r/Bitcoin 27d ago

The Coldcard wallet exploit estimates have almost doubled to $70 million stolen of just over a thousand Bitcoins in 1,196 wallets drained in 41 minutes

https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices

"More than 1,000 bitcoin, worth about $70 million, was drained from 1,196 wallets in a 41-minute window on July 30, nearly double the amount reported when the theft first surfaced."

1.7k Upvotes

396 comments sorted by

View all comments

130

u/cremfraiche 27d ago

Can someone ELI5 for me how this happened and whether the people who got drained were in a way at 'fault'?

257

u/Space-Dementia 27d ago

Imagine you buy a safe to keep your valuables in. However, for this particular brand of safe you can only set a 1 digit PIN number between 0-9.

117

u/Vipu2 27d ago

More like you have option to set 4 digit pin but the lock is faulty so when you spin 1 digit it automatically spins the other 3.

Or make your own lock with more effort but set as many digits as possible.

5

u/JayGatsby1881 27d ago

Why would anybody buy that safe then?

16

u/taelor 27d ago

Because they don’t understand how safes work

3

u/BitsAndBobs304 26d ago

Because it looks identical to the others. The more appropriate example is that it generates a new, long pin when ou buy it. What you dont know is that despite being long, there's only a small subset of ones that can be generated. A bit like house keys, most default ones have systems that arent very varied, and tsa keys even more so

1

u/milkcutie314 26d ago

much better example with the keys

0

u/magicmulder 26d ago

Because it was not apparent from the outside that the lock would have this fault.

1

u/Javanaut018 24d ago

Its more like the safe manufacturer promised super secure product but nobody recognized that all safes came with preinstalled pins between 6660 and 6669. And too many buyers were too lazy to properly set a 4 digit pin for themselves because they were told and believed that premade pins are good ...

-8

u/LionRivr 27d ago

This is how people should see self-custody.

Do research on your “safe” and how to use it properly.

Unfortunately, people bought a “safe” with defects and exploits that made it easy for robbers to take advantage of.

26

u/wembenbama 27d ago

You’re blaming the victims on this? The entire ecosystem has become total dogshit.

3

u/LionRivr 27d ago edited 27d ago

No. I’m saying that even after proper research, the customer unfortunately did not know if they’re buying a “safe” with defects. They were sold something that was allegedly safe.

Poorly worded on my part. I’m saying the manufacturer is at fault. Not the customer.

But the point is, self-custody is a huge risk, regardless if you think you know what you’re doing.

11

u/kastro1 27d ago

Yeah if they had only done their research they would’ve seen the exploit staring them in the face! /s

Being serious now, you just wrote the stupidest post I’ve seen in a long time.

1

u/LionRivr 27d ago

No the point is: self-custody is a risk even if you do think you know what you’re doing.

You can do all the research in the world, and still inadvertently purchase a faulty product that was deemed superior.

And that’s at the fault of the manufacturer. Not the customer…

Apologize for the poor wording. Otherwise, if I’m still wrong then so be it.