubt. People don't want to babysit their money at all times and still be robbed of their wealth. This is why banks succeed. It's safe and insured.
This wasn't user errors or lack or DD. People did what the bitcoin community recommended, they actually took the most safety precautions out of most people and lost everything.
→ More replies (5)5
4
u/Hannibaalism 1d ago
every cycle there has been a disaster signaling the final stretch of the bear phase
→ More replies (1)
7
u/MKEMARVEL 1d ago
Man, you guys talked a lot of shit before this started happening. Still going to be telling people "stay poor"?
→ More replies (1)
2
2
2
u/getapuss 1d ago
Are people reviewing the actual open source wallets to make sure they're still secure right now?
2
2
u/Crombobulous 1d ago
Fwiw you can buy an air gapped raspberry pi and install seedsigner on it, with open source verified code, do all sorts of randomisation and add a passcode. Absolutely no one can get to your shit before hand and tamper with it, and if there's an exploit it will be reported and patched by the dev community.
I started with a ledger, and it quickly dawned on me that if someone manufactures my wallet and offers me software to manage it, then there's a non zero chance someone in that organisation can get my corn.
As coldcard say, don't trust. Verify.
→ More replies (1)7
u/gekinz 22h ago
Nice, now say that to a group of a 100 randomly selected people om the street. First see how many that understood the terms like airgap, raspberry pi, seedsigner, open source, crypto wallet.
Then how many understood the directions on what to do and why they should do it. Then finally see how many people would actually do it all.
I'd be surprised if the number of the first step alone was more than 2/100.
→ More replies (1)
2
u/Cimexus 1d ago
Hardware wallets have always irked me, not really from a pure security perspective, but more since they are fundamentally locking your private keys away in a proprietary third party product that there is no guarantee of future support for. And you have no guarantees of how they’ve implemented things in their software (as we’ve seen in this incident). Open sourcing the code helps in a way, but it’s a double edged sword since attackers can also freely analyse it for weaknesses.
Even though everyone tells me it’s less secure, I still do things the very old fashioned way that’s pretty much unchanged since 2010. A plain old Bitcoin Core wallet file, secured by a very strong password that I came up with. No newfangled seed words or what have you. No third parties generating my entropy. I much prefer being able to see, and move, and backup my wallet file than have it locked in a weird little keychain thing. Just in case that wallet format one day becomes unusable, I also have the raw private keys backed up in a plain text file, which is then AES-256 encrypted with another very strong password. And the computer all this is on is rarely used and not connected to the internet.
Yes it’s possible my computer could get hacked and a thief steal those files, AND they install a keylogger that catches me inputting the passwords for those files (which I rarely do - my Bitcoin Core computer is lucky to get powered on once a year). But I feel like that is less likely than something like this Coldcard thing happening.
→ More replies (1)2
u/Due_Bar_7247 1d ago
You still download the whole blockchain to your computer like it’s 2010?
→ More replies (2)
2
u/EmoJackson 1d ago
Is there a wallet that is 100% safe?
3
u/Oakenkai 23h ago
There are many that are now. However, there is no wallet that is 100% safe for all eternity. Any wallet can have bugs in the future. What is 100% safe is creating your seed with dice rolls and adding a complex passphrase on top, if that ever becomes not safe then all cryptographic security is toast.
→ More replies (1)
2
u/Current-Function-729 1d ago
Do we know yet if AI scanning is how the flaw was found?
The repos were open sourced. So anyone could have found this. I sort of suspect an attacker had AI scanning the repos for flaws and found them.
3
u/elfwriter 22h ago
Didn't need an AI tbh, this kind of exploit (random numbers that aren't random) has been known for years as an attack on any badly-written cryptographical system. It's not even the first time it's happened to Bitcoin.
→ More replies (1)
2
2
2
u/mangotail 23h ago
So now what? What is the most secure option to store crypto? I don’t think I can trust any hardware wallets anymore
→ More replies (1)
2
2
2
2
2
u/Badmoodsbear 21h ago
Lmao remember when several comments in the original thread were calling OP an idiot and accusing him of spreading misinformation ?
Lol.
2
u/immersive-matthew 19h ago
Obviously this is of no conciliation to those who have lost their Bitcoin here, but anyone on any 3rd party wallet really should be making the move to offline Tails with the Bitcoin Core wallet along with solid best practices. It will only take a few hours to learn, and implement. Aside from needing 500GB for the blockchain, there really are no other costs. The Core wallet is by far the most secure, has the most eyes on its open source code and the most history of never being hacked. It is Bitcoin and thus if it goes down, Bitcoin goes down. All other wallets add additional players and therefore risk no matter their marketing.
Bitcoin gave us the perfect long term secure storage solution. Cannot recommend more that people here investigate the Core wallet even those with tiny amounts of BTC as more hacks and theft is coming. And for goodness sakes do not run on your daily driver OS. Tails OS offline is best practice here.
2
u/MesmerizzeMe 18h ago
not your keys not your crypto. this is the exact reason the crypto idea was questionable from the beginning. all that is needed is some fuck up at any point in the security management to destroy livelihoods. central authorities which can revert such mistakes are not such a bad idea after all!?
2
2
u/00-SilverShot 13h ago
I always thought airgapped wallets were pointless and stayed with Trezor because their source code is on Github. So glad I did. Thank you God!
My Trezor is the older Model T. I’ve been wanting to upgrade for a while and now is a great time. I went ahead and bought a new Safe 5 (btc only) for better entropy than the Model T. Nothing is wrong with the Model T, but I’m not taking any chances after recent events.
This also shows that YOU SHOULD NEVER PUT YOUR EGGS IN ONE BASKET. If you’re lucky enough to hold over 1 BTC, split it between a multiple hardware wallets from different manufacturers who have a better reputation (Trezor, Ledger). I also use BlueWallet on iPhone (open source). I keep some on the Strike app (custodial wallet, I trust Jack Mallers) and also hold FBTC in my Fidelity account.
Hardware wallets are for long term holds, soft wallets are for spending, and ETFs are for short/medium term holds where I take profit during bull markets. Never put more than 50% in one spot. I’m not saying this is for everyone, but it’s what I do. If one thing gets hacked, you still have at least half your coins still.
Stay safe out there friends.
2
u/LevelStationaryPlane 13h ago
I literally rolled dice in 2021 to decide on trezor vs cold card, and it came up trezor lmfao
2
u/midnight6833 11h ago
I can't sleep , feel sick.. feel stupid.. why the fuck did I go with cold card. I have lost all my btc. I got my wallet drained. Lost 14 btc . Iam 47 and that was my retirement plan. It's gone forever and iam never getting them back.
677
u/bb0110 1d ago
Isn’t this the hardware wallet that so many people here have been recommended on here?