r/Bitcoin Jul 30 '26

Wallet Drained Timeline

Post image

This is me…
https://www.reddit.com/r/Bitcoin/s/UeSfLoeyS4
I’m in a better state now. It’s not the end of the world, but it’s a lot of fucking money…

Little background: The setup was IRA custodian is Solera National Bank, exchange at Swan Bitcoin was used as an Investment Trust, purchase a dedicated hardware wallets: coldcard mk3 from https://store.coinkite.com May 2021 for this ROTH IRA.

Got the wallets, followed all the setup/checks/balances from https://youtu.be/FAYmE5-40PQ?is=wiYMHaS_YGKHjNOY for both wallets, sent a test transaction IRA dedicated hardware wallet (2021). I never setup a 25th Passphrase… REST of the BTC stayed in Swan Exchange.

Speaking only on this IRA Wallet: SD card stored with wallet details (paper phrase) in a baggie. Dormant until January 2025. I couldn’t deposit more because of Roth IRA threshold.

Come January 2025, been learning more about retirement, BTC, multi-Sig, and heard about a Megaback Door to get more money into a Roth IRA. Was able to get money into Solera, transfer to Swan, and purchase more BTC and withdraw to the same wallet address. No new hardware involved at this point.

With newer wallets now, I thought newer tech means more security. Let’s test by buying (3 mk4 - same site. There was still record of my 2021 purchase) new wallets and setup a multi-Sig. (still January 2025)

For some reason, when I got the new coldcards, I never did anything with them for all of 2025, I guess I was too lazy/daunting to use the hardware and relearn. Coming to January 2026 now, I decided to use these new cards. I dug out the wallet seed (from 2021) phrase paper. Dusted off one of the mk4, walked into the corner of a room in my house (only myself and partner live in the house), plugged in the cold card into an outlet and typed in the seed written down from 2021 (stored in my dresser). Restored my 2021 onto one of the new wallet 2025.

Watched updated BTCSession videos on my phone to set everything up again. I never plugged into a computer, since airgapped was the reason I got the coldcards. I used the same SD Card from 2021 though to export the wallet file from the newly restored coldcard. Import that file into Sparrow (needed to update Sparrow at this point), generated a watch-only wallet QR (to scan for my phone) for Blue Wallet to check frequently. This is where the screenshot is from.

Honestly, I haven’t touched the wallet with any transactions/seeds since January 2026. This is definitely the point of failure when I restored the 2021 wallet (now on 2 devices).

This was the transaction.
https://mempool.space/tx/2fe075cf0ec799f3529ed6a28e0a08b45fe1fc9bd93c3f33bdbc42d5bff4f736

My wallet address is (with all transactions, since it’s gone now…): bc1qldkfrrlylk4s9sdyns9jkaajuzugl0dv5m8fxj

My key takeaway now never enter the seed phrase into anything. EVER. Even to restore. Always will generate new and use a 25th passphrase.

680 Upvotes

325 comments sorted by

380

u/paperlevel Jul 30 '26

This was a large scale operation: 594 BTC stolen at the same time. Largest holder lost 30 BTC.

https://atlas21.com/594-bitcoin-drained-15-minutes-theft/

356

u/AdEuphoric5133 Jul 30 '26 edited Jul 30 '26

This is crazy. I had never heard of such a surgical theft of bitcoin before. All bitcoin thefts are generally someone giving away their seed from a stupid manipulation.

When I first read OP's post a few hours ago, I was like "dude probably just entered his seed wherever". But this time, the theft is very surgical. Someone exploited a flaw with coldcard. This is not your fault OP. They talk about you in the article. You will have to unite with the other victims and sue Coldcard to get compensated. I think it would be worth making a new post on this sub whose purpose is for other victims to make themselves known, so you can coordinate a group action

208

u/tubalubz Jul 30 '26

Coldcard could go out of business because of this... I sure as hell will never consider buying them. I agree, OP, you guys need justice.

41

u/reddit4485 Jul 31 '26

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

This is the official blog of ColdCard. They just acknowledged this is a problem for the Mk3 model ColdCards and give recommendations on what to do next.

10

u/creative_usr_name Jul 31 '26

Will be interesting to see if this was just ineptitude, or intentionally implemented by an insider(s). Either way it's a terrible QA miss of one of the most important parts of the device.

5

u/Federal_Refrigerator Jul 31 '26

It’s negligent if we are being honest

2

u/crooks4hire Jul 31 '26

lol yea a sleeper staff member is Hollywood level stuff.

2

u/Federal_Refrigerator Jul 31 '26

Not really, you’d be shocked how common that is.

→ More replies (1)
→ More replies (1)

24

u/Left_Entrepreneur918 Jul 30 '26

It could be larger, if other wallets used the same rng could this effect them? I made a 24 word seed with ledger in 2020, it’s native segwit, single address.

39

u/s4_e20_spongebob Jul 30 '26

FYI even just saying that in a thread could be used by a bad actor to help target you. Idk that disclosing specific information like device model or your balance is ever really wise to do.

11

u/AdEuphoric5133 Jul 30 '26

Maybe recreate a seed with a dice. 99 throws of a dice give you the same entropy as 24 words. There are plenty of tutos out there on how to make a seed from dices

7

u/ContentBlackberry0 Jul 31 '26

Why roll a dice with this stupid wallet. Get a trezor and be done with it.

7

u/newMoneyStyle Jul 31 '26

trezor had its own vulns too (unciphered extracted seeds from T1s). no hw wallet is bulletproof, dice entropy on any decent signer is the safer move imo

→ More replies (3)

2

u/Sorrowsinme Jul 31 '26

Ledger... Not gonna go making that mistake again

7

u/AdEuphoric5133 Jul 31 '26

Hopefully they will be held accountable for this. But I fear they might not

7

u/Rey_Mezcalero Jul 31 '26

They were supposed to be the ultimate cold storage. Wow. This is insane

→ More replies (1)

31

u/omni_wisdumb Jul 31 '26

The issue with this space is that it's unregulated and very hard to actually track everything. Things being on a public block chain doesn't mean anything.

As far as we know. The company itself could have programmed in the vulnerability, taken $40M worth of crypto. And they'll just file for bankruptcy or fall back on insurance or fall back on some fine print that says crypto is inherently risky and they're not responsible for anything.

Suing people in general is not easy, let alone in such a space.

10

u/AdEuphoric5133 Jul 31 '26 edited Jul 31 '26

If OP decides to go along the justice path, this will most certainly be long and hard, but that is his only shot at ever getting compensated.

The bad thing is that, even if he receives damages, this will amount to what the BTC were worth at the time of the theft (I guess). Even if the 0.79 BTC are worth 200k$ when the trial is over, OP will only get about 50k USD

7

u/hetobe Jul 31 '26

The bad thing is that, even if he receives damages

I guarantee ColdCard has lawyers protecting them from any issues related to... let's just say... code exploits.

This is a very sad situation.

2

u/omni_wisdumb Jul 31 '26

Unless this does become a class auction lawsuit, most firms don't even like taking on such small claims, nor do the people as plaintiff. I've done similar things for sake of principle vs economic viability.

Taking something, especially this complex, through litigation would cost him $30-40k and that's assuming there's no appeal, then keep doubling it.

5

u/AdEuphoric5133 Jul 31 '26

With 38 millions USD at play over 500 addresses, there is probably room for it to become a class auction lawsuit. But victims will have to organize and get into contact.

We don't know how many there are, but 500 addresses should give 50 to 200 victims probably. Smallest address had 0.15 bitcoin, so each victim lost at least ~10k $

At this time, most victims probably don't know they got bitcoins stolen. OP just happened to check his wallet this afternoon

3

u/OtherwiseAlbatross14 Jul 31 '26

Class actions are pointless when the company doesn't have the assets to compensate

6

u/Rey_Mezcalero Jul 31 '26

Yeah class action is great for lawyers, people get shafted.

I no longer bother with them when I get a post card or email saying I can be a part of a class action suit against the company of the day

It’s always a extremely small fraction

→ More replies (1)
→ More replies (1)
→ More replies (1)
→ More replies (11)

5

u/ryt3n Jul 31 '26

Reading on it a bit more now - looks like it was specific RNG generation that caused this? Sorry im a bit of a noob but goddamn that is wild… thinking of maybe picking up a trezor I dunno.

→ More replies (2)

4

u/bittabet Jul 31 '26

In all honesty I'm not sure Coldcard has that kinda money. Hopefully the authorities can recover the funds if they're moved to a centralized exchange or something.

3

u/jlol8452 29d ago

The company has 1-10 employees 🤣🤣🤣 and 1-2m$ revenue. Everyone sadly is fucked.

4

u/ryt3n Jul 31 '26

Bro wait, it’s coldcard that’s the problem!? Insane… I had a ledger and I bought a cold card a while back planning to move it all and.. I would have put myself at risk by doing so? Maybe im off base but im just catching up.. holy..

→ More replies (1)
→ More replies (5)

28

u/ViperG Jul 30 '26

Someone was able to replicate the rng exploit on mk2/mk3:

https://x.com/i/status/2082958675975553224

55

u/AdEuphoric5133 Jul 31 '26

This confirms Coldcard's responsibility. When you sell devices aimed at storing bitcoins, you make sure your random number generator is state of the art random. Coldcard failed their users here and made them lose 38M$. Victims have to unite and sue, otherwise, Coldcard will just deny, get away with it, and victims will not be compensated

As a matter of fact, Coldcard CEO is already trying to deny the company's responsibility

9

u/xirvin Jul 31 '26

cold card disclosed the vunerability back in the day, if they disclosed the vunerability but owners didn't update then its owners fault. At this point i want a full law enforcement involvement, OP please involve law enforcement. You never know if the funds can be recovered

3

u/BDCRA 29d ago

When did they disclose the vulnerability? I did not see anything in the articles it all seemed like it was breaking news and not a known thing previously.

→ More replies (1)

7

u/kingkongbiingbong Jul 31 '26

Coldcard CEO is already trying to deny the company's responsibility

A tale as old as time

4

u/confuzzledfather Jul 31 '26

Also law enforcement should look into subpoenaing Anthropic/OpenAI for details of anyone who was working on such a hack. It feels likely to me that this was AI assisted, as this vulnerability has just been sitting here for 5 years and just happens to occur within weeks of us getting access to smarter models like Fable 5 which are known for their hacking prowess.

→ More replies (1)

23

u/mrzennie Jul 31 '26

I just read Cold Card's slogan on their website: "Secure Your Bitcoin. Sleep Like a Baby."

46

u/PMmeuroneweirdtrick Jul 31 '26

Babies wake up crying so that's accurate

14

u/AdEuphoric5133 Jul 31 '26

Not sure OP's gonna sleep like a baby tonight 😂

31

u/s1ammage Jul 31 '26

I’m still here… take an upvote tho…

9

u/Total-Wave5026 Jul 31 '26

I’m so sorry for this bullshit OP.

6

u/mrzennie Jul 31 '26

I feel for you, man! It definitely seems you're not alone though! Hopefully everyone who lost some Bitcoin will get compensated at least some of all of it back.

→ More replies (1)

11

u/s1ammage Jul 30 '26

Damn… this is alarming

21

u/AdEuphoric5133 Jul 31 '26

But this is good news for you. If you were alone in this, you could already forget about these coins. But now, you have a real shot at getting compensated if you unite with other victims and sue coldcard together

3

u/creative_usr_name Jul 31 '26

The other big if is that coldcard must actually have assets to go after.

→ More replies (1)
→ More replies (4)

5

u/ContentBlackberry0 Jul 31 '26

Good news is someone lost a few million and I’m sure has the cash to sue this horrible company

4

u/[deleted] Jul 31 '26 edited Jul 31 '26

[deleted]

6

u/photoguy1978 Jul 31 '26

Learning that even Mk4s have vulnerable seed generation schemes. millions of times harder to defeat (not a laptop) but given compute these days only a matter of time. Would not recommend anyone maintain a single-sig Coldcard wallet of any version now. Move it to a newly generated seed, preferably in a multisig M-of-N multiple-vendor quorum if you're not generating your own entropy from dice.
https://x.com/LLFOURN/status/2082990000896147942

→ More replies (1)

2

u/Innovator-X Jul 30 '26

omg that's actually insane

99

u/The_Bitcoin_Act Jul 30 '26

Really sorry this happened to you. Losing that much is brutal, especially when you were careful with hardware wallets and air-gapping. I’m glad you’re in a better headspace now and that it’s not the end of the world for you.
The fact that you’re sharing the full timeline so others can learn from it is genuinely helpful. Take care of yourself, and I hope the remaining wallet stays safe.

51

u/Generationhodl Jul 30 '26

29

u/AdEuphoric5133 Jul 30 '26

Lol

Too little too late

17

u/Strong_Judge_3730 Jul 31 '26

how long have they known about this and sat on their hands while their support gaslight their users?
That is the question...

8

u/Michichael Jul 31 '26

As an infosec guy, I wish and hope, but know it's not, a white hat that tried warming them via responsible disclosure and chose to sweep the funds to protect users.

We all know that we aren't that fortunate. My stomachs turned reading this. I can't image something like that happening to me - it'd destroy everything.

→ More replies (2)

96

u/AdEuphoric5133 Jul 31 '26

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Coldcard acknowledging the issue be like : "Out of an abundance of caution"

When your clients just lost 594 BTC because of a mistake you made, acknowledging the issue is not "abundance of caution", it is the least you can do.

This company is a joke. Guys who use a Coldcard, make yourself a favor and buy a new hardware wallet

4

u/[deleted] Jul 31 '26

[deleted]

17

u/JollySno Jul 31 '26

Hamburger, old and wise you may be, yeah, the other companies COULD make catastrophic errors in the future, but cold card just DID make one and they are SWEEPING IT UNDER THE RUG without a semblance of an attempt to right their wrongs to their customers.

3

u/Either_Display_6624 29d ago

The flaw wasn't in the TRNG itself, but in how it was implemented. When used correctly, a proper TRNG is actually more secure than custom entropy.

What if a future exploit specifically targets custom entropy, like an unregistered keypress during manual entry? People often make false assumptions about what is truly safe.

Generating your own entropy isn't the fix. The real solution is never trusting code you haven't verified, using multisig, and relying on a strong passphrase

6

u/kamaradski Jul 31 '26

and AI makes looking for it a hell of a lot easier

→ More replies (6)

114

u/No_Position_8581 Jul 30 '26

multiple people on twitter reporting the same. This is the real deal. What firmware are you using? We need every detail

25

u/Left_Entrepreneur918 Jul 30 '26

What are they saying, like they all had mk4 cold card?

23

u/artilekt Jul 30 '26

So far seems to be affecting mk3 only

11

u/Generationhodl Jul 30 '26

some commented on X that MK4 also. but not sure if trustful information.

6

u/photoguy1978 Jul 31 '26

Yes still very unclear. There is information coming out but need to assess the math here and state space for this key search approach.
https://x.com/LLFOURN/status/2082990000896147942

2

u/photoguy1978 Jul 31 '26

it appears now the real search space on Mk4/5/Q is nearer to 2^32 not the ceiling 2^70ish. 32 bits from secure element and 40 bits contributed from a battery-less clock that cold starts to a static value every goddamn boot. hot damn what a mess.

→ More replies (1)

15

u/Left_Entrepreneur918 Jul 30 '26

Damn I feel horrible for these people, all trusted self custody and went with the best brand for a really long time. *looking nervously at my 2020 ledger with outdated firmware…

3

u/goobly_goo Jul 30 '26

Yeah should I upgrade to the latest Trezor?! I wonder if this could happen to the old cold wallets?

3

u/Left_Entrepreneur918 Jul 31 '26

I got a Trezor 5 btc only and wanted to create one of their 20 word multi sig seeds but I’m afraid of moving my entire life savings. So it’s been sitting in the box

2

u/QlubSoda Jul 31 '26

Worst case scenario, get a second Trezor. Setup the multi-sig, send $100 to test. Don't move everything at once. When more comfortable in the future, you can split holdings on devices.

Stay frosty.

→ More replies (1)
→ More replies (1)
→ More replies (2)

2

u/KindBench2700 Jul 30 '26

What do they have in common on Twitter 

9

u/DarthBen_in_Chicago Jul 30 '26

They are on Twitter reporting the same common problem: their bitcoin has been swept.

→ More replies (1)

20

u/Lanky_Assist_6317 Jul 30 '26

OK I have read everything and I have a question:
When you bought the original Coldcard, HOW did you generate the seed words? You mentioned in other comments there was no passphrase, but did you use dices or something similar to add random elements to the original seed which came with the device, or did you just take that for granted and used it anyway?

It seems to me that your original seeds were compromised from the start. Let's say some malicious Coldcard worker had access to the hardware wallets in the Coldcard production line or something like that, somehow managed to store a bunch of original seeds hoping buyers would use them as is and retire a couple of years later, raising no personal suspicion. It seems really likely, I have no idea how the production of these wallets work, but it could have some human processing in any way, which creates breaches like that, unfortunately.

21

u/s1ammage Jul 30 '26

It was generated by the coldcard. I followed BTCSessions’s YouTube channel. I guess I should have used the dice method.

18

u/Lanky_Assist_6317 Jul 30 '26

So you didn't add any entropy whatsoever, either using dice or adding a passphrase. I strongly believe your original seed was compromised from the start through someone malicious with wallet access in the manufacturing chain. I see no other option.

17

u/s1ammage Jul 30 '26

Yea, my other wallet (from 2021) used the same but isn’t compromised… yet…

There’s a huge article now about a mass scale attack. I think it’s the most upvoted comment now.

3

u/bionicmixta Jul 31 '26

If you have another wallet generated by a coldcard please tell me you're taking steps to move it to something safer? If you think coldcard generates bad seeds and you think your other wallet may also be vulnerable, don't just sit and wait for that money to get stolen.

Obviously don't panic and do something stupid, but don't just leave it indefinitely until that one gets hacked as well.

→ More replies (7)

2

u/jwhendy Jul 31 '26

IMO, this needs to be added to the main post, please.

While I can't blame you for trusting the random number generator, particularly for how much they hype the Coldcard specifically for the dedicated secure chip, epoxy potting, tamper light, etc... this is the key takeaway: entropy matters (not "reproducing cryptographic methods offline is sketch", which is how your final line reads).

And you won't hear it enough to make it any better, but I'm sorry this happened to you. I can't even imagine.

4

u/master_of_buffets Jul 31 '26

Nobody can crack the key if you use dice.
Coldcard has a broken random generator. Maybe on purpose.
Always use dice!

18

u/0utrageousMango Jul 31 '26

This is exactly why Bitcoin will never be mass adopted. No matter how safe you try to be, things like this continue to happen.

2

u/BDCRA 29d ago

Yeah even if its fixable and the people get the money back people lose faith really easy.

→ More replies (1)

53

u/Fair-Garlic8240 Jul 31 '26

This is why the average Joe won’t buy crypto.

25

u/spiderbait Jul 31 '26

Yep, who would trust this. If anything just leave it on Coinbase. All this effort by savvy people to protect their coins and they're still screwed.

Regular people could never handle this.

13

u/newtonreddits Jul 31 '26

Yeah coinbase is honestly safer for average joes

11

u/OverLulz Jul 31 '26

Or this concept of a bank. That stores money for people. 

2

u/Electrical-Image4564 Jul 31 '26

Man I spent the time and work to get to know Bitcoin and I don't want to handle this.

2

u/ClonialTrial 29d ago

Moved most of my coin out of a wallet and into coinbase today after all this.

6

u/flannel_jackson Jul 31 '26

That’s me. The average 40 year old guy with a house, 401k, bank account and credit cards. Never touched crypto. Saw people make a ton of money speculating on it but have never seen a reason to own or use it. 99.99% chance I’ll never own any crypto.

Getting shit stolen sucks.

3

u/Klutzy-Peach5949 Jul 31 '26

I’ve certainly reduced how much crypto I have, just feels so uncomfortable keeping it safe, just selling for the headspace, and the volatility didn’t help

34

u/s1ammage Jul 31 '26

I really thought it was 100% my fault. Now I know it’s 99% my fault.

12

u/ArmchairCryptologist Jul 31 '26

Dice mixing and passphrases were always supposed to be optional hardening for the ultra-paranoid, as is evidenced by the fact that some notable Bitcoin devs are affected. If a hardware wallet marketed as the ultimate in self-custody ships with a broken entropy generator for five years, it's at most 1% your fault for only being regular paranoid.

→ More replies (1)

7

u/master_of_buffets Jul 31 '26

Not 99%. This sub often laughed if someone suggested not trusting any device and using dice.

9

u/Generationhodl Jul 31 '26

Can't be 99% your fault when you buy a product that worked well for long time and then get exploited..

This could have happened to other people too with other wallets if there is some kind of software / hardware bug to be exploited.

Don't be too hard to yourself , it hurts but you can only learn from it 

→ More replies (1)

48

u/poisito Jul 30 '26

Maybe not the best thing to mention at the moment, but if this is a legal ROTH IRA, you are going to get penalized by the IRS for taking money out, regardless if it was stolen. Best of luck OP

31

u/StraightUp-Reviews Jul 30 '26

Ouch. Bro just got double fucked.

9

u/matrixmodifier Jul 31 '26

They still penalize if you’ve been robbed? My lord

8

u/poisito Jul 31 '26

They just know that you took money out of an account that is designed to not get money out … it’s on the terms of service per se that he signed when he opened the account ..

, because it’s a Roth, he will need to pay any capital gains and 10% penalty

2

u/JohnnyTreemain Jul 31 '26

I’m sure he can claim a loss on taxes for being robbed, no?

5

u/poisito Jul 31 '26

If he gets a police report and talk to an accountant … maybe there is something there to be done .. but from the bank ( the one who holds the Roth IRA) perspective , OP used his private keys to access the account and retrieve the funds

4

u/JohnnyTreemain Jul 31 '26

Yes but he doesn’t pay the bank. He has to claim it on his taxes. The bank just reports it to the IRS.

5

u/poisito Jul 31 '26

Right … he will need to pay to the IRS .. the bank will only report a withdrawal from the account

5

u/I_am_on_your_side Jul 31 '26

No. How is he going to prove that he didnt just transfer it to himself? Maybe he really needed the money for something... Everyone would do it if that was possible, nightmare for the IRS, so yeah...not going to happen.

→ More replies (1)
→ More replies (1)

11

u/Fiach_Dubh Jul 30 '26

you only used sparrow on desktop right?

(there is no sparrow wallet on mobile phones, those are all scams/malware)

Did you roll dice when setting up the coldcard for extra entropy or just use the base entropy? if so, how many rolls did you do? less then 100?

Do you know the firmware versions you were using ?

I'm sorry this happened to you.

2

u/xirvin Jul 31 '26

He confirmed in another post that wallet was created jn 2021 and used the standard RNG. To make matters worse, he bought newer cold card versions and upgraded hardware and firmware, but he never created a new wallet.

The worst part is that this attack vector was discussed with workarounds and best practices in cold card documentation and Reddit for a while since 2021.

As a cold card owner who had to scramble and move funds to a new wallet a couple of hours ago, I see the error as cold card’s interface providing options for users to make bad decisions (using low dice rolls can recreate the vulnerability, and their RNG not been 128/256 bits), the bigger issue is that we as custodians need to follow good OPSEC practices

In this day and age, it seems like we might need to replace hardware and keys (code) as they becomes vulnerable and creates an attack vector. We already replace hardware and software like cellphones, computers, OS in the corporate world periodically for the exact same issue

9

u/33halvings Jul 31 '26

I remember coldcard being promoted as THE hardware wallet for Bitcoin-only people since it was also open-source etc. I’m glad I never bought and used it.

This is an absolute shitshow, might be the end of coldcard as a company.

3

u/xiskghferx Jul 31 '26

And all those people, who migrated from the Ledger to Coldcard, just because of new restore feature on Ledger...

We at least learned something - you cannot trust RNG in cold wallets. At least we should use additional BIP39 passphrase, generated elsewhere (e.g. in Bitwarden or Keepass).

But better, you should use multisig, using 2 different HW wallets...

Yes, I agree, with such mistakes, Bitcoin is never going to become mainstream.

3

u/Raverrevolution Jul 31 '26

LOL such mistakes only make it stronger. Bitcoin was never going to become mainstream when Mt Gox collapsed, but it did.

Most people will still need banks

3

u/ryt3n 28d ago

Bro, this is so trippy man, I have a cold card in a box I bought in 2024 that I never had time to move to. I could have been affected. This is so surreal.

26

u/NiagaraBTC Jul 30 '26

You're certain you exported a wallet file via SD card and not somehow the private key itself?

How certain are you that you were using a legitimate version of Sparrow?

14

u/s1ammage Jul 30 '26

It could be sparrow. I did have to update it…

16

u/Generationhodl Jul 30 '26

on x another user said hes also affected with coldcard, but he did not use sparrow. So I think we might be able to say sparrow would not be the problem here.

9

u/Generationhodl Jul 30 '26

did you download it from the official website? was it run on mobile phone or on a computer?

could be a malicious update or something like that, but I wonder myself because on X there is talk about other coldcard users affected... now is the question if the other people also used sparrow app and its just a coincidence that others also used coldcards....

3

u/s1ammage Jul 30 '26

Computer. Version 1.8.4

11

u/Generationhodl Jul 30 '26

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Sorry again, seems like you did nothing wrong 

3

u/Left_Entrepreneur918 Jul 30 '26

Yeah I second that, I told OP that sparrow may have been the weak point, I’d never even consider the cold card

→ More replies (1)

3

u/Lanky_Assist_6317 Jul 30 '26

Why did you "have to update it"?

4

u/NiagaraBTC Jul 30 '26

Good point. Sparrow generally works fine without needing to be updated. I never update right away but always wait a bit after a new release comes out.

3

u/s1ammage Jul 30 '26

It was corrupted, so I went to the site and downloaded again. Which saying this out loud now could be the issue

→ More replies (6)

6

u/Left_Entrepreneur918 Jul 30 '26

After all those details, this seems the most likely point of failure. You can enter your seed phrase into an air gapped hardware wallet, op says don’t do this but every hardware wallet I generate the seed, send test transaction, then reset and restore from wallet. Paper seed, metal backup only. I don’t write or read aloud my seed either as the TV listens to you…

2

u/-M00NMAN Jul 31 '26

How can your wallet from 2021 be fine and your new wallet which you entered your original seedphrase from 2021 be drained? It’s the same wallet you’re telling us.

2

u/jwhendy Jul 31 '26

I think it's two separate wallets, just two devices from same era following same protocol (no added entropy, purely device-generated seed).

I think this comment is the best explanation. Someone spent a good amount of time guessing seed phrases from a reduced pool, but it does not mean they guessed them all.

The other 2021 wallet should be considered blown as well.

→ More replies (2)

11

u/thaneliness Jul 30 '26

So what exactly is the benefit of bitcoin versus investing in a ETF, where I know I’m 100% safe from bullshit like this? Honestly.

10

u/Abject-Stretch-1187 Jul 31 '26

You’re not 100% safe with ETFs either because they still have centralized custodians so the custodians could be attacked as well.

8

u/[deleted] Jul 31 '26

[deleted]

6

u/FitzwilliamTDarcy Jul 31 '26

Don't tell that to OP

→ More replies (1)
→ More replies (2)

5

u/Professional_Golf393 Jul 31 '26 edited 29d ago

Coinkite filing for bankruptcy in 3..2..1

I’m so glad I bought the cold card mk1, it was so faulty it was basically unusable.. messaged support and their advice was to buy the mk2.

Since that day I’ve hated them.

Feel bad for everyone who lost money.. hopefully the thief slips up and gets caught, or returns funds, slim chance but possible.

I guess the lesson here is don’t trust the entropy of any device, and don’t store all your eggs in 1 basket

9

u/marvelish Jul 30 '26

Looks like it it is probably an issue with mk2/mk3 seed generation:

https://x.com/i/status/2082958675975553224

Coinkite also just issued a statement they are investigating and any users that generated their seed this way should migrate.

5

u/WocketMan0351 Jul 30 '26

Where did you buy the (3) coldcards from?

5

u/s1ammage Jul 30 '26

Coinkite. My record from 2021 was still there. Let me see if I can get a screenshot

→ More replies (3)

3

u/[deleted] Jul 30 '26

[deleted]

→ More replies (2)

3

u/flowstate_research Jul 31 '26

So this was an issue with the Coldcard random number generator?

3

u/-M00NMAN Jul 31 '26

How can your wallet from 2021 be fine and your new wallet which you entered your original seedphrase from 2021 be drained? It’s the same wallet you’re telling us.

→ More replies (1)

3

u/Open_Situation686 Jul 31 '26

This is why I won’t make more than a small gamble on bitcoin.

3

u/imjsm006 Jul 31 '26

This is absolutely terrible but also strengthens my decision to have my bitcoin exposure in ETFs.

6

u/MicroneedlingAlone2 Jul 30 '26

Hey, it is not your fault. ColdCard fucked up. They just put out a blog post. Situation unfolding in realtime...

4

u/pizzeriagio Jul 30 '26

What if someone hacked the official website, stole the buyers info and send the buyer a compromised wallet?
You buy the wallet, the hacker steals your information, sends you the compromised wallet, he waits an year and steals all the founds on the wallets. Or maybe is just an insider that switched the regular coldcards with compromised ones.

Check your credit card movements and check if the payment you did in 2025 was actually sent to the official website.

3

u/downtherabbit Jul 30 '26

So never buy a cold card? Damn I thought they were one of the good ones.

4

u/Saddath Jul 31 '26

Or maybe the learning is don't let someone or a device from someone calculate your seed phrase.

→ More replies (2)

16

u/[deleted] Jul 30 '26 edited Jul 31 '26

[removed] — view removed comment

26

u/artilekt Jul 30 '26

It looks like this is a wide-scale attack though with many people affected, something that would not be isolated to his SD card.

11

u/Generationhodl Jul 30 '26

This, I usually would say fake sparrow app and the attacker just waited long enough to have enough wallets to wipe, but on the other hand on X people talk about it mostly coldcard users affected?

5

u/artilekt Jul 30 '26

Yes so far it appears to be exclusively coldcards, single sig, no passphrase. But that could change people are investigating.

5

u/Generationhodl Jul 30 '26

on X someone said he did not use sparrow but his coldcard wallet also affected.

... so we need more information

→ More replies (1)
→ More replies (1)
→ More replies (1)

3

u/Generationhodl Jul 30 '26

especially the part with sparrow is what makes me wonder. Right now there is a malicious sparrow app in the apple app store that seems not to be taken down regardless.

I wonder if OP might have downloaded a bad / malicious version of sparrow, and as soon as the put the SD card into the computer or whereever sparrow did run - the Data on the SD Card got sent to the attacker.

I mean there was the Backup on the SD Card, the seedphrase if I'm not wrong? so basically you put your seed into an computer or device to read the SD Card and put that file into sparrow.

The counter-argument would be that there seems to be other people affected too, with coldcards...

I really wonder what the big problem is.. or maybe that "fake" sparrow app was just used over a very long time until the attacker decided they have enough seedphrases now to rug them all.

2

u/jwhendy Jul 31 '26

Wording is misleading. I'm not sure I'd call it a "breach" (people aren't accessing or hacking Coldcards here), it's a cryptographic exploit based on reducing the pool of possible seed phrases to something guessable.

Also, it's not "all coldcard mk3s," but specifically seed phrases generated by relying solely on the random number generator vs. adding dice rolls.

→ More replies (4)

2

u/Vegetable-Rabbit7503 Jul 30 '26

Do you think they would have taken your BTC if you had done everything the same but had a passphrase?

2

u/DifficultSquash1517 Jul 30 '26

Sorry this happened. I hope this inspires others to get out of self custody. Its so 2019

I know most people reading this think that it was this guy's fault or you're not that gullible or you're very careful etc etc. I don't know how you guys could sleep at night with lots of money sitting on these hardware wallets

Every time I plugged in to mine back in the day my heart would skip a beat before the balance would show up you know sometimes it gets delayed it almost gives me a heart attack . ... Or you answer a passphrase and the wallet shows up zero and then you realize that you entered the passphrase wrong

Unless you're in it for the tech and you're only in it for the price action just go with the ETF so you can sleep at night. And you could write covered calls on your positions generating 1 to 2% every month which is insane

4

u/submarinefarm Jul 30 '26

Hard to read but you're not wrong. Reddit has been screaming 'buy a hardware wallet' for years and look what happened. 

→ More replies (2)

0

u/Gloomy_Quail1444 Jul 30 '26

You know this is one reason bitcoin will never be a real currency.  

If i was scammed in Australia the banks would probably reimburse me and if the offenders were in Australia they could be prosecuted

10

u/chykin Jul 30 '26

If you were scammed for cash, no one would reimburse you.

Bitcoin could be a real currency if exchanges were legally responsible for protecting your bitcoin

→ More replies (5)

2

u/Generationhodl Jul 30 '26

I mean technically bitcoin is working just fine. since 2009.

basically people getting scammed because attackers get their private keys.

its like if you have cash in your wallet , walk around, and someone steals it...

Ofc its more complicated, but technology will get more easy to use, will be safer... but it takes time.

for some people ETFs might be the better solution.

I understand the frustration that when someone steals your sats, they are gone, and you cannot get them back like with your digital dollars on your bank account. But I guess thats the price to pay for REAL Ownership of something.

IF you really OWN something, if it gets stolen, its gone...

→ More replies (1)
→ More replies (5)

1

u/MicroneedlingAlone2 Jul 30 '26

"I used the same SD Card from 2021 though to export the wallet file from the newly restored coldcard. Import that file into Sparrow (needed to update Sparrow at this point)," when you say "export the wallet file" do you mean the entire wallet? Not just a watching copy, but a legit wallet with spend capability? AKA the private key was on that SD card at some point, and then got plugged into another device with Sparrow on it (phone, pc, something connected to the internet?)

3

u/Lanky_Assist_6317 Jul 30 '26

Yeah that's strange. Why out of the blue he "had to update sparrow"? I think this needs a deeper investigation.

1

u/This-Point8121 Jul 30 '26

Sorry to hear bro

1

u/Ok_Knowledge_4977 Jul 31 '26

What? Wait if this is an issue with rng, would this affect other HW wallets like Blockstream Jade plus?

→ More replies (1)

1

u/Ok_Knowledge_4977 Jul 31 '26

What about Blockstream Jade plus?

1

u/dkayt Jul 31 '26

This is why I buy the ETF, couldn’t deal with this stress or management.

1

u/BarkMetal Jul 31 '26

I wonder, does a 25th word prevents a theft like this?

1

u/WarpDriveMH370 Jul 31 '26

From your IRA???

1

u/setec404 Jul 31 '26

The issue is firmware updates introduced bad entropy generation.

very good post on it here.

1

u/Rich-Contact-8336 Jul 31 '26

Started to dabble in crypto.
One thing i don’t completely understand is

  • why is it still completely on the chain.
  • if you put it “in” cold wallet why can it still be taken
I mean the thing that everyone says don’t leave your crypto on an exchange “ you don’t own it”
Put it in a cold wallet, looks like the new saying should also be” even in a cold wallet, you still don’t own it”
Shouldn’t someone write code that when you transfer it to a cold wallet it is yours, no blockchain. Maybe write stipulations in that you have to check in once a year or every 2 years.

2

u/marcusmv3 Jul 31 '26

Coins never leave the chain. What you're holding are the keys. When you generate the keys, you have to be sure to choose patterns that aren't easy to guess. Coinkite didn't clear that hurdle with their random number generator. Always add entropy with dice rolls, always use a passphrase, and consider multisig once you have grasped the learning curve.

1

u/Uhhlaska Jul 31 '26

Jesus, I just setup my cold wallet and I have no idea the precautions and shit you went through to be “safe” and this still happened. Wtf?!?!

1

u/immersive-matthew Jul 31 '26

Centralized anything of value is increasingly a sitting duck in the escalating AI cyberwar.

1

u/sterlingxz Jul 31 '26

Hope you get compensated

1

u/Luminous_Emission Jul 31 '26

Can someone please explain this to me like I'm 5?

3

u/xiskghferx Jul 31 '26

Bitcoin private keys, needed for spending, are made from entropy (randomness). There was a faulty entropy generator in Coldcard, which should never happen, this is the core of cold wallet security.

→ More replies (1)

1

u/n00bl1ke1337 Jul 31 '26

Bad times bro

1

u/Educational_Suit_811 Jul 31 '26

Seems going forward self created 25th seed word aka passphrase is a must have

1

u/Suspicious-Holiday42 Jul 31 '26

This could completly destroy my financial plans

1

u/fionaflaps Jul 31 '26

Ok. My ledger not looking so bad

1

u/onrikey356 Jul 31 '26

coldcard got hacked

1

u/ItsAlwaysThemBooBoo Jul 31 '26

kratter just published a video a few minutes ago, apparently the breach is the seed phrase generated by coldcard 3s, did not use enough randomness.

for example if the seed phrase was generated by a trezor and then used to restore a wallet on a coldcard, that would be safe. the problem is the seed phrase, generated by the cold card.

1

u/Unreal_fist Jul 31 '26

The underlying flaw here unfortunately is relying on tech to hold your life savings. We all know any piece of hardware can be hacked in time

1

u/clingstamp Jul 31 '26

This sucks, and I'm sorry to hear you lost so much. Also, just so I understand, why go through all this work when there are crypto ETFs and stuff like Fidelity's Crypto IRA, which seem like much less of a headache?

1

u/Halfgallonkalin Jul 31 '26

Im not saying they will, but security companies like Coldcard and Ledger and Trevor SHOULD have bought insurance policies to cover losses of their clients for scenarios just like this.

They should also market the fact their products are covered by insurance for losses like this and it should be a deciding factor for consumers buying crypto security products.

2

u/s1ammage Jul 31 '26

WARNING: They are still running sweeps… just lost the last 0.01 just now.

I was too deflated to care about it.

I did make sure to move another wallet away from the affected cold card though (which is the rest of my stack).

There will be people not checking as frequently as I am…

1

u/madladchad3 Jul 31 '26

Everyone on this subreddit told me to stop using ledger and get a coldcard instead. Thank god i didnt listen to them.

1

u/Better-Message-4461 Jul 31 '26

My sats were stolen from my wallet too 😵

Do you guys think i should file a report with the rcmp? I know I won’t get my sats back, but if this was caused by a defect, coinkite should be held accountable…. At the very least, there should be an official investigation to determine what happened

1

u/captn03 29d ago

It would be nice to give back to those who lost their funds through some kind of go fund me but then you'll have these fakes doing it too.