Live data from Hacker News

The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

medium.com

31–40 of 44 posts

Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

#31
post #9

There's still some small part of me hoping that the later waves are whitehats and the reason they're keeping everything in segmented addresses is because they hope to find a way to return the funds.

how would the original owner prove ownership of the original wallet?

The STM32 in the ColdCard has a 96-bit UID "fused" at the factory. The lower 32 bits of this are seeded into the Yasmarang PRNG's initial state. Possession of a ColdCard with a UID matching a contested wallet might be able to serve as evidence of ownership.

Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

#32

Earlier quoted context omitted.

how would the original owner prove ownership of the original wallet?

Don't know much about bitcoin, but if they know which numerical wallet it came from, can't send it back even if they don't know the person who owned it or communicating with that owner? Like if I woke up one morning and found money in my bank account that wasn't supposed to be there, I could just tell the bank to send it back where it came from.

The underlying issue here is that addresses created by the tool at fault can have their private key derived from public data. If you send it back, it'll just get stolen again. Furthermore, the typical way that someone proves ownership of an address is by making a transaction from that address with parameters set via private communication with someone else. But since the private key is knowable, anyone can do that. There's no generic way to prove ownership of an address if the private key associated with that address can be determined by an attacker.

Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

#33
post #7

This is the best technical analysis I have seen, so far. https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt It doesn't appear that Coinkite, the company behind ColdCard products, had a mature senior engineer in the loop. At least, no engineer who could immediately flag such sloppy code commit practices. This sort of thing is ongoing, as we can see in commits made this week, even. Clearly seems like a corpor…

I disagree with the underlying cause claimed in that analysis: https://news.ycombinator.com/item?id=49141886

Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

#34
post #20
post #3

The Bitcoin communities seem to really be struggling with this hack. The people losing their coins in this case were following best practices. Typically when someone loses their coins there’s a big pile-on to victim blame them for making some mistake. I think it’s comforting to others to be able to identify a mistake someone else made and then convince yourself that you’re too smart to make the same mistake. In this…

5% of btc users use a hardware wallet and Cardkite wasn't even in the top 5 MFGs as far as i'm aware. also as far as I care the btc community members who chose to go with one of the few hardware wallets that wasn't open source were not doing due their diligence. >My guess is that the next phase is to revise history and form a consensus that Coldcard was never a recommended wallet and that it was obvious to everyone w…

> but to be clear, it's nowhere near a revision.

That’s how the retroactive victim blaming always works: It is retroactively determined that there were signs, which turns into victim blaming anyone who didn’t predict that those signs would lead to loss of their coins.

You are doing it.

> also as far as I care the btc community members who chose to go with one of the few hardware wallets that wasn't open source were not doing due their diligence.

I can’t tell if you’re confused about the details of this story or if you’re trying to make a point that isn’t landing. You may want to read up on the open source status of the wallet before doing the whole victim blaming song and dance.

Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

#35
post #20
post #3

The Bitcoin communities seem to really be struggling with this hack. The people losing their coins in this case were following best practices. Typically when someone loses their coins there’s a big pile-on to victim blame them for making some mistake. I think it’s comforting to others to be able to identify a mistake someone else made and then convince yourself that you’re too smart to make the same mistake. In this…

5% of btc users use a hardware wallet and Cardkite wasn't even in the top 5 MFGs as far as i'm aware. also as far as I care the btc community members who chose to go with one of the few hardware wallets that wasn't open source were not doing due their diligence. >My guess is that the next phase is to revise history and form a consensus that Coldcard was never a recommended wallet and that it was obvious to everyone w…

Cold wallet was definitely recommended late 2025, along with the meme of using dice to generate the entropy. Ledger wasn't recommended by coldcard definitely was

Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

#36
post #3

The Bitcoin communities seem to really be struggling with this hack. The people losing their coins in this case were following best practices. Typically when someone loses their coins there’s a big pile-on to victim blame them for making some mistake. I think it’s comforting to others to be able to identify a mistake someone else made and then convince yourself that you’re too smart to make the same mistake. In this…

> In this case, there isn’t much of a mistake to point out. I don’t buy this. There is no $249 device that I would trust with even 1 BTC. These folks looked at the options to preserve $100,000 and picked a $249 device over an exchange. Or a bank. Or the DOW. It is heartbreaking the loss that some have suffered. But it doesn’t benefit anyone to say “Who could have known?” Everyone knew: because not one person said “I…

> I don’t buy this. There is no $249 device that I would trust with even 1 BTC. These folks looked at the options to preserve $100,000 and picked a $249 device over an exchange. Or a bank. Or the DOW.

Bitcoin communities have been advocating for hardware wallets over exchanges for a long time. The phrase goes “not your wallet, not your coins”

Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

#37

Earlier quoted context omitted.

> In this case, there isn’t much of a mistake to point out. I don’t buy this. There is no $249 device that I would trust with even 1 BTC. These folks looked at the options to preserve $100,000 and picked a $249 device over an exchange. Or a bank. Or the DOW. It is heartbreaking the loss that some have suffered. But it doesn’t benefit anyone to say “Who could have known?” Everyone knew: because not one person said “I…

> I don’t buy this. There is no $249 device that I would trust with even 1 BTC. These folks looked at the options to preserve $100,000 and picked a $249 device over an exchange. Or a bank. Or the DOW. Bitcoin communities have been advocating for hardware wallets over exchanges for a long time. The phrase goes “not your wallet, not your coins”

Yeah. It’s propaganda. It ought to be “Not your code? Not hardware you designed and built? Not your coins.” But then like ten people could safely own BTC. BTC is a criminal conspiracy that requires fools for legitimacy.

Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

#38
post #35
post #20

Earlier quoted context omitted.

5% of btc users use a hardware wallet and Cardkite wasn't even in the top 5 MFGs as far as i'm aware. also as far as I care the btc community members who chose to go with one of the few hardware wallets that wasn't open source were not doing due their diligence. >My guess is that the next phase is to revise history and form a consensus that Coldcard was never a recommended wallet and that it was obvious to everyone w…

Cold wallet was definitely recommended late 2025, along with the meme of using dice to generate the entropy. Ledger wasn't recommended by coldcard definitely was

At least my dice don’t boot up with insufficient entropy

Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

#39
post #35

Earlier quoted context omitted.

Cold wallet was definitely recommended late 2025, along with the meme of using dice to generate the entropy. Ledger wasn't recommended by coldcard definitely was

At least my dice don’t boot up with insufficient entropy

Did the dice method prevent this attack? I only skimmed about it being that the seed was mistakenly using 40 bits of entropy but I don't know at which point of the generation the bug was.

Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

#40

> but the fact that there are three waves in the attack shows the level of coordination and pre-planning that was involved in making it happen. That's a strange interpretation. If it was planned well, why weren't all affected addresses drained as quickly as possible? I would have continuously emptied all vulnerable addresses, from highest to lowest without taking a break in the middle. > Instead of picking the lowest…

More likely the higher fees forces through the transaction faster. If it sits around waiting for a miner to pick it up, there's a chance the real owner or competitor could replace-by the transaction with a higher fee and redirect it. Instead of writing that logic, just make sure it gets into the next block before anyone catches on.
Post reply on HN