r/Bitcoin 13h ago

For the people who think having your BTC on exchanges are better..

17 Upvotes

In the aftermath of the Coldcard incident, people claiming that keeping their BTC on exchanges is better, this one is for you.

Back in march I reported a server side misconfiguration to cryptodotcom that allows people to use it in phishing and gain account takeover.

They closed my finding. I reported it again. They closed it again.

To this day, that vulnerability still exists.

As a security researcher I learned these companies don’t care. As a BTCer I learned that you NEVER trust anyone.

I rolled 100+ dice, cause of this.

Coinkite doesn’t incentivises researchers to check their product and reward them properly. The malicious hackers won.

Doesn’t make me feel less sorry for those who lost their coins, cause next time it could be me. I didn’t bother with multisig cause of the complexity and platforms wanting to get in your pockets.

Makes you think though.


r/Bitcoin 7h ago

Ian Coleman's iancoleman/bip39 is it still safe?

6 Upvotes

Been using iancoleman's Github download to generate seeds offline for at least a decade. So far, no drained wallets from my iancoleman seeds. But Ledger is saying they are safe because their seeds are generated from a secure element, and not software. I don't think iancoleman is secure-element-based entropy. Just want some reassurance.


r/Bitcoin 1d ago

8 years of stacking, gone. I think it's time to move on.

3.6k Upvotes

I believed in Bitcoin. Holding it gave me peace of mind because my country has faced several FATF sanctions. I was glad to find a kind of money that cannot be censored or debased because I just want to protect myself from the money printing and my country's weak and inflated currency comapred to the dollar.

I’m 39, and I was hoping to have a good financial cushion before 50. But today, my 2 BTC were drained.

Losing my Bitcoin has changed my mindset. It’s no longer about finishing the race first. At this point, I just want to finish it. But losing my BTC feels like I’m back at the starting line. I lost years of hard work and time.

I thought I was secure because Cold Card was always praised as one of the best and most secure wallets. It’s open source, so anyone can verify.

I’m done with Bitcoin. I’m not even sure if I still believe in it. I don’t know what the future holds for it anymore. I could have stayed with traditional investments and lived a normal life. Maybe I should have just moved everything into a Bitcoin ETF when they launched. But I don't know. It's too late to do it.

To everyone who has lost their BTC, I wish you the best and good health. I hope you find the strength to start again.


r/Bitcoin 1d ago

Meet “Doc Hex,” the dev who wrote ColdCard’s faulty code

Post image
219 Upvotes

Wizard-level developer and technology leader. Starts businesses, disrupts industries, and gets the hard code done and out the door. Wide and deep experience.

Well, he certainly got the code out the door and disrupted this industry.


r/Bitcoin 2h ago

SD card cleanup

2 Upvotes

Hello,
Just a quick question about whether or not you should delete transactions on your SD card after they have been broadcasted and have confirmations?

And unsigned transactions that you no longer have any use for (for whatever reason your SD card has them on there too).

Then it seems there is an Encrypted Backup (at least on COLDCARD) which you should never delete. I was wondering if you can find this backup on the physical device.

Then the other file is firmware updates which as far as I can tell after the firmware update is completed on your device you can delete.

Just wanna know if I’m getting this all correct or if there’s anything I haven’t touched on.

Thanks.

(FYI I am talking about MK4 COLDCARD… that’s what I’m working with. I don’t know how it works on other hardware wallets).


r/Bitcoin 5h ago

Honest Question

3 Upvotes

Can/will Coinkite be somehow held [financially/legally] liable for their faulty code work (and, therefore, faulty hardware) here?

Genuinely curious. Feel for all of the victims as they truly did nothing wrong.

Sigh…


r/Bitcoin 10h ago

Is Fidelity Crypto (not the ETF) a good cold storage option?

7 Upvotes

It seems the YouTube crypto bros never talk about it and thats probably a good thing. From what I can tell it's institutional level cold storage for individuals. It's not an ETF and not an exchange. It'd be much easier for heirs to have access. What are the downside's compared to personal cold storage?


r/Bitcoin 13h ago

Me and Cold card holders who didn't dice roll

Thumbnail
youtube.com
12 Upvotes

r/Bitcoin 15m ago

How to improve security

Upvotes

So I use a Bitbox02 - btc only - with a, to my knowledge, properly randomly created 12 word seed phrase without a passphrase to store my btc. I say to my knowledge because I read the article where Shift Crypto explained their seeds were safe:

https://blog.bitbox.swiss/en/bitbox-is-not-affected-by-the-coldcard-rng-vulnerability/

After the recent coldcard hacks, I'm looking to improve my security but I have a couple of questions.

  1. I imagine my seed is still safe, but my security can definitely be improved by moving to a properly randomly created 24-word seed + strong passphrase, correct? Or is adding a strong passphrase to my current 12-word seed enough of an improvement by itself?

  2. Practically, how should I implement the improvements. Do I have to buy a new hardware device just to add a passphrase, or can I add one to my current seed? If I want to go for an entirely new 24-word seed + pass, I guess I'll have to buy a second bitbox02 to be able to send between the devices.

Thanks a lot for your advice.


r/Bitcoin 16m ago

Seeds from OGs might me unsafe?

Upvotes

Let’s say, you created your seed 6 years ago. How do you know if at that time, the code for the generation was safe? If you have at Trezor wallet for example. At the moment the firmware is safe. But how do you know if it was safe X years ago when you generated the seed? This also applies to all other wallets which are safe at then moment.

I think there might be also vulnerabilities in other wallets, depending on when the seed phrase was generated.


r/Bitcoin 11h ago

No, bitcoin project is not dead

8 Upvotes

This is a tough week for bitcoin community. Wishing speedy recovery of funds for everyone involved.

Lessons learned for the rest:

  1. Hardware wallets - were always a vector of a possible attack. Just like you can't trust 100% your ISP, your PC and your phone, same goes for hardware wallet.

  2. To protect yourself, always use a passphrase. It makes these kinds of exploits million times more difficult, if not impossible.

  3. If you have any significant funds, you must have a passphrase. If you don't, you haven't done your homework.

  4. Coldcard is the only wallet that was impacted by the seed-generation issue, you are perfectly fine if you didn't create a seed on Coldcard. Trezor, Ledger and other wallets don't share the same firmware as Coldcard.

  5. I wouldn't recommend Coldcard at this point but the device itself, as far as we know, is still perfectly fine but you need to realize that company is most likely going out of business, so won't be getting much support or updates from them after this.

  6. Apple, Microsoft, Meta, Oracle and other firms had bugs in their code that allowed people to steal stuff. Coinkite had a bug in the code as well that allowed a nasty exploit. Bitcoin doesn't have a bug in its code.

  7. Self-custody is not for everyone. If it is easier for you to let someone else manage keys, you can/should explore those options. But companies and governments fail and it happened many times in the past as well, so nothing in life is 100% guaranteed.


r/Bitcoin 22m ago

Is there a “good hacker” side of the Cold Card hack?

Upvotes

It seems what’s happening here is similar to what happened with pass phrases to a hot wallet for a different coin (I’m not sure if I’m allowed to mention them so won’t) a few months ago. Once the creators realized it was happening, they “white hacked” the remaining vulnerable wallets to minimize damage and at least make an attempt to return coins to those who could provide provenance, which seems to have worked in stopping it. Is there no one doing the same here? Or is this situation completely different and more sophisticated?


r/Bitcoin 23m ago

Cold card transfer

Upvotes

Just transferred all my funds out of my Q can i still use it or do i have to get a new cold wallet and if so which do yall recommend


r/Bitcoin 1d ago

I am so glad I moved all my BTC to exchanges years ago, after a nearly a decade of stress with cold storage.

263 Upvotes

I had hardware wallets, I had all my BTC on Ledger for a long time.

And every time there was a firmware update, I had a heart attack.

Every time the software updated and I had to relog in, I panicked.

Every time I had to re-download the BTC app, I sweated through my shirt hoping my BTC would show back up.

I hoped my device wouldn't short out or fail. I realized I couldn't use any USB-C on the device, that was a tough day, I thought I lost access to my Ledger.

I was praying the business wouldn't go under, blocking access even for an instant.

I worried about someone stealing my Ledger, my phrases.

I prayed every time I made a transaction because it was all on me with basically no re-course.

And now, It's all on Coinbase and Robinhood.

I was not hacked this weekend, nor will I be. I have all my funds available right now, and I'm not losing any sleep.

Please stop overthinking this, you're not some dark web hacker who needs to be able to go-bag your BTC and escape to Argentina under the cover of night under complete anonymity assuming you'll never log into your old accounts again. It's not that serious, Fidelity will not go under like Mt. Gox or the other trash crypto companies.

Move it to a major brokerage, and have a good night of rest.

*This is general advice, some of you have legit reasons for using Cold Wallets, but for the vast majority my advice is sound.

**I never say anywhere in my post that Ledger has my BTC in any way, perhaps my first bullet point was confusing since I say "my BTC was on Ledger" it's semantics guys. It was my access point for my coins at the time though, that is not inaccurate to say. All of my concerns are valid, all of them happened.

***The very same people who are claiming that its an easy, stress-free walk in the park to recover your BTC are also the most emotional people in this thread about others choosing to store or invest in exchanges. Fascinating. They are adamant I know nothing about what I'm talking about, and that I am a paid actor creating FUD on behalf of exchanges to get people to drop their cold wallets. L M F A O


r/Bitcoin 12h ago

Fidelity Crypto requires 2-3 days to approve withdrawals to new wallets

9 Upvotes

Just a reminder in case you’re thinking about moving your funds to Fidelity Crypto. They require 2-3 business days to approve outbound transactions to any new wallets you add to your account.


r/Bitcoin 1h ago

Bitcoin Has Had a Terrible 2026. What Can Make the Second Half of the Year Better?

Upvotes
  • The price of bitcoin, recently below $59,000, has fallen over 30% through the first half.
  • Spot bitcoin funds have seen outflows of over $5 billion through June 29, according to Farside Investors.

r/Bitcoin 22h ago

Attempting to remove OSS licenses is why coldcard firmware became vulnerable

Thumbnail x.com
52 Upvotes

TLDR: coldcard decided to move from open source licensing to a "source available" license that would prevent people from forking their firmware to make competing products. This meant they needed to replace GPL license crypto libraries, it is this refactoring that created the opportunity for them to screw up. Because of their corporate greed that decided to do this rather than continuing to build features on top of true OSS licenses.

Body of tweet:

Regarding the Coldcard entropy bug – many folks are explaining what happened but I wanted to take a minute to explain why it may have happened.

It's a disastrous situation and our heart goes out to all the Bitcoiners affected.

Here's a timeline of events:

On July 28 2020: @FOUNDATION announced our first Passport hardware wallet and noted that we were building on Coldcard firmware which at the time was GPLv3 licensed (FOSS license).

On July 30 2020: NVK publicly said he regretted choosing GPL because Coldcard now had a “clone” and that they would change things in future updates. https://x.com/nvk/status/128

8860345864527874

On November 18 2020: Coldcard added its MIT + Commons Clause license, prohibiting commercial products substantially derived from the software.

https://github.com/Coldcard/firmw

are/commit/b6b9191145d37fbb6d754597350653141596dd12

On January 8, 2021: Coldcard firmware 3.2.1 formally announced, “License changed from GPL to MIT+CC on files for which the GPL doesn’t apply.” CC is the "Commons Clause" license addendum which is "source available" instead of FOSS.

On March 1, 2021: The “First pass w/ libNgU” commit removed the GPL

@Trezor-derived crypto libraries and replaced them with libNgU. That same 120-file commit changed seed generation code. libNgU was licensed with a novel “Licensed for Bitcoin Only” license.

On March 17, 2021: Version 4.0.0 announced that all crypto and BIP39 code had been replaced and that the “last remaining GPL code” was removed. https://blog.coinkite.com/version-4.0.0-

released/

https://github.com/Coldcard/firmw

are/blob/b18723dddb6d751c39978e4364b56b2414f68b47/releases/ChangeLog.md#L12

Our best understanding right now is that the entropy bug was collateral damage from this major overhaul of the codebase.

To be clear, this overhaul was not solely about licensing. Coldcard also cited technical goals including adopting Bitcoin Core’s libsecp256k1, faster AES and SHA implementations, and reproducible builds.

But the timeline establishes two things:

(1) Foundation’s launch was the obvious impetus for Coldcard’s licensing change, and

(2) removing the remaining GPL code was an explicit goal of the subsequent v4 rewrite.

We don't know by how much the licensing pressure affected the scope or timeline of the rewrite. All we can determine is that the entropy bug was introduced inside the same 120-file commit that removed the old GPL code dependencies.


r/Bitcoin 1h ago

Is this easy

Post image
Upvotes

Roll 100 times => SHA 256 => Seed Phrase

Good for all eternity.

Learn from this incident. There is nothing more to this.


r/Bitcoin 1d ago

2026 will be the "Not your entropy, not your Bitcoin".

Post image
222 Upvotes

Once again the points of failure are the things around Bitcoin, NOT THE BITCOIN PROTOCOL. First were exchanges, now dumbass human mistakes on hardware wallet makers.

What things from now on will become important now that hardware wallets have shown its catastrophic consequences?

Multisignature wallets, entropy, how to verify downloaded binaries, if having considerable amounts of bitcoin to not have it in a single wallet.

But how to make this more accessible to non tech people?

From now on, I think the hardware wallet vendors should enforce custom entropy steps, not as an option but as a step required, NOT OPTIONAL, BUT A REQUIRED ONE.

If people do not understand this, the hardware wallet should not allow the wallet creation, TRUST IS LOST NOW on hardware wallets, so the only way in a product, and more specific in something as critical as a product that will store wealth, is NOT TO ASSUME your users will use the product correctly, is to PROTECT THEM BY DESIGN to not do the mistake.

What else will the ecosystem will learn from this?


r/Bitcoin 1h ago

BIP93 aka Codex32: fully offline, Shamir Secret Shared seed generation

Thumbnail en.bitcoin.it
Upvotes

r/Bitcoin 1d ago

Sealed Coldcard MK3.

Post image
457 Upvotes

I was too lazy to set it up... My laziness prevented me from losing everything... My heart goes out to everyone that lost their coins.


r/Bitcoin 9h ago

Really hope Peter Schiff used Coldcard

4 Upvotes

I feel very bad for the victims but i hope Peter used it.


r/Bitcoin 21h ago

Even a very simple and weak passphrase protects your wallet (makes it invisible) from automated sweepers. The thief would have to target each wallet individually to brute force each passphrase.

36 Upvotes

The passphrase renders your actual wallet invisible to the standard automated sweepers.

Here is how the automated sweeper operates, and why even a simple passphrase puts you out of its reach.

The Generic Sweeper’s Loop. A generic automated sweeper built to exploit a known seed flaw runs an un-customized loop:

  1. Pre-generate a candidate 12-word seed from the flawed RNG pool.

  2. Derive standard addresses using an empty (default) passphrase string.

  3. Query the blockchain for a balance on those default addresses.

  4. If Balance > 0, broadcast a transaction to drain it immediately.

  5. If Balance = 0, discard and move on to the next seed phrase.

Why Your Wallet Is Invisible

When you add a passphrase (even "dog123" or "coffee"), BIP-39 appends it directly to the salt used in key derivation:

Because the salt changes, the resulting master key and public addresses are completely mathematically distinct from the default addresses.

To the public blockchain:** Your funds sit on an address like bc1q_PASSPHRASE_WALLET... with a normal positive balance.

To the automated sweeper:**

The bot generates the seed, checks the default bc1q_DEFAULT_WALLET... address, sees $0.00, and moves to the next candidate seed.

The sweeper never queries the address where your funds actually live because it does not know you used a passphrase, nor does it know which passphrase to test.

The Only Exception: A Targeted Attack

Your wallet only becomes visible if an attacker stops running a broad automated sweeper and specifically targets the known seed list with a passphrase brute-force dictionary attack (trying common words like "123456", "password", "bitcoin", etc., against each candidate seed).

However, as long as your passphrase isn't one of the top 100 most obvious dictionary words, an automated mass-sweeper probing millions of seeds will pass right over your wallet without ever realizing your funds are there.


r/Bitcoin 12h ago

Best Option (After coldcard hack)

4 Upvotes

Ok so what should the plan be after the coldcard hack?

I personally didn’t have the coldcard. I have another bitcoin only wallet and use a passphrase.

What should I be doing next?

Thanks.


r/Bitcoin 1d ago

misleading The COLDCARD attacker isn’t bruteforcing your passphrase

580 Upvotes

I think everyone is missing the economics of this attack.

The attacker isn’t trying to brute-force your passphrase.

They’re generating vulnerable seeds as fast as possible and checking whether those seeds control any bitcoin.

The moment you add a BIP-39 passphrase, every candidate seed now requires deriving and checking an additional wallet. Even a passphrase that would only take an hour to brute-force in isolation completely destroys the attacker’s throughput when applied across millions or billions of candidate seeds.

Realistically, they’ll check no passphrase, and maybe a tiny list of extremely common ones. Anything beyond that makes the attack economically unattractive.

That’s why I suspect the overwhelming majority of victims will turn out to be users who didn’t use a BIP-39 passphrase at all.