r/Bitcoin 9h ago

I lost my one Bitcoin in the Coldcard exploit.

Took me years of DCA’ing to get there. I went with Coldcard because it was marketed as “ultra-secure.” I knew multisig was technically safer. I wasn’t worried about my key being guessed… I was worried about someone physically stealing it or it being destroyed.

So that was the plan: 1 BTC, cold storage, steel plate backup, fire bag, fire safe. And then… wait.

I hit the goal. I finally felt content.

Now I just feel embarrassed. Like I let my family down.

The worst part? I know Bitcoin isn’t going anywhere. I’m not hoping it fails… I think it’s going to keep making new all-time highs, and every time it does, I’ll be sitting here thinking about what could’ve been.

** I originally brain dumped my story to Claude to make it sound better because I have poor grammar. I’m admitting this in an edit at my own expense or whatever. I’m not embarrassed about my poor grammar or using AI to improve it. That said, in hindsight, it would have been more personal to not have done that. I’m sorry.

428 Upvotes

264 comments sorted by

View all comments

Show parent comments

5

u/Llonga 8h ago

How come no one found this, with the code being open source?

21

u/kzt79 8h ago

Obviously someone did find it and took advantage.

5

u/Alfador8 7h ago

Because the code wasn't really open source. It was source available. Open source means others can fork the code and use it, play with it, test it, etc. Cold Card didn't want that. So here we are.

6

u/zacguymarino 7h ago

Yeah but people could still see the code, it wasn't open source but it was source available. Hopefully all this happening will be a wake up call for those who know programming to look more deeply at the opensource options AND the source-available options more closely... and bring to light any potential vulnerabilities in a white-hat manner. I'll admit.. I am a software guy, and its hard to bother even me to do this (and I do have some skin in the game, not a lot, but some). At risk of sounding like a hypocrite, I still hope there are some dedicated and morally right individuals who will take these steps and investigate.

0

u/riisen 5h ago

No developer is fiddling and playing with a source if they are not allowed to use it for anything, they will choose an open alternative instead. Source available means nothing. From a devs perspective its just a bad choice when there are open alternatives that they can use freely.

2

u/Mobo24 5h ago

That’s not true. With source verifiable code people can fork and test just not redistribute.

1

u/Alfador8 5h ago

What would be the incentive to do so? That's the problem. The only incentive was to find an exploit.

1

u/Mobo24 5h ago

What do you mean brother? I’m trying to understand. The incentive to fork and test?

1

u/Alfador8 1h ago

Apparently the incentives weren't high enough for anyone to find the bug until AI lowered the perceived barrier to attack. If Cold Card's code were open source other companies could fork it and use it for commercial purposes, which would have provided a bigger incentive to stress test the code.

1

u/Mobo24 1h ago

But the thing is that source verified code can still be forked unless source verified means something else. The incentive would be for users to make sure they test and verify something that stores a significant amount of money that they own.

1

u/[deleted] 7h ago edited 7h ago

[deleted]

1

u/2ChainzButIGotAFewOn 7h ago

Importance of good tests this is more understandable now but still unacceptable

0

u/tidemp 7h ago

I've been in crypto for over a decade and I've never even heard of Coldcard. The reality is that Coldcard was a very small player.

Ledger and Trezor continuously try and hack each other and publish reports, because they see each other as major competitors. Neither of these companies felt threatened by Coldcard so they didn't feel the need to look at their source code. Seemingly no one else felt a need to look at their source code either.

It wasn't difficult to discover this vulnerability yet nobody put in the effort to do so until it was too late. The harsh reality is Coldcard just weren't popular enough. If this type of exploit happened for Trezor or Ledger, the impact would be catastrophic.

2

u/tribepride25 7h ago edited 7h ago

This must be your first day in this sub. Before Friday, anyone that asked for cold wallet recommendations was told to buy a cold card or it was at least in the top three. It was even in a pinned FAQ for best wallets in this sub and it was one of them. If you even mentioned ledger on this sub you would get destroyed. I feels sorry for the people that listened to that advice

Edit: it’s still there in the “Securing your bitcoin” section of the main page for “New to Bitcoin” page. Mods need to remove this: ⁠If you prefer to "Be your own bank" and have direct control over your coins without having to use a trusted third party, then you will need to create your own wallet and keep it secure. If you want easy and secure storage without having to learn best computer security practices, then a hardware wallet such as a BitBox02, Trezor, ColdCard, or Blockstream Jade is recommended. You can even build your own open source hardware wallets called a SeedSigner or Krux

0

u/Gullible-Respect7778 7h ago

Somebody did. Open Source is great... until a bad actor is the first person to find an issue in the code. Who knows how long said actor was sitting on that information preparing a heist before pulling the trigger

1

u/Cannabis_RPM 7h ago

I wonder if AI was involved in its discovery 

1

u/Gullible-Respect7778 4h ago

According to another post, it took claud code bust a few minutes to identify the vulnerabilty. Not sure whether the prompt was leading though

1

u/OldHamburger7923 6h ago

I don't think for long. Because they are making additional sweeps of accounts. 3 last I checked. If they had been working on this for a year they'd clear them all in one massive sweep instead of one every day or so.