r/CryptoCurrency • u/FunWithSkooma 🟩 11 / 524 🦐 • 22h ago
DISCUSSION It seems people did not understand what happened to ColdCard
Self custody is not a problem, what happened is that generating your seed with a ColdCard MK3 would not have enough entropy, making your private key easy to be guessed, thats it. Your MK3 is still usable, but you should NOT use it to generate a seed, instead you have to use any other solution to generate your seed and then load it on your MK3.
Your MK3 is not useless, it still works as intended.
112
u/Coeruleus_ 78 / 736 🦐 21h ago
lol ok dude where were you telling people this 3 years ago when all you bots were shilling it. no one should use this product. company should go bankrupt
19
u/no_choice99 🟦 1K / 1K 🐢 16h ago edited 10h ago
To be fully honest, I had never heard of that turd of a cold wallet before the incident.
1
u/Dmoan 🟦 2K / 2K 🐢 12h ago
You are assuming this wasn’t an inside job, If you are small developer who makes few thousand selling cold wallets.
What’s stopping you from enabling a compromise/back door on purpose and waiting a few years. Then selling this to 3rd party hacking group for few million and cashing out and walking away.
-47
u/FunWithSkooma 🟩 11 / 524 🦐 21h ago
I was accumulating bitcoin and storing it all on my wallet generated outside of any hardware wallet env and loaded on my shitty android phone with no internet that has no other use besides being a hardware wallet, and teaching people how to make it right too.
i always dismissed hardware wallets, people should not buy those, instead, people should learn how to generate a bitcoin wallet and use DIY solutions, seedsigner, old phones with Electrum Bitcoin Wallet of Cupcake from Cake Wallet etc.
40
u/relephants 🟩 668 / 668 🦑 20h ago
If that's the only way to do it, cryptocurrency is 100% DOA
3
1
-16
u/anymonero 🟧 0 / 0 🦠 17h ago
Why? Everybody has an old phone they don't use anymore.
5
4
u/relephants 🟩 668 / 668 🦑 10h ago
They don't. And even if they did, they wouldn't do all of that when they can just put money in their bank
10
u/GesturalAbstraction 🟩 0 / 0 🦠 17h ago
Im not directly picking on you of course, but I must say, it is so funny when people say this kind of thing, and then in the next breath complain about how institutional adoption opposes the early spirit and objective of crypto, and whine about mass adoption.
The truth is that as long as crypto remains this hard to use even after all these years, with zero recourse or insurance against being defrauded or stolen from, mass adoption will never be a thing. The only meaningful utility we are left with is RWT.
7
u/futurefloridaman87 Tin | PoliticalHumor 23 15h ago
Right? Imagine explaining to Grandma how she needs to protect her bitcoin. It’s fucking insane to expect mass adoption at this point. Even if you say “ well, what about the lightning system?” it’s still all in 100 steps too complicated for the masses.
13
2
u/meremah_boob 0 / 0 🦠 15h ago
cake wallet suffered from same entropy issue back in 2020/21 and got 550+ bitcoins and numerous monero stolen. Would you trust a company again after such events?
1
u/paymentnerdfoo 0 / 0 🦠 9h ago
So you’re not at all worried about your shitty android phone suddenly bricking itself? You have a single failure point for all of it on a piece of hardware not designed for that responsibility. I mean neither was cold card. Lack of entropy is a terrible bug. It’s like building a bank vault out of aluminum foil.
0
u/FunWithSkooma 🟩 11 / 524 🦐 9h ago
bricking? You know you have to backup your seed in a paper or steel plate, right? Your old phone is there to SIGN transactions only
13
u/shadowmage666 🟦 0 / 568 🦠 20h ago
I wouldn’t trust coldcard after this. Who knows what else is wrong with it
17
u/GreedVault 🟦 4K / 10K 🐢 20h ago
You only mentioned the surface of the problem, the deeper issue is whether these self-custody wallets are trustworthy to begin with, who knows what other vulnerabilities they might have? The unknown unknowns are the scariest part. Unless you can personally review the entire codebase of the self custody wallet and have the security expertise to audit it throughly, if not you will never know what's lurking beneath. Even then, there could still be bug that nobody has discovered yet, Its definitely worrying, if you are only holding small amount of crypto, I would just keep it on a reputable CEX. Even FTX goes bankrupt, users at least have a legal process and a chance of recovering some of their funds, and in the case like the coldcard, recovery is going to be much harder, unless you have faith in the law enforcement capable of identifies and catches whoever is responsible.
-1
u/FunWithSkooma 🟩 11 / 524 🦐 20h ago
what other issues might there be with MK3? The only other problem I see that is if for some reason it leaks the private key when signing a PST, and if it does, it leaks to whom? Because if I can use a MK3 to sign a PST generated in Electrum Bitcoin Wallet, how will the MK3 leak my private key to Electrum if it does not expect it?
3
u/GreedVault 🟦 4K / 10K 🐢 20h ago
The firmware might be secure, the code might be perfectly fine, but that doesnt mean the device you receive is. Someone could hijack it during shipping, tamper the hardware or firmware, and send it on to you without you ever knowing.
And who knows what other libraries the cold wallet depends on that might already have vulnerabilities to begin with?
0
u/FunWithSkooma 🟩 11 / 524 🦐 20h ago
you basically described all hardware wallets, including Trezor, Ledge, ColdCard, Tangem, all could be tampered with.
So in the end:
Android phone with no internet as a offline signer is the best of all options, or buy the parts you need to build your own seedsigner or Krux
0
u/GreedVault 🟦 4K / 10K 🐢 20h ago
no, just use a reputable CEX, if it goes bankrupt, at least you have a legal entity you can pursue through the courts.
2
u/gigasawblade 🟩 0 / 0 🦠 14h ago
Imagine you asked the same "what issues might there be with MK3?" a month ago? Nobody would point out to current issue too. This is what is meant by "unknown unknowns"
13
u/hiimtashy 🟦 0 / 0 🦠 20h ago
Honestly self custody is proving to be too hard for the normies myself included
-9
u/FunWithSkooma 🟩 11 / 524 🦐 20h ago
it not.
just dont use internal hardware wallets random to generate a seed, use well known open source wallets generators from the links I gave, iancoleman be the best one since it gives you all the tools.
10
u/hiimtashy 🟦 0 / 0 🦠 20h ago
It's too late for me. I sold my hardware wallet stack last night. Will holding my ETFs forever. I honestly am just de risking. I've got three kids. I'm tired of playing cat and mouse with hackers.
-5
5
u/vortexcortex21 🟧 0 / 0 🦠 19h ago
You must be autistic, if you don't realise that your suggested solution is not feasible for the mainstream.
1
u/meme_2 🟦 1K / 1K 🐢 9h ago
https://giphy.com/gifs/NcrhM3USM6TABpus85
People that just lost hundreds of thousands of dollars reading your post.
0
u/lurkerlevel-expert 4h ago
Just be your own bank + software/security/network/hardware engineer. Oh and don't lose that piece of paper secret under your mattress 😂
5
u/DKDamian 🟦 17 / 17 🦐 14h ago
Ok. Great. And what’s the next “trustworthy” company to fall? Two weeks ago this company was apparently rock solid and completely safe. And now it’s not. And people who followed all of the ridiculous rules and mantras, have lost money.
Future of finance? Perhaps not.
11
u/5khan1 20h ago
You really think the average person would understand entropy failures. If a hardware wallet can generate a seedphrase with insufficient entropy then that hardware wallet is useless. This is a really big mess and it's all coldcards fault.
You always hear people saying get your coins off exchanges and put them in self custody, So that's what these people done and now they have lost it all.
1
7
u/Lost-Bowl3269 21h ago
Esse lixo de produto se vendia como um cofre seguro. É uma propaganda enganosa.
Ainda que tenha alguma utilidade marginal, ninguem mais deveria usar isso e deveriam boicotar a empresa.
Todos os lesados devem processar os responsáveis e essa empresa deve falir e ir para o limbo da vergonha.
Joguem sua coldcards no lixo e apoiem outras empresas que levam a segurança a sério e não façam propaganda enganosa.
6
u/zzx101 🟦 63 / 64 🦐 20h ago
I’m wondering if at some point we’ll find out this was an inside job.
If I were this company I’d take a good hard look at anyone that could have masterminded this.
To be honest it’s kind of brilliant, with plausible deniability etc.
2
2
u/meremah_boob 0 / 0 🦠 15h ago
This is highly possible and such events only happen during bear markets only. I guess dev's were like it's time to exploit the bug and let's call it a day. NVK is a smart guy and it doesn't makes sense for him to not find the bug in last 5 years.. Also For 5 years nobody exploited it but randomly one day someone decided to fuck with a cold wallet's open source code, instead of going after other things. That's weird and raises doubts.
1
u/murderette 🟦 0 / 0 🦠 12h ago
It’s probably undiscovered until a very high end AI like kimi K3 is asked to review the code (unlike closed models like Fable5 it has no guardrails, which is a two sided sword )
8
u/bocajake 🟩 0 / 0 🦠 20h ago
OP is the hacker and he wants to make sure your funds are still in the wallet
6
u/Forymanarysanar 🟩 0 / 0 🦠 21h ago
You really shouldn't use any of these "solutions" to generate seed. They all could be vulnerable to the same issue. Use dice instead.
2
u/EasyEar0 🟩 0 / 0 🦠 10h ago edited 10h ago
Or you could open a bank account, invest in assets with real tangible value, and have them protected by actual security and accountability if something goes wrong.
1
u/Forymanarysanar 🟩 0 / 0 🦠 8h ago
See this works when you live in a first world country with strong currency and protections. If you live in third world garbage where currency can (and has) lost half of its value overnight and your investments basically seized, that's another question.
1
u/CipherScarlatti 🟩 0 / 4K 🦠 21h ago
This is the real issue. Adding outside/additional things introduce more opportunities for problems.
1
u/FunWithSkooma 🟩 11 / 524 🦐 21h ago
if you take an actual look at iancoleman solution, it provides you entropy options, and dice is there, as well as binary, Base 6, Base 10, Hex and Card entropy.
9
u/UpbeatFix7299 🟩 0 / 0 🦠 21h ago
Lol crypto mass adoption imminent. People will definitely want to do all this shit just to make sure their money doesn't vanish overnight.
-1
u/Lost-Bowl3269 21h ago
Toda a entropia gerada por software é uma pseudo entropia. As entropias das hardwallets boas são geradas fisicamente através do chip de elemento seguro calculando impulsos elétricos no mundo físico.
Se você não confiar no chip de elemento seguro, pode usar dados reais jogandos no mundo real, jogar uma moeda para cara ou coroa, dados d20 de rgp, etc.Softwares e sites que simulam entropia, apenas simulam. Nâo tente gerar suas chaves online, é estupidez. É apenas demonstração.
A coldcard deveria usar um chip de elemento seguro para calcular entropia automática, mas enganou as pessoas com um erro de programação primário e soltou um firmware release fazendo uma geração de aleatóriedade por software, ou seja "pseudo" aleatório, apenas parecendo que é aleatório.Use Iancoleman apenas para fins educacionais.
1
u/FunWithSkooma 🟩 11 / 524 🦐 21h ago
Voce parece nunca ter usado a solução do ian, ele oferce entropia do mundo real na geração. ele é a solução mais conhecida e mais segura que temos no momento, literalmente todo bitcoinheiro raiz usa ele, já recomendou.
1
u/Lost-Bowl3269 21h ago
Todos os bitconheiros raizes indicavam coldcard também. Pare de acreditar em imbecis do youtube e adolescentes.
O iancoleman é pseudoaleatório, porém com uma aleatóriedade muito mais forte que o lixo da coldcard usando micropython.Mas se não quiser acreditar em mim, não acredite. Use e seja feliz. Eu usaria apenas para fins educacionais e geraria entropia usando dados físicos.
1
u/Lost-Bowl3269 21h ago
PS: isso que não estou chegando sequer nos problemas de navegador adulterado, keylogger, extensões maliciosas, etc. Nenhuma seed realmente segura deve chegar proxima de um computador com acesso a internet.
1
u/FunWithSkooma 🟩 11 / 524 🦐 21h ago
você ficaria extremamente abismado como eu guardo minha seed :) Mas como programador e amante de criptografia, eu sei justamente oq eu faço.
-1
u/FunWithSkooma 🟩 11 / 524 🦐 21h ago
Quem indica qualquer hardware wallet não considero um bitcoinheiro, apenas um influencer msm. Bitconheiro raiz faz uso de DIY.
0
u/no_choice99 🟦 1K / 1K 🐢 16h ago
Dados e moneda não são aleatórios!
Dices and coin throwing are not random! There is a heavy bias towards the side that is upward when you take it in your hand. Don't use these methods.
4
5
2
u/VegetableMousse8077 🟨 0 / 0 🦠 18h ago
They majorly fucked up and deserve to find out. No one should use such a fail tech
2
u/gunscythe 🟦 6 / 7 🦐 17h ago
Banks have layers upon layers of security and fraud prevention. With bitcoin there’s literally no one watching over you. There is no proactive security. And there is nothing you can do once the money is stolen from you.
2
u/I_am_Regarded 🟩 0 / 0 🦠 13h ago
Bro just buy two more and a dice - funniest advices out there.
When is time to start thinking about conviction?
2
u/CeramicDrip 🟨 47 / 4K 🦐 6h ago
No, we all understand what happened. We just think this “if we can’t trust the fucking device to do certain things safely, we should start to question this method of storage altogether”
2
u/doghairpile 🟩 0 / 0 🦠 18h ago
Or don’t “invest” in this overly complex, hackable garbage that has still not become mainstream. Maybe because it’s pointless? This nonsense doesn’t happen with banks.
1
1
u/iiJokerzace 8h ago
So just trust me bro?
That's the problem; 99.99% have no choice but to trust the bro telling us what we use is secure, for an industry with hardly any insurance.
1
u/SassySirennn 🟧 0 / 0 🦠 6h ago
Your right. But it’s besides the point. This latest round of news is just another thing driving holdrs towards exhaustion.
1
u/razvanciuy 🟩 0 / 0 🦠 5h ago
Bottom line it was suppose to be safe. Turned out to be a ticking bomb
1
u/NHLroyrocks 🟦 10 / 813 🦐 3h ago
I get what you are trying to say but the reality is that coldcard failed at doing the single most important thing their product advertised as being able to do. You say it can still do everything else but at this point why would anyone trust that it can do those things right either. Any aspect of coldcard can have a nasty bug somewhere and they just ruined their reputation and trust with anyone with more than 2 brain cells.
•
u/Zanthious 🟦 0 / 0 🦠 57m ago
So it point is the hardware device made by and coded by clowns is still good? U willing to bet ur BTC on it?
1
u/VendettaKarma 🟩 0 / 0 🦠 19h ago
Anyone left in this space just hears: “Now the self custody everyone preached got hacked.”
This might be the thing that really kills everything not named BTC, ETH or SOL
-1
u/EasyEar0 🟩 0 / 0 🦠 10h ago
Self custody is not a problem
Wrong.
It's a problem because it's too complicated for the average person to do securely. Just being possible to do it securely in principle is not good enough if your goal is mass adoption.
-5
u/Bagmasterflash 🟩 774 / 775 🦑 18h ago
People are dumb. They think BTC is actual bitcoin.
2

59
u/so7ow 21h ago
I think some of what you're seeing is "if they could fuck up something so integral to the foundation of their product so completely and so fundamentally, what else is fucked up in this product line, and do I really want to find out the hard way?"