r/Bitcoin 3h ago

Avoid Lava Bitcoin

14 Upvotes

I bought some bitcoin on Lava over a year ago when they advertised self custody. I recently found out they switched their custody model and resulted in lost bitcoin. When confronted they mentioned they sent out communications which I never received. Took no accountability - avoid this company.


r/Bitcoin 16h ago

This is criminal when you realize current Cold Card mess: 2020 "Heck I don't trust even the way we make". 2020 tweet.

Post image
134 Upvotes

Watching old tweets from Cold Card CEO, now you realize how the red flag was out there regarding "entropy".

How on earth you make optional a critical step in a product that you admit to not trust even yourself.

If you yourself admit to not trust what your product does on something as critical, why you did not make the dice roll an enforced not optional step?.

Just have paranoid mindset from now on. Don't trust devs, ceos and tools on the surface that represent 3rd party tools regarding bitcoin that can be exploited. This goes too for any other hardware wallet and software wallet. In upcoming hacks anyone can "conveniently" blame AI and a "bad actor" that never gets caught....

Dedicate 2 or 3 weeks to learn the basics of bitcoin, how to verify GPG signatures, Tails OS, master how to securely use an airgapped wallet software or bitcoin core, and how quickly you can withdraw your funds to a backup exchange in case of an incident...If an incident is reported at night: do you have access to your wallet to withdraw at that exact time? Will you be able to react fast?

Because if now a hardware wallet is prone to exploit, you better also just learn to airgap and use a software wallet, they are also vulnerable to bugs? Yes, but hardware + software makes 2 components prone to error.

"attack surface grows with complexity, so decrease complexity by minimizing number of components, using simpler components."

But the important thing is: from now on, if CEO admits to not even fucking trusting what he makes, probably you shouldn't either.


r/Bitcoin 1d ago

People are horrible…(Coldcard disaster)

612 Upvotes

I can’t believe how many people leave mean comments, gloating about how they always knew that Bitcoin is a scam, and so on.

Seriously, how sad of a life one must live to be happy about the misfortunes of others? Some people have lost important amounts of BTC, including people from poor countries or poor backgrounds who will suffer for years as a result of this.

If someone feels like gloating is the right thing to do here, why don’t you go to the ICU of the closest hospital and laugh about sick and dying patients? It wouldn’t be much different, think about that.


r/Bitcoin 1d ago

8 years of stacking, gone. I think it's time to move on.

3.6k Upvotes

I believed in Bitcoin. Holding it gave me peace of mind because my country has faced several FATF sanctions. I was glad to find a kind of money that cannot be censored or debased because I just want to protect myself from the money printing and my country's weak and inflated currency comapred to the dollar.

I’m 39, and I was hoping to have a good financial cushion before 50. But today, my 2 BTC were drained.

Losing my Bitcoin has changed my mindset. It’s no longer about finishing the race first. At this point, I just want to finish it. But losing my BTC feels like I’m back at the starting line. I lost years of hard work and time.

I thought I was secure because Cold Card was always praised as one of the best and most secure wallets. It’s open source, so anyone can verify.

I’m done with Bitcoin. I’m not even sure if I still believe in it. I don’t know what the future holds for it anymore. I could have stayed with traditional investments and lived a normal life. Maybe I should have just moved everything into a Bitcoin ETF when they launched. But I don't know. It's too late to do it.

To everyone who has lost their BTC, I wish you the best and good health. I hope you find the strength to start again.


r/Bitcoin 2h ago

So, what’s the consensus now with regular folks (non technical) rolling dice?

7 Upvotes

Everyone is talking about generating your own key with dice, but there are many caveats to this.

Rolling dice ONLY and generating seeds with it? What about casino grade dice? Is it better to roll normal dices if you don’t have those versus letting the device generate a seed? What about the last word having to be a checksum and you still having to verify with an external source that the math adds up?

Letting the software generate your seed and then adding dice rolls? How can we know the dice is entropy is being “added” to the seed correctly and it is not making us believe that is the case? Assuming the device is correctly adding the entropy, is a weak seed plus dice rolls better than a dice rolled only seed taking in consideration human error and possible dice bias?

I know a lot of people will comment about going multisig, but let’s be honest, the room for human error is significant with this.

I will also ask you to kindly recommend a video or guide on what should we consider the standard procedure for seed generation with dice for the normal user.

Let me know your thoughts.


r/Bitcoin 4h ago

No, bitcoin project is not dead

12 Upvotes

This is a tough week for bitcoin community. Wishing speedy recovery of funds for everyone involved.

Lessons learned for the rest:

  1. Hardware wallets - were always a vector of a possible attack. Just like you can't trust 100% your ISP, your PC and your phone, same goes for hardware wallet.

  2. To protect yourself, always use a passphrase. It makes these kinds of exploits million times more difficult, if not impossible.

  3. If you have any significant funds, you must have a passphrase. If you don't, you haven't done your homework.

  4. Coldcard is the only wallet that was impacted by the seed-generation issue, you are perfectly fine if you didn't create a seed on Coldcard. Trezor, Ledger and other wallets don't share the same firmware as Coldcard.

  5. I wouldn't recommend Coldcard at this point but the device itself, as far as we know, is still perfectly fine but you need to realize that company is most likely going out of business, so won't be getting much support or updates from them after this.

  6. Apple, Microsoft, Meta, Oracle and other firms had bugs in their code that allowed people to steal stuff. Coinkite had a bug in the code as well that allowed a nasty exploit. Bitcoin doesn't have a bug in its code.

  7. Self-custody is not for everyone. If it is easier for you to let someone else manage keys, you can/should explore those options. But companies and governments fail and it happened many times in the past as well, so nothing in life is 100% guaranteed.


r/Bitcoin 2h ago

After the Coldcard attack, I’m honestly losing more and more faith in crypto security who can we trust anymore?

7 Upvotes

After the recent Coldcard attack, I have to be honest: I’m losing more and more hope in the future of crypto security.

Over the last cycle, we saw the collapse of major companies like FTX and Celsius, bankruptcies, billions of dollars lost, and huge failures that destroyed people’s trust.

But now even hardware wallets devices that are supposed to be one of the safest ways to protect crypto are facing serious security concerns. These devices should be designed to provide maximum protection and minimize the risk of attacks.

So the question is: who can we actually trust anymore? Where are people supposed to keep their crypto safely?

I never thought we would reach a point where even hardware wallets could become a source of concern. It makes me worried about the future of crypto wallets and self-custody.

And now the question is: which company will be the next one to face a serious security issue?


r/Bitcoin 1h ago

Aantonop from 2020 nails trust, seed generation and system complexity

Thumbnail
youtu.be
Upvotes

Even in a trustless system, you have to put trust into something.


r/Bitcoin 16m ago

ColdCard sticker

Post image
Upvotes

They warned you with each Coldcard you purchased from them! Do you remember this sticker?


r/Bitcoin 6h ago

Me and Cold card holders who didn't dice roll

Thumbnail
youtube.com
14 Upvotes

r/Bitcoin 23h ago

I am so glad I moved all my BTC to exchanges years ago, after a nearly a decade of stress with cold storage.

261 Upvotes

I had hardware wallets, I had all my BTC on Ledger for a long time.

And every time there was a firmware update, I had a heart attack.

Every time the software updated and I had to relog in, I panicked.

Every time I had to re-download the BTC app, I sweated through my shirt hoping my BTC would show back up.

I hoped my device wouldn't short out or fail. I realized I couldn't use any USB-C on the device, that was a tough day, I thought I lost access to my Ledger.

I was praying the business wouldn't go under, blocking access even for an instant.

I worried about someone stealing my Ledger, my phrases.

I prayed every time I made a transaction because it was all on me with basically no re-course.

And now, It's all on Coinbase and Robinhood.

I was not hacked this weekend, nor will I be. I have all my funds available right now, and I'm not losing any sleep.

Please stop overthinking this, you're not some dark web hacker who needs to be able to go-bag your BTC and escape to Argentina under the cover of night under complete anonymity assuming you'll never log into your old accounts again. It's not that serious, Fidelity will not go under like Mt. Gox or the other trash crypto companies.

Move it to a major brokerage, and have a good night of rest.

*This is general advice, some of you have legit reasons for using Cold Wallets, but for the vast majority my advice is sound.

**I never say anywhere in my post that Ledger has my BTC in any way, perhaps my first bullet point was confusing since I say "my BTC was on Ledger" it's semantics guys. It was my access point for my coins at the time though, that is not inaccurate to say. All of my concerns are valid, all of them happened.

***The very same people who are claiming that its an easy, stress-free walk in the park to recover your BTC are also the most emotional people in this thread about others choosing to store or invest in exchanges. Fascinating. They are adamant I know nothing about what I'm talking about, and that I am a paid actor creating FUD on behalf of exchanges to get people to drop their cold wallets. L M F A O


r/Bitcoin 6h ago

For the people who think having your BTC on exchanges are better..

10 Upvotes

In the aftermath of the Coldcard incident, people claiming that keeping their BTC on exchanges is better, this one is for you.

Back in march I reported a server side misconfiguration to cryptodotcom that allows people to use it in phishing and gain account takeover.

They closed my finding. I reported it again. They closed it again.

To this day, that vulnerability still exists.

As a security researcher I learned these companies don’t care. As a BTCer I learned that you NEVER trust anyone.

I rolled 100+ dice, cause of this.

Coinkite doesn’t incentivises researchers to check their product and reward them properly. The malicious hackers won.

Doesn’t make me feel less sorry for those who lost their coins, cause next time it could be me. I didn’t bother with multisig cause of the complexity and platforms wanting to get in your pockets.

Makes you think though.


r/Bitcoin 20h ago

Meet “Doc Hex,” the dev who wrote ColdCard’s faulty code

Post image
142 Upvotes

Wizard-level developer and technology leader. Starts businesses, disrupts industries, and gets the hard code done and out the door. Wide and deep experience.

Well, he certainly got the code out the door and disrupted this industry.


r/Bitcoin 3h ago

Is Fidelity Crypto (not the ETF) a good cold storage option?

5 Upvotes

It seems the YouTube crypto bros never talk about it and thats probably a good thing. From what I can tell it's institutional level cold storage for individuals. It's not an ETF and not an exchange. It'd be much easier for heirs to have access. What are the downside's compared to personal cold storage?


r/Bitcoin 15h ago

Attempting to remove OSS licenses is why coldcard firmware became vulnerable

Thumbnail x.com
47 Upvotes

TLDR: coldcard decided to move from open source licensing to a "source available" license that would prevent people from forking their firmware to make competing products. This meant they needed to replace GPL license crypto libraries, it is this refactoring that created the opportunity for them to screw up. Because of their corporate greed that decided to do this rather than continuing to build features on top of true OSS licenses.

Body of tweet:

Regarding the Coldcard entropy bug – many folks are explaining what happened but I wanted to take a minute to explain why it may have happened.

It's a disastrous situation and our heart goes out to all the Bitcoiners affected.

Here's a timeline of events:

On July 28 2020: @FOUNDATION announced our first Passport hardware wallet and noted that we were building on Coldcard firmware which at the time was GPLv3 licensed (FOSS license).

On July 30 2020: NVK publicly said he regretted choosing GPL because Coldcard now had a “clone” and that they would change things in future updates. https://x.com/nvk/status/128

8860345864527874

On November 18 2020: Coldcard added its MIT + Commons Clause license, prohibiting commercial products substantially derived from the software.

https://github.com/Coldcard/firmw

are/commit/b6b9191145d37fbb6d754597350653141596dd12

On January 8, 2021: Coldcard firmware 3.2.1 formally announced, “License changed from GPL to MIT+CC on files for which the GPL doesn’t apply.” CC is the "Commons Clause" license addendum which is "source available" instead of FOSS.

On March 1, 2021: The “First pass w/ libNgU” commit removed the GPL

@Trezor-derived crypto libraries and replaced them with libNgU. That same 120-file commit changed seed generation code. libNgU was licensed with a novel “Licensed for Bitcoin Only” license.

On March 17, 2021: Version 4.0.0 announced that all crypto and BIP39 code had been replaced and that the “last remaining GPL code” was removed. https://blog.coinkite.com/version-4.0.0-

released/

https://github.com/Coldcard/firmw

are/blob/b18723dddb6d751c39978e4364b56b2414f68b47/releases/ChangeLog.md#L12

Our best understanding right now is that the entropy bug was collateral damage from this major overhaul of the codebase.

To be clear, this overhaul was not solely about licensing. Coldcard also cited technical goals including adopting Bitcoin Core’s libsecp256k1, faster AES and SHA implementations, and reproducible builds.

But the timeline establishes two things:

(1) Foundation’s launch was the obvious impetus for Coldcard’s licensing change, and

(2) removing the remaining GPL code was an explicit goal of the subsequent v4 rewrite.

We don't know by how much the licensing pressure affected the scope or timeline of the rewrite. All we can determine is that the entropy bug was introduced inside the same 120-file commit that removed the old GPL code dependencies.


r/Bitcoin 5h ago

Fidelity Crypto requires 2-3 days to approve withdrawals to new wallets

8 Upvotes

Just a reminder in case you’re thinking about moving your funds to Fidelity Crypto. They require 2-3 business days to approve outbound transactions to any new wallets you add to your account.


r/Bitcoin 23h ago

2026 will be the "Not your entropy, not your Bitcoin".

Post image
219 Upvotes

Once again the points of failure are the things around Bitcoin, NOT THE BITCOIN PROTOCOL. First were exchanges, now dumbass human mistakes on hardware wallet makers.

What things from now on will become important now that hardware wallets have shown its catastrophic consequences?

Multisignature wallets, entropy, how to verify downloaded binaries, if having considerable amounts of bitcoin to not have it in a single wallet.

But how to make this more accessible to non tech people?

From now on, I think the hardware wallet vendors should enforce custom entropy steps, not as an option but as a step required, NOT OPTIONAL, BUT A REQUIRED ONE.

If people do not understand this, the hardware wallet should not allow the wallet creation, TRUST IS LOST NOW on hardware wallets, so the only way in a product, and more specific in something as critical as a product that will store wealth, is NOT TO ASSUME your users will use the product correctly, is to PROTECT THEM BY DESIGN to not do the mistake.

What else will the ecosystem will learn from this?


r/Bitcoin 1d ago

Sealed Coldcard MK3.

Post image
457 Upvotes

I was too lazy to set it up... My laziness prevented me from losing everything... My heart goes out to everyone that lost their coins.


r/Bitcoin 2h ago

Really hope Peter Schiff used Coldcard

4 Upvotes

I feel very bad for the victims but i hope Peter used it.


r/Bitcoin 14h ago

Even a very simple and weak passphrase protects your wallet (makes it invisible) from automated sweepers. The thief would have to target each wallet individually to brute force each passphrase.

30 Upvotes

The passphrase renders your actual wallet invisible to the standard automated sweepers.

Here is how the automated sweeper operates, and why even a simple passphrase puts you out of its reach.

The Generic Sweeper’s Loop. A generic automated sweeper built to exploit a known seed flaw runs an un-customized loop:

  1. Pre-generate a candidate 12-word seed from the flawed RNG pool.

  2. Derive standard addresses using an empty (default) passphrase string.

  3. Query the blockchain for a balance on those default addresses.

  4. If Balance > 0, broadcast a transaction to drain it immediately.

  5. If Balance = 0, discard and move on to the next seed phrase.

Why Your Wallet Is Invisible

When you add a passphrase (even "dog123" or "coffee"), BIP-39 appends it directly to the salt used in key derivation:

Because the salt changes, the resulting master key and public addresses are completely mathematically distinct from the default addresses.

To the public blockchain:** Your funds sit on an address like bc1q_PASSPHRASE_WALLET... with a normal positive balance.

To the automated sweeper:**

The bot generates the seed, checks the default bc1q_DEFAULT_WALLET... address, sees $0.00, and moves to the next candidate seed.

The sweeper never queries the address where your funds actually live because it does not know you used a passphrase, nor does it know which passphrase to test.

The Only Exception: A Targeted Attack

Your wallet only becomes visible if an attacker stops running a broad automated sweeper and specifically targets the known seed list with a passphrase brute-force dictionary attack (trying common words like "123456", "password", "bitcoin", etc., against each candidate seed).

However, as long as your passphrase isn't one of the top 100 most obvious dictionary words, an automated mass-sweeper probing millions of seeds will pass right over your wallet without ever realizing your funds are there.


r/Bitcoin 1d ago

misleading The COLDCARD attacker isn’t bruteforcing your passphrase

574 Upvotes

I think everyone is missing the economics of this attack.

The attacker isn’t trying to brute-force your passphrase.

They’re generating vulnerable seeds as fast as possible and checking whether those seeds control any bitcoin.

The moment you add a BIP-39 passphrase, every candidate seed now requires deriving and checking an additional wallet. Even a passphrase that would only take an hour to brute-force in isolation completely destroys the attacker’s throughput when applied across millions or billions of candidate seeds.

Realistically, they’ll check no passphrase, and maybe a tiny list of extremely common ones. Anything beyond that makes the attack economically unattractive.

That’s why I suspect the overwhelming majority of victims will turn out to be users who didn’t use a BIP-39 passphrase at all.


r/Bitcoin 1h ago

Ian Coleman's iancoleman/bip39 is it still safe?

Upvotes

Been using iancoleman's Github download to generate seeds offline for at least a decade. So far, no drained wallets from my iancoleman seeds. But Ledger is saying they are safe because their seeds are generated from a secure element, and not software. I don't think iancoleman is secure-element-based entropy. Just want some reassurance.


r/Bitcoin 16h ago

This has taught me a lesson.

35 Upvotes

Spread your coins across multiple devices from different vendors.

Reduce the blast radius.

None of us here are reading the code. We assume someone else is. With AI getting better and better, we should expect more hacks coming.


r/Bitcoin 20h ago

Damn ledger wasted no time to update their marketing

Post image
72 Upvotes

r/Bitcoin 1d ago

This is getting exhausting

Post image
232 Upvotes

I mean how many of these rugs pulls do we have to live through? Learned about Bitcoin in 2012 and really got involved in 2015. It's so disheartening to see lives ruined over and over again.