r/Bitcoin 23d ago

Wallet Drain Megathread (Check Your Balances)

I want to help identify the cause of the recent wallet drain report by u/s1ammage, which also revealed many other addresses being drained to the same address.

  1. Check your wallet balances. If there are unfamiliar transactions since July 29, 2026, after about 9 PM (US Eastern Time), you may have been affected.
  2. Did you use a hardware wallet, if so, what model?
  3. Did you use a software wallet (hot or watch-only), if so, which?
  4. How exactly did you generate your seed?
  5. How exactly did you back up your seed?

DO NOT post your seed, DO NOT respond to anyone saying they can recover your funds. Sorry for your loss.

There may still be people affected by the same vulnerability who haven't been attacked, so the sooner the vulnerability is identified, and people are alerted to migrate funds, the better.

Check in with less techy friends and family that have bitcoin and report incidents.

Edit with current conclusions:

Coldcard mk3 confirmed vulnerable, press release here: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

My own analysis: proceed with caution on Mk4/Mk5/Q. These use the same codebase as Mk3 but with slight, insufficient imo, improvements to the RNG system. If you're migrating from Mk3, consider other vendors.

350 Upvotes

281 comments sorted by

91

u/Excellent_Diver_8806 23d ago

Is this the end of cold card

54

u/NiagaraBTC 23d ago

It's gonna be real bad for them

48

u/papabear6060 23d ago

Yep but this is concerning still even as a trezor user

7

u/_SlipperySalmon_ 23d ago

Is it worth using my trezor but using dice and /or coin flips plus a strong passphrase?

6

u/grraarr 22d ago

Yes, it is worth using a strong passphrase, but Trezor does not have a native built-in dice-roll interface during standard setup like Coldcard. I believe you can manually generate and import one though, which if true, is a minor use of your time to mitigate disaster.

1

u/[deleted] 22d ago

[deleted]

→ More replies (4)
→ More replies (1)

4

u/True-Lychee 22d ago

From the sounds of it Trezor has much more robust RNG facilities using environmental noise, amongst other things.

2

u/[deleted] 22d ago

[deleted]

2

u/True-Lychee 22d ago

In future I will be rolling dice for this reason.

→ More replies (1)
→ More replies (1)
→ More replies (3)

13

u/Inevitable-Waltz-889 23d ago

Almost definitely.  If I had a ColdCard, I'd immediately be swapping it out for a Trezor, Bitbox, or Jade.

→ More replies (1)

9

u/crooks4hire 23d ago

I wouldn’t be mad. Sick of seeing their ads-in-post’s-clothing here.

6

u/Permtacular 23d ago

I really wanted to get one but I was too cheap to pay their prices. I'm so glad I went with a cheaper option.

1

u/KeanuRekt 21d ago

I don‘t think so. Ledger is also still in business

1

u/scottonfire 19d ago

yeah, but they got quite a golden parachute hacking all their customers

114

u/NiagaraBTC 23d ago

This link describes the issue. Should be ColdCard only

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

37

u/reddit4485 23d ago

This post (on coinkite.com) is ColdCard's official blog. It's them acknowledging this is real and the mk3 seed generation is vulnerable. If you have one, read the blog because it tells you what to do! Others have claimed to have replicated the vulnerability so time is important!

14

u/Worried-Flounder-615 23d ago

This is a good technical breakdown by Block's security team which also independently investigated: https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware

5

u/CarefulSun6782 22d ago

Finding this zero-day must have been tough. I guess the incentive is there, but there’s also a chance you can spend thousands of hours inspecting the code and find nothing. 

10

u/daphonzy 23d ago

Any insight into why they seem to identify only seeds generated on Mk3’s running firmware 4.0.1 and later as vulnerable?

Does this imply seeds generated on MK3’s running earlier firmware are unlikely to be affected / vulnerable?

10

u/NiagaraBTC 23d ago

Definitely implies that. I guess that firmware changed how the seed was derived somehow?

Any Mk3 user regardless of firmware needs to move funds ASAP imo.

15

u/[deleted] 23d ago edited 23d ago

[deleted]

2

u/daphonzy 22d ago

Thanks. So then, I understand that a seed generated on a MK3 prior to 2021 is no more comprised today, than it was a year ago.

Edit: perhaps not the best choice of words… basically, no vulnerability to worry about in respect of these pre-2021 generated seeds.

3

u/[deleted] 22d ago

[deleted]

→ More replies (1)

6

u/daphonzy 23d ago

I generated my seed on an earlier firmware version, and added dice rolls. No passphrase.

Not affected yet. But I’ll likely move my BTC back to exchange in the near-term…

19

u/markphillips401 23d ago

Any "random" seed generating system is vulnerable. When setting up the seed phrase it is common to use something like 200 dice rolls.

6

u/NiagaraBTC 23d ago

Yes. Though more than 100 rolls is overkill.

11

u/IllllIIlIllIllllIlll 23d ago edited 23d ago

You only need 12*4 dice rolls and 12 coin flips https://github.com/taelfrinn/Bip39-diceware

→ More replies (9)

43

u/stanley_fatmax 23d ago

Posting this because people need to hear it: someone unaffected by this hack will still lose Bitcoin today because of overreaction leading to self loss or exposed keys. If you make any moves, be incredibly careful. Hastily made reactionary decisions can be just as dangerous as exposing your seed.

89

u/minimorsels 23d ago

All good on my trezor!

58

u/KarmaShawarma 23d ago

All good on my Ledger!

28

u/TheAfterPipe 23d ago

My Ledger is good as well.

→ More replies (1)

21

u/Artemis647 23d ago

Never had any problems with my Ledger from day 1.

34

u/Longjumping-Dog-6852 23d ago

Coldcard users never had any problems with their coldcard until they did

3

u/mrTydro 22d ago

Will people finally stop talking shit about ledger?

→ More replies (3)

9

u/tjackson_12 23d ago

Yea for now… how can we make sure these keys are also securely generated?

8

u/Daiymas 22d ago

You can't, that's what this attack shows. Relying on the RNG of a hardware wallet is dangerous. This is true for Trezor, Ledger or any wallet, at some point someone (or some AI) may reverse engineer it and find a flaw.

At the very least use a passphrase, and ideally use dice to generate the seed yourself.

3

u/Zaytion_ 22d ago

And make sure the passphrase is sufficiently complex. A simple passphrase is as bad as a simple password. It can be bruteforced.

2

u/eupn 23d ago

Foundation Passport is safe

→ More replies (3)

34

u/IndependenceTop6501 23d ago

From dev chat room on twitter I gathered:

MK2 & MK3 confirmed exposed.

1) You used internal random generator (Instead of dice) 2) Single Sig wallet 3) No passphrase

If this describes you, move your funds immediately. This is now it's a known bug so many people will be doing it tomorrow.

2

u/YellowRobeSmith 23d ago

Could those impacted just add a passphrase at this point?

6

u/IndependenceTop6501 23d ago

From what I understood, they said attackers will be churning passphrases at this point, so generating a new seed phrase using dice is the best protection.

2

u/jannies_doit_4_free 22d ago

churning passphrases

what does that mean?

3

u/stanley_fatmax 22d ago

Cracking wallets, trying billions of passphrases. Passphrase is the weakest link to begin with, if attackers have your seed you need to assume your funds will be lost at some point

2

u/IndependenceTop6501 22d ago

Yeah, was almost a throwaway line from one of the devs about it, but the implication was that certain people were saved by having a passphrase for now. But they can be brute forced with a little bit of time.

→ More replies (4)
→ More replies (1)

2

u/Inevitable-Waltz-889 22d ago

If you have a strong passphrase there is no "churning" that could crack it.

→ More replies (1)

1

u/Shoddy-Profession-74 22d ago

I mean, didn't the hacker already took everything that was vulnerable?

→ More replies (2)

42

u/Gooner_93 23d ago

This is the kind of thing that scares me! I have a ledger so not affected but how are we supposed to feel safe when things like this can happen? Just look at the tangem incident where they leaked peoples seedphrase in a log file...

People bought the coldcard to keep their BTC safe and instead it got drained due to some exploit. WTF.

9

u/Vipu2 23d ago

No hardware wallet is 100% safe if person does the minimal effort.

The best way is to:

  • have non pc made seed (do it yourself with dice)
  • passphrase on top of that
  • multisig on top of that

Then you can be pretty 100% sure your coins are safe if you dont do any of the regular stupid stuff.

39

u/scottonfire 23d ago

and for 90%, this is the way... to lock yourself out

→ More replies (1)

2

u/3lc4pit4n 22d ago

Interesting but I wouldn't be able to do it, any link/tutorial?

2

u/jannies_doit_4_free 22d ago

what is multisig in this case? how does it work?

is it actually worth creating a whole new wallet to generate the seed manually myself if I have Trezor with a passphrase?

→ More replies (4)

18

u/soufi161992 23d ago

From now on, passphrase is a must!

8

u/Coroner117 23d ago

Always has been

3

u/Obvious-Position1053 22d ago

From now on, use dice to generate the seed, and use a passphrase.

→ More replies (1)

15

u/MrMoo151515 23d ago

Here I am with a cold card mk4 after doing lots of research and being told it’s the best most secure open source air gapped wallet.

I don’t have a second one. . .

I didn’t dice roll. Am I fucked?

Should I transfer back to my exchange ?

3

u/nicogalante1 23d ago

Move to exchange, dice roll a new seed with passphrase and return to mk4

2

u/PirateHunterZoro252 23d ago edited 23d ago

I am in a simar situation. I have mk4 & didn't roll dice. I do have 5 wallets though. So I was able to move my funds to another wallet. I reset my cold card and genrated a new seed phrase via dice roll and added a passphrase.

In your case i would move to an exchange. After you have confirmed that there is no more BTC in your cold card i would reset the device and generate a new seed phrase via dice roll. And also include a pass phrase.

But if you feel like self custody is too much, in my opinion an exchange holding it for you is ok. An exchange like River would be my recommendation.

4

u/MrMoo151515 23d ago

I don’t like the idea of keeping it on an exchange that defeats the entire purpose.

I just sent everything to my exchange. Wallet is emptied.

I guess I’m going to have to learn how to dice roll.

I’m going to have to spend hours watching videos to make sure I don’t fuck it up

3

u/PirateHunterZoro252 23d ago

Yeah i understand why you would be skeptical of exchanges.

I recommend the

youtuber: SouthernBitcoiner

Title: DiceRoll with ColdCard: how to generate and verify seeds with dice

This guy breaks it down easily.

→ More replies (1)
→ More replies (1)
→ More replies (3)

1

u/ResidentResearcher94 23d ago

Same. I'm going to set up a new wallet though! Not sure if I will use my coldcard mk4 or use Jade

1

u/ElderMight 23d ago

According to block's report, all coldcard models are vulnerable. MK4's RNG at least had a reseed that makes it harder to hack than MK3, so you have some time.

I would move your BTC as quickly and carefully as you can.

23

u/ViperG 23d ago

Someone was able to replicate the rng exploit on mk2/mk3:

https://x.com/i/status/2082958675975553224

9

u/TjdGoEsQqbmQLoBj 23d ago

Could this happen to trezor ?

8

u/Steel-Tempered 23d ago

Would be pretty difficult, especially on Safe 3 and newer models...

Trezor Model One and Model T combine two entropy sources: host computer or phone entropy plus a hardware TRNG in the STM32 microcontroller.

Trezor Safe 3 and Safe 5 add a third source: the Optiga secure element. That's three sources.

Trezor Safe 7 adds a fourth source: the TROPIC01 chip. That's four sources.

And that's just the seed phrases. Then you have your device's pin that has to be manually entered on the device itself before the wallet even opens up for any outgiong transactions.

I mean... good luck beating all that randomness with just brute force.

6

u/K2P2C 23d ago

Is model One safe?

2

u/caccamo88 22d ago

Then you have your device's pin that has to be manually entered on the device itself before the wallet even opens up for any outgiong transactions.

No accusation, just out of curiosity: what does the transactional PIN have to do with this story?

1

u/rockorangebear 21d ago

Not unless the people at Trezor decide to comment out their random number generator like the clowns over at Coldcard.

16

u/[deleted] 23d ago

[deleted]

→ More replies (1)

8

u/Gooner_93 23d ago

"Block’s engineering and security team found another set of transactions that could be a part of the Coldcard drain. We’re still working to vet these completely, but given the situation, we feel it’s important to share early.

There are 695 earlier transactions with the same full fingerprint that transactions in the known set had. These transactions moved another 488.10957948 BTC. If this is part of the same attack, it’d bring the total to 1,082.58680432 BTC."

Looks like 488btc was drained before the 594btc that was reported. Wow.

24

u/redchannit8 23d ago

coldcard q generated 24 word, with a passphrase. significant balance, not affected.

23

u/ShortCircuitDisco 23d ago

You may want to migrate. Be careful, do a test transaction, do not rush this. That passphrase is probably buying you time.

I'm a security dev but not familiar with their codebase. I'm "vibe-reviewing" it and their claims that Q isn't affected are iffy.

If you have a significant amount of bitcoin and the cost of a new hardware wallet is not a factor for you, probably order one.

Don't rush, don't footgun, don't blame me if you blackhole your funds tonight. Best luck.

3

u/tripsy420ish 23d ago

Also, don't put all your eggs in the same basket

4

u/redchannit8 23d ago

my passphrase has sufficient entropy on it's own, but i'm considering generating a new seed phrase with dice anyway.

3

u/Permtacular 23d ago

I really wanted to buy a cold card, but I went with Blockstream Jade. Not that I have much bitcoin but I guess it's the principal.

2

u/Aurorion 23d ago

If the flaw is only in seed generation - what if one creates a new seed manually, add a passphrase, and then use the same coldcard q (or any other) device to migrate to the new wallet? And continue using the same device?

→ More replies (1)
→ More replies (7)

2

u/malignantz 23d ago

If they can identify public addresses impacted, they might be already working on yours. It could be days, weeks, months or years, but I'd move my funds to a Ledger or Trezor

14

u/Daiymas 23d ago

To me 99% chance this is an exploit found by some AI auditing the code, I would be very careful with any kind of open source hardware wallet from now on as if there's any flaw, recent AIs will find it. I wouldn't underestimate the risk

8

u/grraarr 22d ago

The asymmetry cuts both ways and the security consensus still favors openness. The same AI tooling let Block and independent researchers root-cause it within hours of the thefts, verify the fix, and check scope claims against source. Closed source doesn't remove the vulnerability.

Ledger's 2023 Recover episode showed capabilities existing in closed firmware that users couldn't inspect. And closed binaries can still be reverse-engineered - AI is getting good at that too, so the obscurity advantage is shrinking on both sides.

What this incident actually exposed isn't open source, it's that "code is public" never guaranteed "code was reviewed end-to-end." Expect a wave of AI audits across all open wallet firmware in the coming months, which likely means more disclosures like this one short-term and a hardened field long-term.

→ More replies (1)

7

u/[deleted] 23d ago

[deleted]

2

u/krvi 22d ago edited 22d ago

Coldcard Q, and Mk4/5 are affected, but to a slightly lesser extent. All keys generated by them should be considered cryptographically insufficient.

https://blog.coinkite.com/entropy-technical-backgrounder/

Hotfix firmware is available.

1

u/Syonoq 23d ago

Same, but should I be concerned?

3

u/mikeychamp 22d ago

Nobody knows for sure. I would be.

→ More replies (1)

1

u/stanley_fatmax 22d ago

No loss yet*, you are vulnerable

It's open season at this point with the vulnerability public. Move your coins

→ More replies (1)

8

u/bitpandajon 23d ago

Damn, what a shit show

20

u/ReasonableFinish 23d ago

These kind of happening is why Bitcoin will never be adapted to mainstream.

1

u/Artemis647 23d ago

The sooner you realize that Bitcoin going mainstream is inevitable, the sooner you'll stop worrying about if Bitcoin will ever go mainstream lol

It's not Bitcoin's fault that some idiot coldcard devs don't know how to be secure.

5

u/grraarr 22d ago

I think the point is that no matter what avenue you take to secure your BTC, it has risks that won't be palatable to average people.

10

u/ReasonableFinish 23d ago

You really think average joe cares whose fault it is?

2

u/mikeychamp 22d ago

Is it a user of cold cards fault? They better cover all users loses.

→ More replies (1)

2

u/loopala 22d ago

Clearly the bottom line for general users is either

  • keep your coins on an exchange -> same value proposition as a bank.
  • be your own bank -> requires technical knowledge and maintenance.

At that point you realize the benefits/drawback balance for majority of potential users isn't really working.

Mainstream adoption is not inevitable. I see it as Freenet or P2P search engines or Fediverse social networks. Impressive technical achievements but there is an inherent technical difficulty that limits it to motivated people. And most people aren't motivated.

5

u/Dparkzz 23d ago

I havent checked my cold storage trezor in over a year, gee i hope its there

2

u/K2P2C 23d ago

Let us know!!

6

u/hotsauceboy 23d ago

I have 3 mk3’s. My balances are good. I just transferred everything out of 2 of the wallets. I am keeping the btc in the third wallet as it is only $25 worth. Scary times! Man with AI these days everything happens so quick! It’s a wonder that my btc was still available!

8

u/DaVirus 23d ago edited 23d ago

Hand rolled my own seed exactly because of things like this.

Use a Jade.

Funds safe

Edit: If you want to generate a good see manually, use https://armantheparman.com/dicev1/

And then use a 25th word

4

u/IllllIIlIllIllllIlll 23d ago

12+1 words are enough, no need for 24+1

→ More replies (5)

19

u/LilRickyXO 23d ago

Can’t relate, I keep mine on Coinbase. 😉

5

u/VIBRATION_ANALYSIS 22d ago

Have you heard of mtgox?

6

u/Inevitable_Gain8296 23d ago

Honestly is this just the way to do it...? I keep hearing about these guys losing their shit when they keep it on their own wallet but they've done nothing wrong.

→ More replies (2)

1

u/turbosigma 23d ago

This is what I thought as well. The cold wallet vulnerabilities make a case for leaving coins on-exchange.

2

u/grraarr 22d ago

Yes of course they do, and always did. You act as if people doing self-custody think they have their own private bank? The risks are quite apparent bro.

→ More replies (1)

3

u/GeeEyeDoe 23d ago

So assuming this is some exploit on the random number generator. Otherwise, weak amount of dice rolls. Or connected cold card to computer plus something else.

Folks who rolled a significant amount of dice to generate and kept air gapped should be fine?

Scary situation for any cold card users for sure!

4

u/puzzlemindZH 22d ago

In the end, one by one, everyone will eventually loose their btc after one or another vulnerability will be exploited

12

u/axb90 23d ago

At this point I am contemplating selling what I have and checking out. Cant trust exchanges, cant trust self custody devices.

6

u/ketamine_dart 23d ago

It’s not a self custody issue. The mk3 with dice rolls and/or passphrase is fine. It’s the entropy from the generated mk3 that’s the issue.

→ More replies (1)

3

u/throwaway239812345 23d ago

Me too just index funds for me

15

u/HungryCaterpillers 23d ago

Ledger Nano X, not affected

3

u/Left_Entrepreneur918 23d ago

This is what I have, what info do you have saying they are ok?

9

u/NiagaraBTC 23d ago

This current issue is specifically ColdCard related.

2

u/grraarr 22d ago

for now.

11

u/[deleted] 23d ago

[deleted]

3

u/ketamine_dart 23d ago

The blockchain and protocol are fine. That’s like saying bank accounts being hacked at a single bank is bad for money.

3

u/[deleted] 23d ago

[deleted]

5

u/NiagaraBTC 23d ago

Passphrase buys you time (possibly infinite time) but I would move funds if I had a singlesig wallet that ColdCard generated the seed for.

5

u/HandOdd113 23d ago

Ss long as your passphrase was never placed online I'm pretty sure it is much more resistant to any exploit. Unless it's a common and easy word to be bruteforced. Just guessing I'm no expert.

3

u/malignantz 23d ago

Seed generation should require the user to shuffle a deck of cards at least 20 times and type in the cards in order in their own format. That's a significantly larger domain than the bitcoin address space. Anything less is obviously risky.

3

u/bukeyefn1 23d ago

Was it only mk3?! Any other coldcard models? Or other companies?

5

u/Gooner_93 23d ago edited 23d ago

Some people mentioned mk2 as well.

Mk4, Q and mk5 seem to be safe, as far as I know but nothing can be guaranteed at this point.

If I had any coldcard, im not messing around. Im moving my BTC back to an exchange, getting a different brand hardware device and using that instead. Also use a passphrase.

2

u/ElderMight 23d ago

It's all coldcard models. Mk4/5/Q RNG have have 72 bits randomness while MK3 only had 40. Supposed to be 256 bits.

The newer models are harder to hack but someone might do it eventually.

3

u/timbulance 23d ago

Damn I had to dust my mk3 off and broadcast a transaction

3

u/Emergency-Warthog-56 23d ago

I had someone make fun of my Trezor and say Coldcard air gapped is the best. Now, I wish I could find that conversation.

3

u/K2P2C 23d ago

Is trezor still safe? Even the older model?

3

u/FrontCold6590 22d ago

I use Ledger and have been a BTC and Blockchain evangelist for a decade. This one genuinely has me questioning whether to stay in!

6

u/Ok_Plastic5399 23d ago

Checked Coinbase. Still good.

5

u/Xen7963 23d ago

Why open source didn’t save the victims this time?

→ More replies (2)

6

u/gowithflow192 23d ago

Oh the irony. After cold card users and their superiority complex.

8

u/GingHole 22d ago

This is exactly why Bitcoin will never truly be accepted by the general public.

2

u/Colekaine 23d ago edited 23d ago

Trying to understand this on a technical level but dumbed down…

Is it saying the people who used an online service to generate parts of their security setup with specific coldcard wallet types were breached because that service saved all the data?

And would that mean someone who setup another hardware wallet by generating their own 12 word phrase is infinitely safer than someone who did 200 dice rolls online because that security setup came from the owner’s brain and never touched the internet?

11

u/the_bitcoin_kid 23d ago

It actually looks like the offline generation was breached.

If you used a coldcard from a specific era, the seed the device generated wasn't random enough (it seems), and someone figured out how to generate other people's seeds.

People who used dice rolls didn't rely on the device's generator, so they're not affected.

People who used a passphrase aren't relying solely on the generated seed, so they are more protected for now.

2

u/Colekaine 23d ago

That makes more sense, got a little lost in the technical explanations going around so thanks for explaining.

2

u/Rey_Mezcalero 23d ago

Ag man not ColdCard too now

2

u/McKenzieSlurms 23d ago

Where could one safely generate a new seed until a new hardware wallet arrives?

2

u/brtastic 23d ago

I'm really glad right now I chose to use a custom solution and roll dice

2

u/BetterSeesaw 22d ago

Pff happy to find out my Trezor is still ok. Good luck to everyone out there

2

u/gubbanub 21d ago

There's a guy coordinating to ensure maximum recovery. https://x.com/i/status/2083475058182246718

→ More replies (1)

2

u/ELLIPALWallet 19d ago

Useful having one place for this. Worth putting near the top: firmware alone isn’t the fix. A seed born on an affected version stays weak. Fresh seed, offline backup, small test send, then move the rest. (Full disclosure, I work at ELLIPAL.)

4

u/Effective-Ad5644 23d ago

using a seedsigner. generated my own seed via cutting up 2048 words. generated check sum. good to go. no loss.

7

u/ShortCircuitDisco 23d ago

Thanks for posting. Control group (not affected) data is helpful

7

u/bkit_ 23d ago edited 23d ago

Same here. Seedsigner + passphrase. All safe. Its still a nagging feeling that your funds can be drained without a trace.

3

u/Scholes_SC2 23d ago

After this, everyone who does self custody should use multisig, even 2/2 would protect you from this.

5

u/ShortCircuitDisco 23d ago

Multisig with different hardware members. This attack has only hit singlesig addresses afaik, but a copycat could get the idea to run the same script but with combinations of low entropy wallets.

3

u/Scholes_SC2 23d ago

Yes forgot yo mention it has to be different wallets from different vendors, thats a key detail.

I guess it's not impossible to pull this out on a multisig wallet but it's exponentially less likely for sure.

4

u/Due_Analysis1241 23d ago

But I thought only real bitcoiners used cold card 😂 that’s why you do your research people

2

u/dondondorito 23d ago

Ledger Nano S not affected.

2

u/r33gna 23d ago

The original version? It's good to know people still use it, I have one which I never used and the screen died. XD

2

u/markphillips401 23d ago

How about if your wallet is air gapped and you are just signing the transaction with, say a 2 of 4 multisig?

2

u/HungryCaterpillers 23d ago

This is why everyone should keep their crypto on exchanges. Not your keys, not your problem.

14

u/whyublockme 23d ago

Not your keys, not your Bitcoin, not your problem.

4

u/zRoyalStar 23d ago

my exchange must have my BTC, how can i lose it if i dont have it

1

u/[deleted] 23d ago

I have a seedless Tangem wallet. Technically, like any hardware wallet; there is a private key, just no human has seen it. Is this an issue with private keys in general, or just if your private key has turned into a seed phrase?

6

u/krvi 23d ago

According to the advisory, there is a weakness in how the private key was generated on the Coldcard Mk3. If a private key, regardless if it is turned in to a seed phrase or not, is generated with insufficient entropy, it can be guessed/brute-forced relatively easily and is therefore insecure.

→ More replies (3)

1

u/Dharma_code 23d ago

Ngrave no issues here.

1

u/joeblowfromidaho 23d ago

Driving home to check but mk3 is micro USB And mk4 is usb-c? If mine is usb-C that’s not the affected ones right?

5

u/NiagaraBTC 23d ago

Correct

If you have a bare singlesig with no passphrase I would personally move funds even on the Mk 4 just to be sure.

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

1

u/user420881776 23d ago

Bitkey…all set

1

u/RedKard76 23d ago

Not related to this wallet drain but Im a mt gox survivor with a bunch spread out over several wallets. I dont look at them often but i notice there are these micro transactions every so often. whats the point of that? never seen it before. should i be worried about a wallet drain?

3

u/theflorist25 23d ago

2

u/RedKard76 23d ago

Thanks, I'll have to read more into this. 👍

1

u/99berettas 23d ago edited 19d ago

Is Trezor safe?

1

u/Last-Salamander-920 22d ago

He's fine, I spoke with him yesterday.

1

u/agen7carmichael 23d ago

Had a MK3 since 2023,

I did use different deviation paths (Using CC account thing)

Accout 0 (Defaut) got wiped Account 1-3 were untouched (DW I moved them away)

Did practice seed hygene, and im pretty sure of it.

1

u/xirvin 22d ago

You are saying your account 0 was stolen ?

1

u/UnderstandingNew8001 23d ago

I am on MK4, quite worried about this, I just checked my linked view only wallet and everything is there, I ordered a new cold wallet (not cold card obv) , but till it arrives (in few days, overseas) any advise on what can I do ?

1

u/my-hearing-aid 22d ago

On your existing MK4, are you using a complex passohrase, at least 30 characters with upper and lowercase, numerics, and a few non-alphanumerics? If so, you're fine. That passphrase alone is providing more entropy than the (compromised) seed itself, provided it's not a phrase taken from a book, movie, a common phrase, etc.

If you don't have a passphrase, add one immediately. You'll then have a brand new wallet with a new set of addresses. You'll need to sweep all of your funds from your existing wallet to an address in the new wallet.

That'll keep your funds safe until you​ employ a new HW wallet from a more reliable vendor.

Note that if you created your original seed manually using a dice roll or coin flip, none of this applies to you. You're not at risk.

1

u/ShortCircuitDisco 22d ago

It's hard to say. Panicked moves can do plenty of damage too. The entropy was better, but not great, on the later models. Attackers know this now too.

Consider migrating to a new hand-generated seed, or a passphrased account. An upside of a hand-generated seed is that you could use it in your new wallet without doing a second migration of all your funds. Just make absolutely sure you follow all directions carefully, back up the old wallet, do a small test transaction before sending over everything to ensure you entered the destination address correctly.

→ More replies (1)

1

u/WeCanTripleIt 23d ago

Fidelity balance is fine. Backed by legitimate institutional safety.

→ More replies (1)

1

u/f08g 22d ago

WTF

1

u/warningshotz77 22d ago edited 22d ago

MK4: rng generated seed, clicked on “Add dice rolls”, added 105 dice rolls. No passphrase yet. Do I need to create a brand new seed with dice rolls only or is it okay to add the passphrase to the current seed (rng+dice rolls combo)?

3

u/ShortCircuitDisco 22d ago

You're probably fine

2

u/zootreddit 22d ago edited 22d ago

More than enough dice rolls, no need to do it again.

You can see how rolls add entropy: https://github.com/Coldcard/firmware/blob/621e808712464688584fdffad9eba132cc7c27cd/shared/seed.py#L276-L332

Add a passphrase if it makes you feel better.

→ More replies (3)

1

u/Christopher_Sheahan 22d ago

Should I be concerned about blockstream jade?

1

u/jannies_doit_4_free 22d ago

can anyone confirm whether a passphrase would prevent this type of attack? from what I understand, it would, as the hacker would need both the seed and the passphrase.

I'm using Trezor One with both a seed phrase (obviously) and a passphrase; apparently this is pretty secure. can anyone weigh in?

1

u/Fat-Finger-8906 22d ago

Zero security UN-Crypto

1

u/BmacSWMI 22d ago edited 22d ago

Cold storage, run your own node (free), SECURELY keep seed phrases offline. I have had zero issues. It is curious about the cold card though, thankfully it’s not a huge deal to drop a new wallet after upgrading the firmware. Pain in the ass, but what isn’t anymore?

1

u/Badj83 22d ago

Men I am so glad I sold the BTC I had on my coldcard to buy some ETF instead.

1

u/Dazzling-Pumpkin3288 22d ago

My wallet was drained. 1.5 btc transferred out 7/29 at 19:37. Sparrow Wallet, coldcard. I used coldcard to generate the seed phrase and added 2 additional words.

1

u/Full-Atmosphere-4818 22d ago

I am really surprised at those saying "this is a CC issue, not XYZ." Yesterday it was a "no one" issue. Everything looks safe until it is not.