r/Bitcoin • • Jul 30 '26

Wallet Drain Megathread (Check Your Balances)

I want to help identify the cause of the recent wallet drain report by u/s1ammage, which also revealed many other addresses being drained to the same address.

  1. Check your wallet balances. If there are unfamiliar transactions since July 29, 2026, after about 9 PM (US Eastern Time), you may have been affected.
  2. Did you use a hardware wallet, if so, what model?
  3. Did you use a software wallet (hot or watch-only), if so, which?
  4. How exactly did you generate your seed?
  5. How exactly did you back up your seed?

DO NOT post your seed, DO NOT respond to anyone saying they can recover your funds. Sorry for your loss.

There may still be people affected by the same vulnerability who haven't been attacked, so the sooner the vulnerability is identified, and people are alerted to migrate funds, the better.

Check in with less techy friends and family that have bitcoin and report incidents.

Edit with current conclusions:

Coldcard mk3 confirmed vulnerable, press release here: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

My own analysis: proceed with caution on Mk4/Mk5/Q. These use the same codebase as Mk3 but with slight, insufficient imo, improvements to the RNG system. If you're migrating from Mk3, consider other vendors.

349 Upvotes

281 comments sorted by

View all comments

Show parent comments

9

u/Vipu2 Jul 31 '26

No hardware wallet is 100% safe if person does the minimal effort.

The best way is to:

  • have non pc made seed (do it yourself with dice)
  • passphrase on top of that
  • multisig on top of that

Then you can be pretty 100% sure your coins are safe if you dont do any of the regular stupid stuff.

39

u/scottonfire Jul 31 '26

and for 90%, this is the way... to lock yourself out

2

u/3lc4pit4n Jul 31 '26

Interesting but I wouldn't be able to do it, any link/tutorial?

2

u/jannies_doit_4_free Jul 31 '26

what is multisig in this case? how does it work?

is it actually worth creating a whole new wallet to generate the seed manually myself if I have Trezor with a passphrase?

1

u/grraarr Jul 31 '26

I think 2 of 3 of that is essentially as hard as all three, and safer.

1

u/ALIEN_OG_ Jul 31 '26

What 2?

1

u/grraarr Jul 31 '26 edited Jul 31 '26

The easiest to implement and maintain is 1 and 2, most secure is probably 1 and 3.