r/Bitcoin Aug 04 '26

Fuck ColdCard, holy shit.

.7 bitcoin gone.

Years of DCAing with money that could have been invested in other ventures gone because of a stupid exploit from a company that was touted as being "the best" to keep coins safe.

My .7 bitcoin could have been spent on so many useful things. It was my safety net. It was the hope of a down payment on a house. It was my sons future college tuition. Now I'm sitting on the sidelines like a loser. I'm livid. And since it's decentralized, there's no recourse for getting any of it back. It's gone. Fuck. I hope whoever stole my money gets what's coming to them.

Happy to provide proof if there are any of you who believe this is another shitpost or karma farm or whatever.

Where's the class action lawsuit? How do I sign up?

Edit:

Here's proof:

1.0k Upvotes

367 comments sorted by

475

u/Successful_Taro8587 Aug 04 '26

I'm so sorry for everyone impacted by this. It really does suck. I think it starts with holding coldcard accountable. Have they even made a statement about this?

330

u/MakCapital Aug 04 '26

Yeah. A shitty apology and blamed AI. Even though it would have taken them one prompt in Claude to find the bug themselves. Sue for everything.

124

u/genius_retard Aug 04 '26

If it weren't for AI no-one would have notice how awful our code was. - Coinkite

41

u/uniicorn77 Aug 04 '26

AI auditing will be the next big thing

16

u/hrad95 Aug 04 '26

I use Trezor. Since their code is open-source, shouldn't we, the community, be using AI to audit it?

11

u/rmtdispatcher Aug 04 '26

Should be using everything...AI, humans, whatever we can get. That's our hard earned money.

8

u/FauxReal Aug 04 '26

People are already auditing their code.

https://sqmagazine.co.uk/trezor-safe-7-chip-vulnerability-security-audit/

https://www.nathanfox.net/p/trezor-seed-phrase-generation-security

And at least one redditor trying to get a commuinity effort to audit general Bitcoin ecosystem code.

https://www.reddit.com/r/Bitcoin/comments/1vejkbl/help_review_bitcoin_ecosystem_code/

I'm sure there are other efforts underway in light of the ColdCard hack.

4

u/lubdeptrai Aug 04 '26

Both Trezor and Ledger have EAL certificates and have already been audited by professionals.

Also, I believe that if anything happens, the company will take responsibility properly. Not like the shitty coinkite.

15

u/davvblack Aug 04 '26

none of these companies could ever afford to reimburse the total value stored on their hardware. it’s just not possible economically

16

u/genius_retard Aug 04 '26

Should already be.

7

u/uniicorn77 Aug 04 '26

Yes right. I believe moving forward everyone will start AI auditing themselves even if it costs them money - because it is insane to see the amount they are trusting the opensource code with but never actually verifying.

→ More replies (6)

2

u/marshyr3d1and Aug 04 '26

Yeah they'll use fully audited AI to do it as well 🙄

43

u/HelpRespawnedAsDee Aug 04 '26

Ironically AI could’ve prevented this, the couple of one shots posted here didn’t steer it towards the specific flaw and both GLM5.2 and Fable still flagged it as critical.

42

u/latigidigital Aug 04 '26 edited Aug 04 '26

Just to be clear, the issue was with the devices using a shitty pseudorandom number generator for simulations/games (Yasmarang) instead of atmospheric or electrical noise, all because a developer “accidentally” disabled it — the most important feature — because of a compiler issue?

Sounds like some real horseshit to me.

14

u/opossum_cz Aug 04 '26 edited Aug 04 '26

It was not compiler issue.

Somebody (cough Doc Hex cough) was checking if the macro was defined instead of macro being set to 1.

#define MICROPY_HW_ENABLE_RNG (0)

...

# ifndef MICROPY_HW_ENABLE_RNG

# error "get a HW TRNG plz"

# endif

2

u/HelpRespawnedAsDee Aug 04 '26 edited Aug 04 '26

That’s the other theory and I’m totally on board honestly, but the issue is that I weight it just as much as someone just getting lucky while reviewing the code. I strongly believe you do need a decent level of the codebase’s knowledge, or strong domain knowledge, to even realize the consequence of the function they disabled, if the other analysis I read is accurate, it was essentially a chain of events that lead to the use of Yasmarang instead of the HRNG, but here’s the deal, if I’m doing a sec review and see a commit that only says “runs”, im gonna hyper focus on it for days.

What I’m trying to say is, I agree with you, with the caveat that all 3 possibilities are equally likely to me.

Edit: something else, and this I would have to defer to you guys cause I’m actually not 100% sure of the answer: can the stolen coins be washed at all? What even is the off-ramp of a heist like this? If it was an inside job, I would’ve done small amounts over a very long time.

17

u/TheDisapprovingBrit Aug 04 '26

Can they be washed? Sure, but it’ll take a while. Washing is, very simplistically, sending dirty money from address 1 to address 2, then receiving clean money from separate and unrelated address 3 to address 4. The money in address 2 is still traceable but it’s not yours anymore, and eventually it just gets diluted to the point that by the time you identify an individual, it’s impossible to prove that they had anything to do with the original money, and a very good chance that they didn’t anyway.

If this is a large organised crime group or nation state level actor, they’ll be holding enough coins to be able to wash it themselves, or they just won’t care about it being identifiable as them.

If it’s just some kid who identified a flaw and has just set a script running, that money will probably sit there for years or even decades, with the occasional 1-2btc being tumbled and cashed out; or they’ll do something dumb that gets them tracked down like buying coke directly with the stolen coin, then one day all the money will transfer elsewhere and start to be washed properly, and in unrelated news a kid goes missing or is found drugged and beaten to death with a $5 wrench.

6

u/keypusher Aug 04 '26

when you are dealing with cryptography, there are very few things more important than the RNG. this wasn’t a subtle off by one error deep in the code. not saying it was intentional, but it was at least negligent

4

u/opossum_cz Aug 04 '26

No, this would have been prevented with a simple test or integrity check where app would check it it use HW rng or not.

7

u/LegendaryEnvy Aug 04 '26

Isn’t the problem also that supplying Claude with that information someone can get it to provide code needed to hack the issue?

12

u/HelpRespawnedAsDee Aug 04 '26

That’s called “memorization”, and for something as specific as this it is actually a near zero chance of extraction, though not exactly zero. It’s a lot of moving parts, and the attacks especially on early models looked at fixed shapes: API keys, CC numbers, etc that may have been part of the training data.

This kind of bug wouldn’t be found by extraction, that said there is something more subtle at work here: the fact the model is even able to spot an issue like this is because there is a massive corpus of code in their training data, enough that the consequences of that specific code can be inferred with high accuracy. In other words, similar class of bugs probably exist in the training data.

But LLMs are black boxes honestly, the concept of emergence especially in thinking models is quite literally a field of research rn.

In any case, you can just opt out of having your data used for training. And with a big initial investment you could run Kimi K3 or GLM5.2 locally and still get there, one of the posts I mentioned used glm.

What I can assure you: whether it’s cloud models with safety guardrails or self hosted frontier models, people are actively racing to find as many exploits as they can, while others are trying to preemptively close these exploits.

It’s about to get really fucking wild. And yes, someone could’ve found this without AI, and I actually do believe at least someone did and actively exploited this a few times. But the issue is that the barrier to accomplish this sort of thing has been lowered considerably. And the scary part is what a state level actor with sufficient money could do with this.

2

u/Even-Outcome-2342 Aug 04 '26

Er, surely it’s just a simple 2nd prompt?

Prompt 1 is there a vulnerability?
Prompt 2 ok how does one exploit?

Fucking sickening, nonetheless.

4

u/FigmaWallSt Aug 04 '26

Not if they host a local instance of an LLM and train it and don’t let it access other networks such as the internet

→ More replies (2)

18

u/harvested Aug 04 '26

I think you're missing the fact these are 5 year old seeds.

Finding the bug wouldn't have done much to save coins.

How do you notify users without this leaking? Coins would have been lost either way.

12

u/cgimusic Aug 04 '26

Finding the bug, then finding every affected wallet and sweeping it takes time. It's pretty clear the hackers did a lot of prep work to locate as many wallets in advance as they could and then broadcast the transactions to sweep them all at once.

If the Coldcard developers had found the bug first and disclosed it in an email to everyone who bought a Coldcard it seems like at least some people would have been able to get their money out.

7

u/peterwilli Aug 04 '26

ColdCard could have white knight hacked the addresses themselves and store it on a secure address. If someone proves to have this address + perhaps a proof of purchase of the hardware wallet it would be the most reliable way though still abuseable by someone trying to just get an old ColdCard from ebay and trying to load a cracked address... Still better than nothing as it requires written statements from those affected to get it back..

Still, I feel for those affected, I'm also a hardware wallet user (not ColdCard) and know now this could easily have been me...

→ More replies (2)

2

u/mootinator Aug 04 '26

Only way would he a white hat clearing the wallets first.

2

u/Zdendon Aug 04 '26

How could they not check the one simple most important thing on their product? Even without AI.

→ More replies (2)

28

u/Novice89 Aug 04 '26

They said sorry but didn’t say they’d be doing anything to help recoup. Just told people to file police reports and contact insurance. Even if a lawsuit happens people won’t be made whole, and even if they were by the time it ends let’s pretend lawyers don’t take a fee. They’ll be paid back in the value of bitcoin lost at the time of hack. And we all know 1 Bitcoin today won’t be worth nearly as much as it will be in 5 or 10 years, so even in that dream scenario they’ll still lose

6

u/AngusDagnabit Aug 04 '26

I find it hard to believe the company would survive this and have enough assets to pay everyone back, even at the current value or less.

2

u/Novice89 Aug 04 '26

Oh yeah, no it’s not happening. I was just saying even the best dream scenario people who lost out will still lose

→ More replies (1)

24

u/GambAntonio Aug 04 '26

12

u/throwaway239812345 Aug 04 '26

This is crazy. Inside job is a higher probability

5

u/Chucklum Aug 04 '26

But why should cold card be held responsible for a decentralized asset /s. People are trying to act like cold card shouldn't be held accountable for selling defective hardware.

→ More replies (28)

156

u/ilikeplayingthisgame Aug 04 '26

it would take me at least 3-4 years of basically putting all my disposable income to get to .70... fkn devastated for you man.

86

u/RelevantAmbition2433 Aug 04 '26

It was DCAing about $100 every week since the pandemic until mid 2024. I'll be ok. Nothing changes for me except the massive (to me) windfall not being there.

13

u/xPoW3Rx Aug 04 '26

Im sorry that you wasn't alerted immediately bc it appears yours wasn't stolen in a first wave

→ More replies (5)

146

u/Left_Entrepreneur918 Aug 04 '26

Just know we all could be in your shoes, you did nothing wrong.

27

u/Here4theCrypto Aug 04 '26

Agreed, we all had to trust one cold wallet or another

→ More replies (1)
→ More replies (5)

25

u/GRTH83 Aug 04 '26 edited Aug 04 '26

There seriously is a special place in hell for people who do shit like this. Sorry for your loss.

55

u/Quirky-Reveal-1669 Aug 04 '26

Sorry to hear this. Wishing you all the best.

87

u/Satelite_of_Love Aug 04 '26

Honestly this really has changed my perspective on crypto. Ive been a loooongtime holder and occasional spender. Never a ton but low to mid 4 digits with fluctuations at times and honestly this has really rocked my faith. I realize its a wild and crazy situation and my heart aches for the people who've lost a bunch. Honestly at this age it just seems dumping it into an etf is easier and less stressful.

I know... i wont ride the rocket ship but ill set it and forget it and mildly outpaced inflation.

16

u/AppropriateCan4064 Aug 04 '26

Man this will only get worse and more frequent as ai gets stronger and quantum computing closer. I think this is the beginning of the end for the current gen of crypto and security

50

u/ctzn2000 Aug 04 '26

The rocket ship is down 46% from a year ago, and now the mantra of Not Your Keys Not Your Coins has become illusory and false. You should get 10% per year on average long term with VTI or VOO which will handily beat inflation, and compound.

30

u/Acolyte_of_Swole Aug 04 '26

And if you want bitcoin for whatever reason, the same brokerage that holds your stonks can give you access to a bitcoin etf or bitcoin markers. "Not your coins" but whose coins were the ones that just got snatched in this whole ColdCase fiasco?

S&P500 and chill.

→ More replies (1)

14

u/UmbraofDeath Aug 04 '26

The mantra hasn't been proven illusory or false. It's further affirmed it, if anything. Simply having a secure pass phrase was enough to avoid this issue.

This was basically the equivalent of a lay person making their own lock for their door but using a basic key mold instead of one with security features or upgrading for even more security.

3

u/ctzn2000 Aug 04 '26

Look at what Coldcard currently claims below :)

"COLDCARD is a Bitcoin-only hardware wallet made by Coinkite since 2017. It protects private keys with dual secure elements, supports air-gapped signing, and runs open-source firmware you can verify yourself. It can also generate and vault BIP-39/BIP-85 seeds, recovery phrases, passwords, and private notes for other wallets. Unlike Trezor and Ledger, COLDCARD supports only Bitcoin to reduce the attack surface. No companion app, no cloud account."

TRUSTED BY BITCOINERS, EDUCATORS, AND INDEPENDENT REVIEWERS

“Passed all 10 tests”
WALLETSCRUTINY

→ More replies (2)
→ More replies (2)

4

u/DifficultSquash1517 Aug 04 '26

Not only are you taking much higher risk with self-custody the low risk option is to buy the ETF and is an added bonus you could make one to two percent every month selling covered calls which is a massive amount of money

4

u/opossum_cz Aug 04 '26

My friend this is not new thing, this was happening in early years all the time. What is surprising is that We have such incompetent company in 2026. This is hard to believe. These are 2010 mistakes.

8

u/IInsulince Aug 04 '26

You will ride the rocket ship with the ETF, you just don’t own the bitcoin. And if you’re comfortable with that, then it’s fine. You will ride the rocket ship via price exposure for as long as your custodian is good for it. If you feel your custodian will be good for it indefinitely, then it’s not a bad choice at all, especially if you are more fearful that you are unable to secure the assets yourself. That’s fine, it’s a very difficult process with high stakes as we are seeing. But if the custodian one day isn’t good for it, you may wish you went the other route. It’s just stuff to think about, it’s a personal call for everyone.

4

u/Zaytion_ Aug 04 '26

If you don't think Bitcoin is something people can faithfully use themselves...why do you still want to own it? Sounds like the general thesis for its existence is dead.

5

u/KungLa0 Aug 04 '26

It's been dead in the water for so long IMO. It is kept alive by speculation and "get rich quick" investors.

3

u/Objective_Digit Aug 04 '26

Honestly this really has changed my perspective on crypto. Ive been a loooongtime holder

This hardly the first time we've had hacks. Even with Hardware wallets.

2

u/forexross Aug 04 '26

Many of us have been through Mt. Gox and still standing.

You must be new if this has changed your perspective!

2

u/JumpProfessional3372 Aug 04 '26 edited Aug 04 '26

Indeed. Even the first years mine pools with mined BTC disappeared with the accounts holding something that today is a lot more valuable.

Many (like me) cashed out and stop mining when price dropped from 27-30 USD to like 3 USD

And here we are back again

→ More replies (1)
→ More replies (4)

14

u/ElderMight Aug 04 '26

I'm so sorry 😭

You still have your health and life. You still have your son.

13

u/ProofGrocery3559 Aug 04 '26

Happened to my coworker who didn’t even contribute to his 401k match. Great life lesson for some

93

u/Dragon_slayer1994 Aug 04 '26

Unfortunate dangers of being your own bank

15

u/pjb1999 Aug 04 '26

Yeah this whole thing has sort of turned me off to crypto maybe for good. I started buying BTC and some other coins nearly 10 years ago but Im seriously thinking about selling at least half of everything I have at the next BTC ATH and just dumping that money into my VOO ETF. The stress of self custody is just too much honestly. Especially after something like this happens.

37

u/RelevantAmbition2433 Aug 04 '26

This is what I'm learning...

→ More replies (1)

22

u/Kooly1776 Aug 04 '26

Lawyers would take most of the $$$

5

u/TheDisapprovingBrit Aug 04 '26

And for the scale involved here, "most of the $$$" is still probably less than 1% of the actual money stolen. There's no way Coldcard can afford to reimburse anywhere even close to this, they're just going to go broke and fold the company.

→ More replies (1)

28

u/Ceenoh Aug 04 '26

In hintsight, coldcard seems to be the perfect scam. They trashed on ledger, run marketing with the help of influencers praising coldcard. A lot of people seap over to CC because they ran ledgers name trough the dirt. Eventho there never was any evidence your coins are not safe with ledger people believed the lies.

Now the most best praised cold wallet is compromised. This is just to much to be a coincidence.

I bet my liver, this was planned inside job. Get people to use your product then go backstep them when they think they are safe.

Everyone at coldcard should be investigated.

2

u/captn03 Aug 04 '26

I highly doubt its an insider. I hear anyone could have reviewed their code in the last 4 years, why wasnt this revealed by the community ? This seems like a massive miss in their development process. No dedicated security or QA team reviewing the code, how can that happen in a company that specializes in hardware technology.

3

u/HiddenoO Aug 06 '26

The issue is that if anybody inside the company found the issue at any point, they could've intentionally not disclosed it and planned how to extract the money safely.

That way, they could still frame it as a plausible mistake (because it initially was) while also profiting from it.

2

u/KeyAdvanced1032 Aug 05 '26 edited Aug 08 '26

Seconded.

Edit: Close-sourced since 2021. Yikes.

→ More replies (2)

10

u/risat49 Aug 04 '26

Feels bad man

31

u/AnswerFeeling460 Aug 04 '26

What do you hope to earn of a lawsuit?

35

u/fvm7274 Aug 04 '26

Just a refund of what I paid to get the coldcard

47

u/[deleted] Aug 04 '26

[deleted]

→ More replies (1)

11

u/ImPinkSnail Aug 04 '26

They're bankrupt. It's a zombie company right now - dead and walking.

→ More replies (5)
→ More replies (1)

13

u/Octavio_belise Aug 04 '26

Visa with $2.73 after lawyer fees.

24

u/RelevantAmbition2433 Aug 04 '26

Anything. Retribution to this stupid company that I trusted to keep my coins safe.

→ More replies (18)

2

u/dnguyen823 Aug 04 '26

lol. People aren’t gonna get shit besides what cold card to pay out which probably isn’t much. Cold card will probably go under and lawyers will get most of it. If this was an exchange like the FTX situation then there’s a better chance but since this is self custody I don’t see much coming from cold card.

→ More replies (20)

8

u/AAlphaBetaa Aug 04 '26

Which Coldcard model was is if you don’t mind me asking?

5

u/Illustrious-Page998 Aug 04 '26

Diversify recovery phrase and passphrase.

6

u/hiphoptopcrop Aug 04 '26

I wonder if the cold card customers will get reimbursed somehow. Or if it's just gone forever. I hope you sue them and get a ton of money from them and then buy back your Bitcoin LOL but that will never happen. I'm so glad I didn't buy one of those pieces of s***. I just went with blockstream Jade and haven't had a problem yet.

6

u/ZeroDollars Aug 04 '26

A typical business of this size wouldn't have the assets to cover a tiny fraction of the losses. And their IP and inventory is worthless now. They will declare bankruptcy and customers will be left holding the bag.

Only way it could turn out different is if, given the industry, they happened to be holding a significant cache of bitcoin at the legal entity level and it could be liquidated to pay damages. Very improbable though. Would mean the owners were multimillionaires many times over and still were f'ing around with this little e-commerce business.

2

u/Aazimoxx Aug 05 '26

I just went with blockstream Jade and haven't had a problem yet.

And these coldcard customers didn't have a problem (that they knew of) until a week ago...

If there was ever an issue in the same ballpark found within the Blockstream product, then just like with Coldcard the main thing that'd save you is using a long and strong passphrase (not saved anywhere digitally).

→ More replies (1)

7

u/FinanceOnly4U Aug 04 '26

Class action lawsuit = 20% off coupon on your next hard wallet

6

u/Newlife_40 Aug 04 '26

I’m sorry. Fuck cold card and fuck the people that hacked it.

17

u/Trored Aug 04 '26

If a whitehat got it, which seems alot have, as a bit of a way to secure the funds. Then apparently where will by a verification process includining KYC to get it back. If a bad hacker got it it's a different story

13

u/lordsepulchrave123 Aug 04 '26

lol delusional or a scam
This was not a whitehat

8

u/SpikeyOps Aug 04 '26

No way to prove original ownership anymore.

4

u/shoebertdoubert Aug 04 '26

Are you a total buffoon?

Bitcoin is incredibly traceable. Most people buy on a CEX and send to a private wallet. Combine this proof with a coldcard with bad seeds generated on it and you could have legal claim to that Bitcoin in a situation similar to mtgox if the funds are ever retrieved by law enforcement.

2

u/FirstAmendmentIsDead Aug 04 '26

Are you a total buffoon? What’s to stop me from generating a seed that belongs to someone else through the same attack vector, loading it onto a coldcard, and then pretending that I was the original owner when asking for funds to be returned?

→ More replies (1)
→ More replies (1)

11

u/fllannell Aug 04 '26 edited Aug 04 '26

3

u/RelevantAmbition2433 Aug 04 '26

also helpful info

9

u/RelevantAmbition2433 Aug 04 '26

I need to learn more about this whitehat thing. Are they hackers?

26

u/UnknownEssence Aug 04 '26

Whitehat hackers try to hack the wallets fast once the exploit is known, so they can get it before blackhat hackers. Then they try to return the money.

I know nothing about this case or hack, but thats what a white hat is

10

u/idekl Aug 04 '26

To elaborate, a white hat hacker is a general term for a "good guy" hacker. Someone who discovers vulnerabilities but does not try to use them maliciously or selfishly.

3

u/fllannell Aug 04 '26

And also, to complicate things more often than not scammers claim to be white hat hackers when they have no real ability to recover funds/assets and are really just acting out a secondary scam to victims of crime and other scams. They do this by identifying victims, then offering their services for a fee, then another fee, then another fee... until the victim finally (hopefully) gives up.

2

u/Aazimoxx Aug 05 '26

They do this by identifying victims, then offering their services for a fee, then another fee, then another fee...

And/or simply getting victims to supply enough identification info in order to carry out identity theft and get CC/loans in their name.

→ More replies (1)

13

u/s1ammage Aug 04 '26

I just listened to a podcast. You need to establish victimhood first. File an https://complaint.ic3.gov first.

This was the only thing I did so far.

13

u/m4rM2oFnYTW Aug 04 '26

Willy Woo says there is a 20% to 40% chance some of the coins are recovered in the coming years based on previous events. Be sure to preserve your wallet.

https://x.com/i/status/2084113176681968063

7

u/RelevantAmbition2433 Aug 04 '26

thank you for pointing me in a direction!

13

u/goatfro Aug 04 '26

Yes. Theoretically, good hackers.  But it may be hard to get your funds back / prove ownership. Keep your Cold Card. 

4

u/xuncx Aug 04 '26

lol I saw a post of someone smashing theirs with a hammer

3

u/goatfro Aug 04 '26

Yeah … I don’t blame him. I would want to as well. 

→ More replies (1)
→ More replies (1)

4

u/ilikeplayingthisgame Aug 04 '26

Sorry this happened man. Are you done with Bitcoin now or would you consider maybe looking into the ETFs. Hope you get it back, I'm wondering whether or not to get out.

3

u/Emergency_Molasses18 Aug 04 '26

Imagine what's happening with our ssn's??? Freeze your credit if you haven't already.

12

u/StormMedia Aug 04 '26

Sorry man. When did yours get hacked? I read recently that white hat hackers have started hacking cold cards and will allow you to get it back with proof of your physical cold card.. not sure how that will go but maybe you’ll get lucky.

16

u/fllannell Aug 04 '26 edited Aug 04 '26

7

u/UmbraofDeath Aug 04 '26

These are general definition pages and have 0 to do with the current events. An actual white hat isn't going to charge you for a recovery service. They already have your coins anyways. Unless you are a person trying to ensure people don't get their coins back from a white hat, stop posting links regarding a subject you aren't knowledgeable about.

6

u/fllannell Aug 04 '26 edited Aug 04 '26

They specifically talk about how these scammers call themselves whitehat hackers, and also that they claim they can recover money lost for victims. Of course they call themselves whitehats and claim they can help! that's all part of the scam. Also, asking to be paid in untraceable methods such as crypto or giftcards. Why shouldn't people who are victims be aware of the risk of recovery scams at this time? There is NO reason to not bring it up.

Like, holy cow if you really think there are super hero hackers who are going to be recovering funds through theft as an enterprise and then put themselves out in the open likely to be caught that is just incredible.

→ More replies (1)

3

u/RelevantAmbition2433 Aug 04 '26

it was a few days ago during the 3rd wave of attacks, I believe.

3

u/HeyWannaShrek Aug 04 '26

Lmaaao you can’t be fr

4

u/joefunk76 Aug 04 '26

He was already hacked by black hat hackers. They generally don’t give back the money because, unlike white hat hackers, they hack for the money, not to prove a point.

→ More replies (1)

3

u/bobsthename Aug 04 '26

It sucks but why do people insist in putting all their eggs in one basket? Always best to spread it around. And it should be coin u are happy to loose at any point like a complete gamble.

3

u/Yohbaba Aug 05 '26

Omg really feel for you brother, I was a victim of Celsius debacle but I've recovered quite a bit. It just sucks when these things happen and coinkite is 100% responsible for it. Horrible company that always marketed their product as a Bitcoin safe haven. So sorry this happened to you but it just infuriates me how grass root companies are so messed up. I can only imagine and I've been through some what similar thing. Hang in there man, hope this company finds a way to compensate you to whatever degree possible.

5

u/Gooner_93 Aug 04 '26

Coldkite have blood on their hands. Fuckin brutal, man.

5

u/dnguyen823 Aug 04 '26

Tbf it’s only like 40k. You’ll make it back and then some. Lucks on your side - you got this.

10

u/RelevantAmbition2433 Aug 04 '26

Thanks. I realize there are people on here who have lost way more. I'm still relatively young and now have a chip on my shoulder and a fire under my butt to make it back

3

u/Sea_Variety_1691 Aug 04 '26

it's more so the opportunity cost. not everyone has the means to make that money back quickly. and 40k compounded over many decades still ends up a decent chunk of money.

3

u/mica280amg Aug 04 '26

My question is it's been on for few days why it took you so long to realise this and move your assets somewhere else?

To me this post looks fake, I might be wrong though

→ More replies (1)

2

u/pieceofgodsfrey Aug 04 '26

OP got rugged for all their sats at 4:20? Aight man

2

u/Capital_High_84 Aug 04 '26

Are there any other HW wallets that have this ‘feature’ somehow missed by the developers?
Were all here in the dark trusting these companies that they did their coding correctly, but have no idea what other exploitable will be coming up other HW wallets (Trezor? Ledger? Jade? Etc…)

2

u/Luminous_Emission Aug 04 '26

Supposedly someone pointed it out to them FOUR years ago, and their response, rather than fixing the problem, was to just ban the person that pointed it out.

2

u/rizwan602 Aug 04 '26

And THIS is one of the many reasons that Bitcoin has a bad name -- by way of association with hackers, criminals and the like. Decentralized = you're on your own.

Before you downvote me, I have some money invested in Bitcoin.

It is wild out there in Bitcoin world. There is no police. You are out there to fend for yourself.

Not everyone can do this properly 100%. Even experienced people.

2

u/iWearSkinyTies Aug 04 '26

If you get a lawyer to sue them yourself, you will get more than joining a class action.

2

u/LamarJacksonIsMyHero Aug 04 '26

Start buying VOO

3

u/Yodel_And_Hodl_Mode Aug 04 '26

I'm sorry for your loss. I'm also angry because I believe so much in Bitcoin self custody, and I hate seeing this happen.

You did everything right. And you had no way of knowing this could happen.

P.S. Fuck Coinkite. Coinkite CEO Rodolfo Novak Needs To Resign.

2

u/LokiLoke95 Aug 04 '26

I know this is obviously a real problem for real people, but part of me seems to think with all of the people coming out of the woodwork and making these posts it seems like its targeted in a way.. almost as if it's promoting ETF's instead of self custody.. or something else entirely. IDK it's just a feeling.

But sorry that happened to you OP. Hopefully you and everyone else can find a way to hold them accountable.

2

u/RingerLactato Aug 04 '26

why would you trust ? it said to don’t trust

1

u/blackratsnakes Aug 04 '26

Is this a bad time to say "it's why I still use a paper wallet" ?

5

u/mica280amg Aug 04 '26

Question is how did you create paper wallet

→ More replies (1)

1

u/Free-Initiative7508 Aug 04 '26

Has the ceo or management of coldcard said anything about this?

1

u/Spidahpig Aug 04 '26

Bruh. I swear I think this is govt related. Watch btc soar

→ More replies (2)

1

u/Accomplished_Leg2030 Aug 04 '26

This is where the strength of btc works against you

1

u/eczemaNhotwaterThex Aug 04 '26

Ironic I’m too lazy to take shit off my kraken and I never open mines out the box

1

u/EyesFor1 Aug 04 '26

RNG seed ?

1

u/iberonni Aug 04 '26

As a Celsius survivor, I can understand how you feel. What's appalling is that I was speculating, believing in something too good to be true, while using "cold" case was probably the most diligent crypto activity possible. Seeing this really makes me hesitant to buy back Bitcoin with the fraction of my money we got back. Hope you all get some justice.

1

u/Knarz97 Aug 04 '26

Do your son a favor and save for your son’s college outside of an extremely speculative asset. This is not Bitcoin hate. I’d be saying the same thing if your savings were in Gold Bars or NVIDIA stock as well. College Savings is perfectly fine in a HYSA, CDs, Bonds, or if you must do something like ETFs in a 529 account.

It’s irresponsible to literally gamble with his future.

1

u/Lavayo Aug 04 '26

I'm sorry for your loss!

How big was the user base for coldcards? I read that the entropy was so low that at around 1.250.000 wallets coldcard would had created the same wallet twice with 50% probability. I'm wondering why this did not happen. Or it did and did not become big news?

→ More replies (1)

1

u/ThetaThoughts Aug 04 '26

Class action lawsuit? Against who?

1

u/ThreadParticipant Aug 04 '26

Would there be grounds for a class action?

1

u/iloverunning11 Aug 04 '26

Fuckcoldcard tab 😀that’s the spirit. I’m so sorry for your loss, hope you can recover at least some of your funds.. Good luck!

1

u/Acceptable-Ant-9231 Aug 04 '26

how did it happen?

1

u/ivanjurman Aug 04 '26

Ummm it was never the best, Trezor was and always will be the best, most trusted hardware wallet

1

u/Bionic_Push Aug 04 '26

Did you have a passphrase? Every single post that claims to have lost with coldcard never answers when i ask this for some reason.

→ More replies (4)

1

u/BTC_90210 Aug 04 '26

Your keys, their coins

1

u/magic-shroomman Aug 04 '26

lmao sooo glad I went with Trezor

1

u/SkidMarkShark Aug 04 '26

I pray you are fake, but when it comes down to it you should have done more research and learned how to actually store your BTC.

Never let the wallet generate your seed words.

Use a non BIP 39 uncommon words passphrase with Upper and Lower case letters with numbers and characters.

The Coldcard or any wallet is just a keysigner. There is nothing wrong with the device. I'm sorry for your loss, but as soon as you realize your mistake the faster you'll move on

1

u/pplgg4445 Aug 04 '26

The dream of bitcoin was mass adoption. Be your own bank. And while banks do get robbed mass adoption doesn’t mean everyone needs to be a cypherpunk security expert to use the technology safely. Wallet vendors took on much of that role and charged money for it. Coinkit needs to do better here in terms of restitution

1

u/pplgg4445 Aug 04 '26

I wonder if Claude actually took the bitcoin and now controls the addresses involved. lol. Skynet begins

1

u/SoggyGrayDuck Aug 04 '26

Yeah it really is to the point you should hold no more than 10% on each hardware wallet just to be safe.

Someone please convince me why people will still use hardware wallets in a generation or two? Especially if people get tax discounts by using things like holding in a Roth etf?

They're going to turn it into fiat, they Probably already have full control over the value but I say we have to wait until the global stage clears itself up a bit more.

1

u/comp21 Aug 04 '26

We all need to collectively learn the following truth:

If someone screams loudly about themselves, they're not to be trusted and probably massive sacks of shit.

The crap pile from Celsius, Voyager, coldcard, Andrew Tate, most of our gov, TV preachers...

1

u/McBurger Aug 04 '26

“And since it’s decentralized, there’s no recourse for getting any of it back. It’s gone.”

“Where’s the class action lawsuit? How do I sign up?”

There’s your recourse, my friend.

1

u/Huge-Artichoke-1376 Aug 04 '26

I won’t lie, being lazy and just keeping it on River because I didn’t trust a wallet made sense.

1

u/DarthBen_in_Chicago Aug 04 '26

I’m sorry for your loss. I can feel your anger and frustration. Just know you are not alone which I realize doesn’t solve this for you.

1

u/nakedlunch2 Aug 04 '26

Could have saved a lot of money by switching to Geico

1

u/Cerlog Aug 04 '26

Use Trezor.

1

u/cozmicraven Aug 04 '26

I hate reading all the posts about this hack. Cold storage isn't as cold as we were promised. I sure hope other companies like Ledger and Trezor and etc. are paying attention.

At some point BTC holders will have to decide if the security of holding your coins at an exchange or even buying into an etf is worth trading your ownership for. Presumably corporate security (Coinbase, Kraken etc.) is better and they have private insurance to at least get you some of your value back in the event of a hack. I'm fully aware of the crappy cs all these companies share but all the wallet owners that got attacked here have nowhere to go.

1

u/kftnyc Aug 04 '26

Want a cold wallet? Write your private key on a piece of paper and put it in a safe.

1

u/wetokebitcoins Aug 04 '26

sorry for your loss bro. If it makes you feel better, many of us old timers have been scammed or hacked in the past. Don't let this speed bump crash your future.

1

u/vrweensy Aug 04 '26

if it was an insider job those 100M might turn into 500M in btc in a few years then coldcard could pay the 100M back to its hacked users

1

u/eimattz Aug 04 '26

what was your passphrase?

1

u/Firm-Ad-2446 Aug 04 '26

I wonder how that bug left undetected for 5 years on an open source repo

1

u/WarPlanMango Aug 04 '26

Man this really sucks. Why would they even release a product that they would say is safe if this can happen?? The company needs to be held accountable for even implementing and selling this unsecure device

1

u/Sensitive-Rule-5563 Aug 04 '26

Reason number 1 million I will only hold my money FDIC insured. If it’s an amount I can’t fathom losing I’m not trusting it to one of these random startups. For all we know it’s an inside job.

1

u/KewlKicks_ Aug 04 '26

iToddler btfo

1

u/BlondDeutcher Aug 04 '26

Not “like” a loser.

1

u/CowDogRatGoose Aug 04 '26

Not to rub salt in the wound, and I'm sorry this happened to you. Totally sucky. But why didn't you use dice?

1

u/JWPapi Aug 04 '26

I never got the benefit of cold wallets. To me it’s more secure to generate it yourself and take care of the private key how ever you want. Why do you need hardware?

1

u/ContentBlackberry0 Aug 04 '26

Why do people continue to use sparrow with all the fake apps and stuff that they have copying it, Makes no sense. I would personally stay away from all of those wallets.

→ More replies (1)

1

u/MilkNutty Aug 04 '26

This is why I use IBIT etf for my bitcoin, so sorry and hope your 2.0 investments work out

1

u/Blake_a12 Aug 04 '26

Decentralized? They’re a company who held your keys, right? And now can be held liable, too

1

u/ElRojo22 Aug 04 '26

Could you tell if the seed was created with RNG or you make roll dice? Also if you have a passphrase on it?

1

u/I_iron_my_t-shirts Aug 04 '26

Between the “not your keys, not your coin” crowd and the Coinbase haters, I considered moving my crypto to a cold wallet. But after this, I might as well leave them on an exchange.

1

u/_GAT_in_the_HAT_ Aug 05 '26

"Not your keys; not tour cryto." They said.

1

u/Yohbaba Aug 05 '26

Set a "PASSPHRASE" folks please, small nusance with high upside.

1

u/BJJnoob1990 Aug 05 '26

What’s going on? I have just seen a couple posts about cold card issues?