Bitcoin hits $125k - 10/4/25 (Page 615 of 618)
|
I'd love to see them track this fucker down. Coldcard Bitcoin Thief Likely Used Top Blockchain Since over $70 million in Bitcoin was stolen yesterday by an attack that exploited a fault in the Coldcard’s system, it has been reported that the thief used a top blockchain services provider for help. Writing on X Friday, engineer at payments company Block, Clay Garrett, said that the provider — who he did not name at the request of the services provider — had been contacted after finding blockchain movements matched the “suspected workflow” of the attacker. “During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps,” Garrett said. “That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps,” Garrett continued, adding that the authorities had been notified. Galaxy Digital’s research arm also wrote on X that the thief had an unusual pattern of moving the coins. “The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins,” the company said, adding that Bitcoiners should move funds out of single-signature Coldcard addresses and into secure custody. |
|
Helpful iPhone changed my text. I edited it to ATH. Yup been skittering sideways for a looong time. Gave me more time than Han I thought to keep buying. My Mt Gox comment was just to try and equate what happened with Coldcard and the sentiment around it being I something else that had happened in the past. As our resident shuttle door gunner, @woodsie has spoken about. Not sure what the “crash” will look like or what caused it, but something will happen. I get this is waaaay after the 50% decline so it’s not the catalyst for that. |
|
Originally Posted By swampvol: so what does this hack mean for us who hold our btc in Trezor or Ledger?? As of now, it doesn’t affect those including blockstream jade. Although this is what I’m talking about when I said faith is being tested. Coldcard was at the time, one of the most respected and suggested wallets. With it taking a big steaming shit, I don’t like current sentiment. |
|
Originally Posted By swampvol: so what does this hack mean for us who hold our btc in Trezor or Ledger?? Originally Posted By swampvol: so what does this hack mean for us who hold our btc in Trezor or Ledger?? In short, this hack was limited to Coldcards because of a negligent oversight on their part. From the article I posted above: Coinkite said that a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator. This allowed private keys for many single-signature wallets (especially those created without dice rolls or a strong BIP-39 passphrase) predictable enough for attackers to brute-force. Trezor and Ledger have both issued statements on this.
|
|
Ledger has their own set of problems. -They've leaked customer info multiple times. -Their devices are garbage and screens die all the time. -For years they said keys couldn't be extracted then they launched a paid service that does exactly that -They promote exchanges and mixers in their app that exist only to steal people's crypto But this particular exploit they are not vulnerable to. |
|
Originally Posted By Brahmzy: Thanks @P400 ^^ No problem. Honestly, it's upsetting to see this happen to anyone, even if the cause can be compared to buying a new gun safe and keeping the factory combo. People have been posting their losses and drained wallets on some of the other crypto forums. Many lost what I would consider to be life-changing amounts of money. |
|
Originally Posted By Fooboy: What is the most solid wallet these days? Sparrow is great software that you can use to create your own multisig setup using multiple hardware wallets. Also collaborative custody with places like Unchained or Casa. |
-- Thomas Paine, "filthy little atheist"
|
Originally Posted By P400: In short, this hack was limited to Coldcards because of a negligent oversight on their part. "negligent oversight" is putting it mildly if the commentary about the root cause is true. One of the founders apparently disabled the hardware RNG and committed the change with the comment "runs". |
|
Returned from a long vacation to Alaska and just checked in on this thread this morning. Glad I did. Did some research on what to do and moved my coin. None was lost. Apparently my mk4 coldcard was impacted, but less severely than the mk3 and earlier versions. The firmware upgrade process was not difficult, but the migration process from a compromised seedphrase wallet to a newly generated fixed seedphrase wallet was a little tricky when using a single coldcard. This sucks. I really want to continue using it and I want self-custody to become more mainstream. Going to have to do more research. On the plus side, I learned a lot today and I didn't lose any money. |
|
Originally Posted By Torf: Returned from a long vacation to Alaska and just checked in on this thread this morning. Glad I did. Did some research on what to do and moved my coin. None was lost. Apparently my mk4 coldcard was impacted, but less severely than the mk3 and earlier versions. The firmware upgrade process was not difficult, but the migration process from a compromised seedphrase wallet to a newly generated fixed seedphrase wallet was a little tricky when using a single coldcard. This sucks. I really want to continue using it and I want self-custody to become more mainstream. Going to have to do more research. On the plus side, I learned a lot today and I didn't lose any money. Good to hear. What a massively shitty situation for Coldcard users. |
|
I have a feeling ledger and others will have their day in the spotlight Originally Posted By sunnybean: Good to hear. What a massively shitty situation for Coldcard users. Originally Posted By sunnybean: Originally Posted By Torf: Returned from a long vacation to Alaska and just checked in on this thread this morning. Glad I did. Did some research on what to do and moved my coin. None was lost. Apparently my mk4 coldcard was impacted, but less severely than the mk3 and earlier versions. The firmware upgrade process was not difficult, but the migration process from a compromised seedphrase wallet to a newly generated fixed seedphrase wallet was a little tricky when using a single coldcard. This sucks. I really want to continue using it and I want self-custody to become more mainstream. Going to have to do more research. On the plus side, I learned a lot today and I didn't lose any money. Good to hear. What a massively shitty situation for Coldcard users. |
|
Originally Posted By Torf: Returned from a long vacation to Alaska and just checked in on this thread this morning. Glad I did. Did some research on what to do and moved my coin. None was lost. Apparently my mk4 coldcard was impacted, but less severely than the mk3 and earlier versions. The firmware upgrade process was not difficult, but the migration process from a compromised seedphrase wallet to a newly generated fixed seedphrase wallet was a little tricky when using a single coldcard. This sucks. I really want to continue using it and I want self-custody to become more mainstream. Going to have to do more research. On the plus side, I learned a lot today and I didn't lose any money. I would imagine the bug is fixed now but hard to trust the company now, I would bet they get sued as their faulty product caused the damage and not really the fault of the customer who thought they were secure with the seed phrases. I bought a Coldcard Q awhile back as I did want all my btc on Ledger, was gonna put new purchases on the Coldcard. I haven't gotten around to moving all my latest purchases to storage yet, guess it's a good thing I was slacking about getting my funds moved to my Coldcard Q. My newest purchases will just remain on the exchange until I figure out where's a good place to store it. |
|
Originally Posted By Nosler180: I would imagine the bug is fixed now but hard to trust the company now, I would bet they get sued as their faulty product caused the damage and not really the fault of the customer who thought they were secure with the seed phrases. I bought a Coldcard Q awhile back as I did want all my btc on Ledger, was gonna put new purchases on the Coldcard. I haven't gotten around to moving all my latest purchases to storage yet, guess it's a good thing I was slacking about getting my funds moved to my Coldcard Q. My newest purchases will just remain on the exchange until I figure out where's a good place to store it. I do think they owned up to it quickly, and they patched it fast. I do think they will go nuts trying to figure out any further issues. Not sure in the long run, but I'm using a patched device for now. Feeling lucky I didn't jump on the hardware storage bandwagon earlier. I most likely would have ended up with an mk3 instead of a 4.
|
|
Originally Posted By sunnybean: Yeah, it’s a good time for everyone to reassess their storage strategies. Originally Posted By sunnybean: Originally Posted By Lorduss: I have a feeling ledger and others will have their day in the spotlight Yeah, it’s a good time for everyone to reassess their storage strategies. Yup. Just set up a multisig wallet with a ledger and blockstream jade and a software key on sparrow. It was what I had on hand at the moment. Getting a trezor to take th eplace of the software key though. |
Thought this was interesting. For those that are saying its an uninvestable asset due to no recourse:
|
|
Originally Posted By Ender875: Yup. Just set up a multisig wallet with a ledger and blockstream jade and a software key on sparrow. It was what I had on hand at the moment. Getting a trezor to take th eplace of the software key though. Is there a YouTube tutorial for this? I’m starting to think I’m too boomer to hold btc nowadays.
|
|
Originally Posted By swampvol: Is there a YouTube tutorial for this? I’m starting to think I’m too boomer to hold btc nowadays. ![]() Lol. You and me both! Great (not!) conversation with my wife about how we could have lost everything had I been a bit more tech savy in the begining! There are tons of videos on how to set one up. I used this one most recently. Although he did not go into how to make sure you can restore your wallet before you send the bulk over to it. The link below the video has that info from PlanB. Although, he used the cold card when he made the video! ![]() Sparrow Wallet Multisig | The Most Secure Bitcoin Wallet Set Up ?? https://planb.academy/en/tutorials/wallet/desktop/sparrow-multisig-5860333b-6dd8-4aaa-8ab6-89ebc6276f1f |
A good quick overview of wallets for anyone looking to explore new storage options. IMO the clear takeaway from recent events is definitely don't put all your eggs in one basket.![]() Ranking EVERY Cold Wallet from WORST to BEST! |
|
|
Originally Posted By Caeser2001:
|
![]() He Called the 2025 Cycle. Now He Says Bitcoin's 4-Year Cycle Is Dead. |
|
|
Originally Posted By Ender875: Thought this was interesting. For those that are saying its an uninvestable asset due to no recourse: https://pbs.twimg.com/media/HOxA9NoWEAAN4_x?format=jpg&name=small
Oh there are situations where there is no recourse. Crypto has got a long way to go to convince me it's secure. I lost bitcoin in the SBF debacle. To add insult to injury in bankruptcy they froze the assets and then distributed them to the tune of .30 on the dollar after bitcoin had more than tripled in value. So if you had a $1000 at the time of the bankruptcy you got $300 from an asset worth $3000. Then after all that the bankruptcy administrator got hacked and the little crypto i had left disappeared. |
Necessity is the plea for every infringement of freedom. It is the argument of tyrants; it is the creed of slaves.
|
Originally Posted By P400: I'd love to see them track this fucker down. Coldcard Bitcoin Thief Likely Used Top Blockchain Since over $70 million in Bitcoin was stolen yesterday by an attack that exploited a fault in the Coldcard’s system, it has been reported that the thief used a top blockchain services provider for help. Writing on X Friday, engineer at payments company Block, Clay Garrett, said that the provider — who he did not name at the request of the services provider — had been contacted after finding blockchain movements matched the “suspected workflow” of the attacker. “During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps,” Garrett said. “That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps,” Garrett continued, adding that the authorities had been notified. Galaxy Digital’s research arm also wrote on X that the thief had an unusual pattern of moving the coins. “The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins,” the company said, adding that Bitcoiners should move funds out of single-signature Coldcard addresses and into secure custody. Apparently it's up to around 125 million stolen |
|
Originally Posted By Caeser2001:
It was a pain in the ass finding dice in my house for some reason. The dice games we have were almost all missing their dice. I think my kids have raided them to use on trips with friends playing farkle or zilch. I even considered breaking open the dome in "Trouble" just to use that crappy die. Wish they had an easy way to use a deck of playing cards. Every well shuffled intact 52 card deck has almost as much entropy as 100 dice rolls. (225 bits vs 258 bits) Recording a second deck would more than close that gap. I could have generated a "cards to dice" formula in Excel, but I ended up finding 6 dice in my son's backpack. At the expense of making it harder to get my own BTC with a multi-pass, I am considering which second hardware wallet would be best, so thanks for the post! |
|
Originally Posted By 2tired2run: Oh there are situations where there is no recourse. Crypto has got a long way to go to convince me it's secure. I lost bitcoin in the SBF debacle. To add insult to injury in bankruptcy they froze the assets and then distributed them to the tune of .30 on the dollar after bitcoin had more than tripled in value. So if you had a $1000 at the time of the bankruptcy you got $300 from an asset worth $3000. Then after all that the bankruptcy administrator got hacked and the little crypto i had left disappeared. |
|
Originally Posted By CleverNickname: Unless you wrote your own wallet software or have thoroughly audited the source code of whichever wallet you're using, you're still trusting a third party. |
Lots of recent rumblings and questions about a possible insider angle. ![]() Was Coldcard An Inside Job? |
|
Originally Posted By Fooboy: Fair Originally Posted By Fooboy: Originally Posted By CleverNickname: Unless you wrote your own wallet software or have thoroughly audited the source code of whichever wallet you're using, you're still trusting a third party. So go with the most attacked and most proven third-party software, Core? |
![]() Bitcoin Just Fired a Reversal Signal — Here's the 48-Hour Rule That Confirms It |
|
So using dice…. Is there a way to do this without making a Linux partition, without relying on a generated list etc? All videos I have watched entail rolling the dice, inputting the corresponding numbers into a sheet (so to speak) and a words will pop out when you’re done. I don’t see how that is substantially different than trusting a wallet manufacturer to do it for me. What I want is a list of all the words (which I can verify against other lists) to print out. Then some formula which takes my dice rolls and gives me the letter or word or number to correlate to a seed word. Obliviously the formula would be done by hand. Thanks! |
|
Originally Posted By Ender875: So using dice . Is there a way to do this without making a Linux partition, without relying on a generated list etc? All videos I have watched entail rolling the dice, inputting the corresponding numbers into a sheet (so to speak) and a words will pop out when you're done. I don't see how that is substantially different than trusting a wallet manufacturer to do it for me. What I want is a list of all the words (which I can verify against other lists) to print out. Then some formula which takes my dice rolls and gives me the letter or word or number to correlate to a seed word. Obliviously the formula would be done by hand. Thanks! These two things are substantially the same. There is a correct algorithmic method for converting your string of randomdata into seed words, and the seed words aren't actually the wallet keys anyway. The seed words are simply a representation of a private key that is difficult to remember or type. Behind the scenes, logic can convert the words to your key, and vice versa. The wallet manufacturer is supposed to be using the exact same algorithm that you could probably do by hand, only it grabs data from a hardware random number generator (in addition to other randomness inputs) to mix in with whatever other dice rolls or playing card shuffles or other legit sources of randomness that you can find. We Coldcard users were trusting the random number generator to give us enough randomness to be secure, so in the aftermath things like dice rolls become much more important if applied correctly. If you want to have as much confidence as possible that your address is legit and strong, you might have to program a generator yourself. There are probably dozens of online tools to do this for you however. My guess is that legitimate ones are not hard to find, and doing it yourself could result in disaster unless you are very careful and verify your work against a "good" generater. When I regenerated my Coldcard with fixed firmware, a hash of the private key sits on the screen during dice rolls. Each time you add another dice value, this hash changes. That's how you are being shown that the rolls are having some effect. Once I was done rolling, it presented me with a brand new set of words that was different from the set of words presented before adding dice rolls. That showed me that the dice rolls were accounted for in some way. Its not transparent on that tiny little screen, so maybe using a different wallet generator app or website (offline and airgapped preferably) would help confidence that the system is doing what it says it's doing? So in summary, you don't have to do a Linux partition, but your seedphrase must be compliant with the BIP-39 > BIP-32 > BIP-84 chain process that is common. I believe a list of all the legal BIP-39 words is available. |
|
I see this from Blockstream. Id think downloading it and using it as a hard copy would defeat any spyware that sees which page you flip to and thereby narrowing the potential phrases. What says the hive? https://storage.googleapis.com/dxp-production-assets/content/blockstream-jade/add-more-security-functionality/create-a-recovery-phrase-using-dice/JadeDiceRollsGuide.pdf That link is from this page: https://help.blockstream.com/blockstream-jade/add-more-security-functionality/create-a-recovery-phrase-using-dice |
|
Originally Posted By Torf: I somewhat confused about the "what I want" part and the "all the videos I have watched" part. These two things are substantially the same. There is a correct algorithmic method for converting your string of randomdata into seed words, and the seed words aren't actually the wallet keys anyway. The seed words are simply a representation of a private key that is difficult to remember or type. Behind the scenes, logic can convert the words to your key, and vice versa. The wallet manufacturer is supposed to be using the exact same algorithm that you could probably do by hand, only it grabs data from a hardware random number generator (in addition to other randomness inputs) to mix in with whatever other dice rolls or playing card shuffles or other legit sources of randomness that you can find. We Coldcard users were trusting the random number generator to give us enough randomness to be secure, so in the aftermath things like dice rolls become much more important if applied correctly. If you want to have as much confidence as possible that your address is legit and strong, you might have to program a generator yourself. There are probably dozens of online tools to do this for you however. My guess is that legitimate ones are not hard to find, and doing it yourself could result in disaster unless you are very careful and verify your work against a "good" generater. When I regenerated my Coldcard with fixed firmware, a hash of the private key sits on the screen during dice rolls. Each time you add another dice value, this hash changes. That's how you are being shown that the rolls are having some effect. Once I was done rolling, it presented me with a brand new set of words that was different from the set of words presented before adding dice rolls. That showed me that the dice rolls were accounted for in some way. Its not transparent on that tiny little screen, so maybe using a different wallet generator app or website (offline and airgapped preferably) would help confidence that the system is doing what it says it's doing? So in summary, you don't have to do a Linux partition, but your seedphrase must be compliant with the BIP-39 > BIP-32 > BIP-84 chain process that is common. I believe a list of all the legal BIP-39 words is available. Thanks for the reply. Yeah, not so concise. To me, using the wallets mean I am putting blind trust in the manufacturer. Risk is a bit dispersed since I am (or will be when the Trezor gets here) using 3 different hardware wallets. 'Whether using the dice rolls and a program I got online that is supposed to be "trusted" or a wallets seed generator which is supposed to be "trusted" (until it isnt seems to be the same thing. I get the key to sign is different from the seed. Brass tacks, what I am asking is best practice at this point. |
|
Originally Posted By Fooboy: What is the most solid wallet these days? also curious. The volatility of Bitcoin and other cryptocurrencies is always a hot topic, and hitting 125k is a significant milestone. It's amazing to see how much the market has grown and fluctuated over the years, attracting both huge investors and everyday people. It remains a risky but potentially rewarding investment. For those looking to get started, I've seen services like Coinme https://coinme.pissedconsumer.com/review.html that offer Bitcoin ATM and exchange services. |
|
Originally Posted By Ender875: Thanks for the reply. Yeah, not so concise. To me, using the wallets mean I am putting blind trust in the manufacturer. Risk is a bit dispersed since I am (or will be when the Trezor gets here) using 3 different hardware wallets. 'Whether using the dice rolls and a program I got online that is supposed to be "trusted" or a wallets seed generator which is supposed to be "trusted" (until it isnt seems to be the same thing. I get the key to sign is different from the seed. Brass tacks, what I am asking is best practice at this point. Increasing the entropy above 72-bits is considered vital, obviously. But how do you know? That seems to be the question. So from what I have gathered from my own research and opinion: 1) Using a single device is a risk because it's a lottery if/when your device is found to have a vulnerability that matters. 2) Using 2 of the exact same devices is a risk because even when using a multi-sig wallet both keys are hashed completely independently and an issue is likely to break both keys. The keys do not combine to create a stronger key. 3) Using 2 devices by the same manufacturer is a risk. Obviously corporate management and decision making is a factor, but a single manufacturer is more likely to source their parts from the same sources and an issue might be present in the hardware of both models. 4) Requiring too many devices to be present to sign a transaction begins to incur a substantially different risk. 2/2 or 2/3 should be ok, but requiring 3/4 or 3/3 might start to increase the chances that funds could be lost because all the necessary pieces don't survive some calamity or ravages of time itself. 5) When the user is able, using manual entropy sources like dice rolls, RF noise, hand movements, etc is preferable to not using it. This might also require the user to evaluate whether this entropy source is implemented correctly and not faked of course. Given that, it seems best practices coming out of this are: 1) Use a multi-sig wallet of at least 2 out of 2 keys. 2) Make sure these sets of keys are generated by two independent processes, or hardware devices. 3) Make sure you are able to properly store ALL devices in the manner that is safest and most recoverable for you. 4) Choose a device that allows you to add additional entropy manually and preferably shows the adding of manual entropy on a display of some sort. 5) My opinion is that open source device software is preferred to closed source. Hopefully given the recommendations above, you at the very least will greatly delay an attacker from accessing your funds if there is a significant breach long enough to react. People with Coldcard mk4 (like me) luckily had enough entropy to prevent natively generated seeds from being so weak that they could be compromised in minutes. I sincerely hope that anyone with a Coldcard is paying attention and acts quickly. Some people with Coldcard mk4 devices probably imported older Coldcard seed phrases (simple upgrade to a newer wallet) and were obviously still at the greater risk. That brings me to my final recommendation for now. Keep up with the news. The "forget about it for 10 years" is good advice when it comes to appreciation expectations, but not when it comes to physical and cryptographic security. I don't think it's reasonable to constantly upgrade hardware wallets, since that introduces even more risks, but it's reasonable to keep up with your device news, follow recommendations around firmware patching, and keep your ear in the news for security issues and thefts. ETA: Here is a link to download and offline BIP-39 standalone generator that you can use inside an airgapped computer (booted from a live USB stick): The Ian Coleman BIP39 Tool It's an html file. Download it and run it in a brower offline and you can generate your own entropy using dice, cards, or whatever you can cobble together that randomly generates a signal (like using a mouse movement generator, or measuring RF noise and mapping certain waveforms to hexadecimal, etc). |
|
Originally Posted By Ender875: So using dice…. Is there a way to do this without making a Linux partition, without relying on a generated list etc? All videos I have watched entail rolling the dice, inputting the corresponding numbers into a sheet (so to speak) and a words will pop out when you’re done. I don’t see how that is substantially different than trusting a wallet manufacturer to do it for me. What I want is a list of all the words (which I can verify against other lists) to print out. Then some formula which takes my dice rolls and gives me the letter or word or number to correlate to a seed word. Obliviously the formula would be done by hand. Thanks! The difference is that generating a legit random number is a physics problem that is not trivial to implement in electronics/software and is even harder to verify. So, it requires a lot of blind trust to use a RNG chip even if it isn't disabled. Converting a random number into a seed phrase is extremely simple for software and can be easily verified. No trust needed. |
|
Originally Posted By Ender875: I see this from Blockstream. Id think downloading it and using it as a hard copy would defeat any spyware that sees which page you flip to and thereby narrowing the potential phrases. What says the hive? https://storage.googleapis.com/dxp-production-assets/content/blockstream-jade/add-more-security-functionality/create-a-recovery-phrase-using-dice/JadeDiceRollsGuide.pdf That link is from this page: https://help.blockstream.com/blockstream-jade/add-more-security-functionality/create-a-recovery-phrase-using-dice When I recreated my Coldcard, I used regular six-sided dice. Rolling 6 at a time, 20 times generated 120 dice rolls. The process was to shake and roll all 6, then using distance bias, rank each digit in order of how close it was to me. Order is randomized based on how the dice fall across the table and I can get 6 rolls at a time. It only took me about 5 minutes to roll all 120. |





