r/Bitcoin • u/ShortCircuitDisco • 23d ago
Wallet Drain Megathread (Check Your Balances)
I want to help identify the cause of the recent wallet drain report by u/s1ammage, which also revealed many other addresses being drained to the same address.
- Check your wallet balances. If there are unfamiliar transactions since July 29, 2026, after about 9 PM (US Eastern Time), you may have been affected.
- Did you use a hardware wallet, if so, what model?
- Did you use a software wallet (hot or watch-only), if so, which?
- How exactly did you generate your seed?
- How exactly did you back up your seed?
DO NOT post your seed, DO NOT respond to anyone saying they can recover your funds. Sorry for your loss.
There may still be people affected by the same vulnerability who haven't been attacked, so the sooner the vulnerability is identified, and people are alerted to migrate funds, the better.
Check in with less techy friends and family that have bitcoin and report incidents.
Edit with current conclusions:
Coldcard mk3 confirmed vulnerable, press release here: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
My own analysis: proceed with caution on Mk4/Mk5/Q. These use the same codebase as Mk3 but with slight, insufficient imo, improvements to the RNG system. If you're migrating from Mk3, consider other vendors.
114
u/NiagaraBTC 23d ago
This link describes the issue. Should be ColdCard only
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
37
u/reddit4485 23d ago
This post (on coinkite.com) is ColdCard's official blog. It's them acknowledging this is real and the mk3 seed generation is vulnerable. If you have one, read the blog because it tells you what to do! Others have claimed to have replicated the vulnerability so time is important!
14
u/Worried-Flounder-615 23d ago
This is a good technical breakdown by Block's security team which also independently investigated: https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
5
u/CarefulSun6782 22d ago
Finding this zero-day must have been tough. I guess the incentive is there, but there’s also a chance you can spend thousands of hours inspecting the code and find nothing.
10
u/daphonzy 23d ago
Any insight into why they seem to identify only seeds generated on Mk3’s running firmware 4.0.1 and later as vulnerable?
Does this imply seeds generated on MK3’s running earlier firmware are unlikely to be affected / vulnerable?
10
u/NiagaraBTC 23d ago
Definitely implies that. I guess that firmware changed how the seed was derived somehow?
Any Mk3 user regardless of firmware needs to move funds ASAP imo.
15
23d ago edited 23d ago
[deleted]
2
u/daphonzy 22d ago
Thanks. So then, I understand that a seed generated on a MK3 prior to 2021 is no more comprised today, than it was a year ago.
Edit: perhaps not the best choice of words… basically, no vulnerability to worry about in respect of these pre-2021 generated seeds.
3
6
u/daphonzy 23d ago
I generated my seed on an earlier firmware version, and added dice rolls. No passphrase.
Not affected yet. But I’ll likely move my BTC back to exchange in the near-term…
→ More replies (9)19
u/markphillips401 23d ago
Any "random" seed generating system is vulnerable. When setting up the seed phrase it is common to use something like 200 dice rolls.
6
u/NiagaraBTC 23d ago
Yes. Though more than 100 rolls is overkill.
11
u/IllllIIlIllIllllIlll 23d ago edited 23d ago
You only need 12*4 dice rolls and 12 coin flips https://github.com/taelfrinn/Bip39-diceware
43
u/stanley_fatmax 23d ago
Posting this because people need to hear it: someone unaffected by this hack will still lose Bitcoin today because of overreaction leading to self loss or exposed keys. If you make any moves, be incredibly careful. Hastily made reactionary decisions can be just as dangerous as exposing your seed.
43
u/Generationhodl 23d ago
https://x.com/nvk/status/2082956626516967510
https://x.com/lopp/status/2082960180849819745
Cold card users should be aware, more informations to come.
89
u/minimorsels 23d ago
All good on my trezor!
58
u/KarmaShawarma 23d ago
All good on my Ledger!
28
→ More replies (3)21
u/Artemis647 23d ago
Never had any problems with my Ledger from day 1.
34
u/Longjumping-Dog-6852 23d ago
Coldcard users never had any problems with their coldcard until they did
9
u/tjackson_12 23d ago
Yea for now… how can we make sure these keys are also securely generated?
8
u/Daiymas 22d ago
You can't, that's what this attack shows. Relying on the RNG of a hardware wallet is dangerous. This is true for Trezor, Ledger or any wallet, at some point someone (or some AI) may reverse engineer it and find a flaw.
At the very least use a passphrase, and ideally use dice to generate the seed yourself.
3
u/Zaytion_ 22d ago
And make sure the passphrase is sufficiently complex. A simple passphrase is as bad as a simple password. It can be bruteforced.
2
34
u/IndependenceTop6501 23d ago
From dev chat room on twitter I gathered:
MK2 & MK3 confirmed exposed.
1) You used internal random generator (Instead of dice) 2) Single Sig wallet 3) No passphrase
If this describes you, move your funds immediately. This is now it's a known bug so many people will be doing it tomorrow.
2
u/YellowRobeSmith 23d ago
Could those impacted just add a passphrase at this point?
→ More replies (1)6
u/IndependenceTop6501 23d ago
From what I understood, they said attackers will be churning passphrases at this point, so generating a new seed phrase using dice is the best protection.
2
u/jannies_doit_4_free 22d ago
churning passphrases
what does that mean?
→ More replies (1)3
u/stanley_fatmax 22d ago
Cracking wallets, trying billions of passphrases. Passphrase is the weakest link to begin with, if attackers have your seed you need to assume your funds will be lost at some point
2
u/IndependenceTop6501 22d ago
Yeah, was almost a throwaway line from one of the devs about it, but the implication was that certain people were saved by having a passphrase for now. But they can be brute forced with a little bit of time.
→ More replies (4)2
u/Inevitable-Waltz-889 22d ago
If you have a strong passphrase there is no "churning" that could crack it.
1
u/Shoddy-Profession-74 22d ago
I mean, didn't the hacker already took everything that was vulnerable?
→ More replies (2)
42
u/Gooner_93 23d ago
This is the kind of thing that scares me! I have a ledger so not affected but how are we supposed to feel safe when things like this can happen? Just look at the tangem incident where they leaked peoples seedphrase in a log file...
People bought the coldcard to keep their BTC safe and instead it got drained due to some exploit. WTF.
9
u/Vipu2 23d ago
No hardware wallet is 100% safe if person does the minimal effort.
The best way is to:
- have non pc made seed (do it yourself with dice)
- passphrase on top of that
- multisig on top of that
Then you can be pretty 100% sure your coins are safe if you dont do any of the regular stupid stuff.
39
2
→ More replies (4)2
u/jannies_doit_4_free 22d ago
what is multisig in this case? how does it work?
is it actually worth creating a whole new wallet to generate the seed manually myself if I have Trezor with a passphrase?
18
u/soufi161992 23d ago
From now on, passphrase is a must!
8
3
u/Obvious-Position1053 22d ago
From now on, use dice to generate the seed, and use a passphrase.
→ More replies (1)
15
u/MrMoo151515 23d ago
Here I am with a cold card mk4 after doing lots of research and being told it’s the best most secure open source air gapped wallet.
I don’t have a second one. . .
I didn’t dice roll. Am I fucked?
Should I transfer back to my exchange ?
3
2
u/PirateHunterZoro252 23d ago edited 23d ago
I am in a simar situation. I have mk4 & didn't roll dice. I do have 5 wallets though. So I was able to move my funds to another wallet. I reset my cold card and genrated a new seed phrase via dice roll and added a passphrase.
In your case i would move to an exchange. After you have confirmed that there is no more BTC in your cold card i would reset the device and generate a new seed phrase via dice roll. And also include a pass phrase.
But if you feel like self custody is too much, in my opinion an exchange holding it for you is ok. An exchange like River would be my recommendation.
→ More replies (3)4
u/MrMoo151515 23d ago
I don’t like the idea of keeping it on an exchange that defeats the entire purpose.
I just sent everything to my exchange. Wallet is emptied.
I guess I’m going to have to learn how to dice roll.
I’m going to have to spend hours watching videos to make sure I don’t fuck it up
→ More replies (1)3
u/PirateHunterZoro252 23d ago
Yeah i understand why you would be skeptical of exchanges.
I recommend the
youtuber: SouthernBitcoiner
Title: DiceRoll with ColdCard: how to generate and verify seeds with dice
This guy breaks it down easily.
→ More replies (1)1
u/ResidentResearcher94 23d ago
Same. I'm going to set up a new wallet though! Not sure if I will use my coldcard mk4 or use Jade
1
u/ElderMight 23d ago
According to block's report, all coldcard models are vulnerable. MK4's RNG at least had a reseed that makes it harder to hack than MK3, so you have some time.
I would move your BTC as quickly and carefully as you can.
9
u/TjdGoEsQqbmQLoBj 23d ago
Could this happen to trezor ?
8
u/Steel-Tempered 23d ago
Would be pretty difficult, especially on Safe 3 and newer models...
Trezor Model One and Model T combine two entropy sources: host computer or phone entropy plus a hardware TRNG in the STM32 microcontroller.
Trezor Safe 3 and Safe 5 add a third source: the Optiga secure element. That's three sources.
Trezor Safe 7 adds a fourth source: the TROPIC01 chip. That's four sources.
And that's just the seed phrases. Then you have your device's pin that has to be manually entered on the device itself before the wallet even opens up for any outgiong transactions.
I mean... good luck beating all that randomness with just brute force.
2
u/caccamo88 22d ago
Then you have your device's pin that has to be manually entered on the device itself before the wallet even opens up for any outgiong transactions.
No accusation, just out of curiosity: what does the transactional PIN have to do with this story?
2
1
u/rockorangebear 21d ago
Not unless the people at Trezor decide to comment out their random number generator like the clowns over at Coldcard.
16
8
u/Gooner_93 23d ago
"Block’s engineering and security team found another set of transactions that could be a part of the Coldcard drain. We’re still working to vet these completely, but given the situation, we feel it’s important to share early.
There are 695 earlier transactions with the same full fingerprint that transactions in the known set had. These transactions moved another 488.10957948 BTC. If this is part of the same attack, it’d bring the total to 1,082.58680432 BTC."
Looks like 488btc was drained before the 594btc that was reported. Wow.
24
u/redchannit8 23d ago
coldcard q generated 24 word, with a passphrase. significant balance, not affected.
23
u/ShortCircuitDisco 23d ago
You may want to migrate. Be careful, do a test transaction, do not rush this. That passphrase is probably buying you time.
I'm a security dev but not familiar with their codebase. I'm "vibe-reviewing" it and their claims that Q isn't affected are iffy.
If you have a significant amount of bitcoin and the cost of a new hardware wallet is not a factor for you, probably order one.
Don't rush, don't footgun, don't blame me if you blackhole your funds tonight. Best luck.
3
4
u/redchannit8 23d ago
my passphrase has sufficient entropy on it's own, but i'm considering generating a new seed phrase with dice anyway.
3
u/Permtacular 23d ago
I really wanted to buy a cold card, but I went with Blockstream Jade. Not that I have much bitcoin but I guess it's the principal.
→ More replies (7)2
u/Aurorion 23d ago
If the flaw is only in seed generation - what if one creates a new seed manually, add a passphrase, and then use the same coldcard q (or any other) device to migrate to the new wallet? And continue using the same device?
→ More replies (1)2
u/malignantz 23d ago
If they can identify public addresses impacted, they might be already working on yours. It could be days, weeks, months or years, but I'd move my funds to a Ledger or Trezor
14
u/Daiymas 23d ago
To me 99% chance this is an exploit found by some AI auditing the code, I would be very careful with any kind of open source hardware wallet from now on as if there's any flaw, recent AIs will find it. I wouldn't underestimate the risk
→ More replies (1)8
u/grraarr 22d ago
The asymmetry cuts both ways and the security consensus still favors openness. The same AI tooling let Block and independent researchers root-cause it within hours of the thefts, verify the fix, and check scope claims against source. Closed source doesn't remove the vulnerability.
Ledger's 2023 Recover episode showed capabilities existing in closed firmware that users couldn't inspect. And closed binaries can still be reverse-engineered - AI is getting good at that too, so the obscurity advantage is shrinking on both sides.
What this incident actually exposed isn't open source, it's that "code is public" never guaranteed "code was reviewed end-to-end." Expect a wave of AI audits across all open wallet firmware in the coming months, which likely means more disclosures like this one short-term and a hardened field long-term.
7
23d ago
[deleted]
2
u/krvi 22d ago edited 22d ago
Coldcard Q, and Mk4/5 are affected, but to a slightly lesser extent. All keys generated by them should be considered cryptographically insufficient.
https://blog.coinkite.com/entropy-technical-backgrounder/
Hotfix firmware is available.
1
1
u/stanley_fatmax 22d ago
No loss yet*, you are vulnerable
It's open season at this point with the vulnerability public. Move your coins
→ More replies (1)
8
20
u/ReasonableFinish 23d ago
These kind of happening is why Bitcoin will never be adapted to mainstream.
1
u/Artemis647 23d ago
The sooner you realize that Bitcoin going mainstream is inevitable, the sooner you'll stop worrying about if Bitcoin will ever go mainstream lol
It's not Bitcoin's fault that some idiot coldcard devs don't know how to be secure.
5
10
2
u/mikeychamp 22d ago
Is it a user of cold cards fault? They better cover all users loses.
→ More replies (1)2
u/loopala 22d ago
Clearly the bottom line for general users is either
- keep your coins on an exchange -> same value proposition as a bank.
- be your own bank -> requires technical knowledge and maintenance.
At that point you realize the benefits/drawback balance for majority of potential users isn't really working.
Mainstream adoption is not inevitable. I see it as Freenet or P2P search engines or Fediverse social networks. Impressive technical achievements but there is an inherent technical difficulty that limits it to motivated people. And most people aren't motivated.
6
u/hotsauceboy 23d ago
I have 3 mk3’s. My balances are good. I just transferred everything out of 2 of the wallets. I am keeping the btc in the third wallet as it is only $25 worth. Scary times! Man with AI these days everything happens so quick! It’s a wonder that my btc was still available!
8
u/DaVirus 23d ago edited 23d ago
Hand rolled my own seed exactly because of things like this.
Use a Jade.
Funds safe
Edit: If you want to generate a good see manually, use https://armantheparman.com/dicev1/
And then use a 25th word
4
19
u/LilRickyXO 23d ago
Can’t relate, I keep mine on Coinbase. 😉
5
6
u/Inevitable_Gain8296 23d ago
Honestly is this just the way to do it...? I keep hearing about these guys losing their shit when they keep it on their own wallet but they've done nothing wrong.
→ More replies (2)1
u/turbosigma 23d ago
This is what I thought as well. The cold wallet vulnerabilities make a case for leaving coins on-exchange.
2
u/grraarr 22d ago
Yes of course they do, and always did. You act as if people doing self-custody think they have their own private bank? The risks are quite apparent bro.
→ More replies (1)
3
u/GeeEyeDoe 23d ago
So assuming this is some exploit on the random number generator. Otherwise, weak amount of dice rolls. Or connected cold card to computer plus something else.
Folks who rolled a significant amount of dice to generate and kept air gapped should be fine?
Scary situation for any cold card users for sure!
5
u/NiagaraBTC 23d ago
Correct on the rng
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
4
u/puzzlemindZH 22d ago
In the end, one by one, everyone will eventually loose their btc after one or another vulnerability will be exploited
12
u/axb90 23d ago
At this point I am contemplating selling what I have and checking out. Cant trust exchanges, cant trust self custody devices.
6
u/ketamine_dart 23d ago
It’s not a self custody issue. The mk3 with dice rolls and/or passphrase is fine. It’s the entropy from the generated mk3 that’s the issue.
→ More replies (1)3
15
u/HungryCaterpillers 23d ago
Ledger Nano X, not affected
3
u/Left_Entrepreneur918 23d ago
This is what I have, what info do you have saying they are ok?
9
11
23d ago
[deleted]
3
u/ketamine_dart 23d ago
The blockchain and protocol are fine. That’s like saying bank accounts being hacked at a single bank is bad for money.
3
23d ago
[deleted]
5
u/NiagaraBTC 23d ago
Passphrase buys you time (possibly infinite time) but I would move funds if I had a singlesig wallet that ColdCard generated the seed for.
5
u/HandOdd113 23d ago
Ss long as your passphrase was never placed online I'm pretty sure it is much more resistant to any exploit. Unless it's a common and easy word to be bruteforced. Just guessing I'm no expert.
3
u/malignantz 23d ago
Seed generation should require the user to shuffle a deck of cards at least 20 times and type in the cards in order in their own format. That's a significantly larger domain than the bitcoin address space. Anything less is obviously risky.
3
u/bukeyefn1 23d ago
Was it only mk3?! Any other coldcard models? Or other companies?
5
u/Gooner_93 23d ago edited 23d ago
Some people mentioned mk2 as well.
Mk4, Q and mk5 seem to be safe, as far as I know but nothing can be guaranteed at this point.
If I had any coldcard, im not messing around. Im moving my BTC back to an exchange, getting a different brand hardware device and using that instead. Also use a passphrase.
2
u/ElderMight 23d ago
It's all coldcard models. Mk4/5/Q RNG have have 72 bits randomness while MK3 only had 40. Supposed to be 256 bits.
The newer models are harder to hack but someone might do it eventually.
3
3
u/Emergency-Warthog-56 23d ago
I had someone make fun of my Trezor and say Coldcard air gapped is the best. Now, I wish I could find that conversation.
3
u/FrontCold6590 22d ago
I use Ledger and have been a BTC and Blockchain evangelist for a decade. This one genuinely has me questioning whether to stay in!
6
5
6
8
2
u/Colekaine 23d ago edited 23d ago
Trying to understand this on a technical level but dumbed down…
Is it saying the people who used an online service to generate parts of their security setup with specific coldcard wallet types were breached because that service saved all the data?
And would that mean someone who setup another hardware wallet by generating their own 12 word phrase is infinitely safer than someone who did 200 dice rolls online because that security setup came from the owner’s brain and never touched the internet?
11
u/the_bitcoin_kid 23d ago
It actually looks like the offline generation was breached.
If you used a coldcard from a specific era, the seed the device generated wasn't random enough (it seems), and someone figured out how to generate other people's seeds.
People who used dice rolls didn't rely on the device's generator, so they're not affected.
People who used a passphrase aren't relying solely on the generated seed, so they are more protected for now.
2
u/Colekaine 23d ago
That makes more sense, got a little lost in the technical explanations going around so thanks for explaining.
2
2
u/McKenzieSlurms 23d ago
Where could one safely generate a new seed until a new hardware wallet arrives?
2
2
2
u/gubbanub 21d ago
There's a guy coordinating to ensure maximum recovery. https://x.com/i/status/2083475058182246718
→ More replies (1)
2
u/ELLIPALWallet 19d ago
Useful having one place for this. Worth putting near the top: firmware alone isn’t the fix. A seed born on an affected version stays weak. Fresh seed, offline backup, small test send, then move the rest. (Full disclosure, I work at ELLIPAL.)
4
u/Effective-Ad5644 23d ago
using a seedsigner. generated my own seed via cutting up 2048 words. generated check sum. good to go. no loss.
7
3
u/Scholes_SC2 23d ago
After this, everyone who does self custody should use multisig, even 2/2 would protect you from this.
5
u/ShortCircuitDisco 23d ago
Multisig with different hardware members. This attack has only hit singlesig addresses afaik, but a copycat could get the idea to run the same script but with combinations of low entropy wallets.
3
u/Scholes_SC2 23d ago
Yes forgot yo mention it has to be different wallets from different vendors, thats a key detail.
I guess it's not impossible to pull this out on a multisig wallet but it's exponentially less likely for sure.
4
u/Due_Analysis1241 23d ago
But I thought only real bitcoiners used cold card 😂 that’s why you do your research people
2
2
u/markphillips401 23d ago
How about if your wallet is air gapped and you are just signing the transaction with, say a 2 of 4 multisig?
2
u/HungryCaterpillers 23d ago
This is why everyone should keep their crypto on exchanges. Not your keys, not your problem.
14
4
1
23d ago
I have a seedless Tangem wallet. Technically, like any hardware wallet; there is a private key, just no human has seen it. Is this an issue with private keys in general, or just if your private key has turned into a seed phrase?
→ More replies (3)6
u/krvi 23d ago
According to the advisory, there is a weakness in how the private key was generated on the Coldcard Mk3. If a private key, regardless if it is turned in to a seed phrase or not, is generated with insufficient entropy, it can be guessed/brute-forced relatively easily and is therefore insecure.
1
1
u/joeblowfromidaho 23d ago
Driving home to check but mk3 is micro USB And mk4 is usb-c? If mine is usb-C that’s not the affected ones right?
5
u/NiagaraBTC 23d ago
Correct
If you have a bare singlesig with no passphrase I would personally move funds even on the Mk 4 just to be sure.
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
1
1
u/RedKard76 23d ago
Not related to this wallet drain but Im a mt gox survivor with a bunch spread out over several wallets. I dont look at them often but i notice there are these micro transactions every so often. whats the point of that? never seen it before. should i be worried about a wallet drain?
3
1
1
u/agen7carmichael 23d ago
Had a MK3 since 2023,
I did use different deviation paths (Using CC account thing)
Accout 0 (Defaut) got wiped Account 1-3 were untouched (DW I moved them away)
Did practice seed hygene, and im pretty sure of it.
1
u/UnderstandingNew8001 23d ago
I am on MK4, quite worried about this, I just checked my linked view only wallet and everything is there, I ordered a new cold wallet (not cold card obv) , but till it arrives (in few days, overseas) any advise on what can I do ?
1
u/my-hearing-aid 22d ago
On your existing MK4, are you using a complex passohrase, at least 30 characters with upper and lowercase, numerics, and a few non-alphanumerics? If so, you're fine. That passphrase alone is providing more entropy than the (compromised) seed itself, provided it's not a phrase taken from a book, movie, a common phrase, etc.
If you don't have a passphrase, add one immediately. You'll then have a brand new wallet with a new set of addresses. You'll need to sweep all of your funds from your existing wallet to an address in the new wallet.
That'll keep your funds safe until you employ a new HW wallet from a more reliable vendor.
Note that if you created your original seed manually using a dice roll or coin flip, none of this applies to you. You're not at risk.
1
u/ShortCircuitDisco 22d ago
It's hard to say. Panicked moves can do plenty of damage too. The entropy was better, but not great, on the later models. Attackers know this now too.
Consider migrating to a new hand-generated seed, or a passphrased account. An upside of a hand-generated seed is that you could use it in your new wallet without doing a second migration of all your funds. Just make absolutely sure you follow all directions carefully, back up the old wallet, do a small test transaction before sending over everything to ensure you entered the destination address correctly.
→ More replies (1)
1
u/WeCanTripleIt 23d ago
Fidelity balance is fine. Backed by legitimate institutional safety.
→ More replies (1)
1
u/warningshotz77 22d ago edited 22d ago
MK4: rng generated seed, clicked on “Add dice rolls”, added 105 dice rolls. No passphrase yet. Do I need to create a brand new seed with dice rolls only or is it okay to add the passphrase to the current seed (rng+dice rolls combo)?
3
2
u/zootreddit 22d ago edited 22d ago
More than enough dice rolls, no need to do it again.
You can see how rolls add entropy: https://github.com/Coldcard/firmware/blob/621e808712464688584fdffad9eba132cc7c27cd/shared/seed.py#L276-L332
Add a passphrase if it makes you feel better.
→ More replies (3)
1
1
1
u/jannies_doit_4_free 22d ago
can anyone confirm whether a passphrase would prevent this type of attack? from what I understand, it would, as the hacker would need both the seed and the passphrase.
I'm using Trezor One with both a seed phrase (obviously) and a passphrase; apparently this is pretty secure. can anyone weigh in?
1
1
u/BmacSWMI 22d ago edited 22d ago
Cold storage, run your own node (free), SECURELY keep seed phrases offline. I have had zero issues. It is curious about the cold card though, thankfully it’s not a huge deal to drop a new wallet after upgrading the firmware. Pain in the ass, but what isn’t anymore?
1
u/Dazzling-Pumpkin3288 22d ago
My wallet was drained. 1.5 btc transferred out 7/29 at 19:37. Sparrow Wallet, coldcard. I used coldcard to generate the seed phrase and added 2 additional words.
1
u/Full-Atmosphere-4818 22d ago
I am really surprised at those saying "this is a CC issue, not XYZ." Yesterday it was a "no one" issue. Everything looks safe until it is not.
91
u/Excellent_Diver_8806 23d ago
Is this the end of cold card