\
  The most prestigious law school admissions discussion board in the world.
BackRefresh Options Favorite

'Coldcard' Bitcoin wallets turned out to be a scam; BTC drained from users:

lol @ putting your faith in 'hardware' wallets: https://c...
,.,..,.,..,.,.,.,..,.,.,,..,..,.,,..,.,,.
  08/01/26
Claude discovered the vulnerability after thinking about it ...
in minecraft
  08/02/26
...
Kenneth Play
  08/02/26
you think this will happen to bank accounts anytime soon?
Kenneth Play
  08/02/26
The whole point of crypto is super fast movement of money wi...
Roblox
  08/02/26
but but but my DeFi! he lisped
Long PlayroomPoon Clown Conniption
  08/03/26
banks can unilaterally freeze or revert transactions, so, it...
,.,..,.,..,.,.,.,..,.,.,,..,..,.,,..,.,,.
  08/02/26


Poast new message in this thread



Reply Favorite

Date: August 1st, 2026 7:46 PM
Author: ,.,..,.,..,.,.,.,..,.,.,,..,..,.,,..,.,,.


lol @ putting your faith in 'hardware' wallets:

https://cryptobriefing.com/galaxy-research-coldcard-btc-attack-1367/

Galaxy Research identifies 1,367 BTC drained in attacks on Coldcard addresses

Hardware wallets are supposed to be the vault, not the vulnerability. But a newly uncovered firmware defect in Coldcard Mk3 devices has flipped that assumption, with Galaxy Research confirming that 1,367.05 BTC, worth roughly $88.6M, was drained across three coordinated attack waves targeting 4,585 affected addresses.

The scale of the theft is jarring. Earlier estimates had pegged losses at around 594 BTC from approximately 500 addresses. Galaxy’s on-chain analysis more than doubled that figure, revealing a much broader and more methodical assault than initially understood.

What happened, and how fast

The largest single wave hit on July 30, 2026, and it was efficient in the worst possible way. Attackers swept 1,082.65 BTC, roughly $70.2M, in just 4 minutes.

Galaxy’s analysis found that the first two waves shared nearly identical transaction fingerprints, specifically hardcoded fees of 30 sat/vB and the same batching patterns. That level of consistency suggests a single operator, or at minimum a single toolkit. The third wave broke from that pattern, pointing to either a different actor or a deliberate tactical shift.

The stolen funds have largely stayed put. The BTC has not been significantly moved since the thefts, sitting in a small number of attacker-controlled addresses.

The root cause: predictable randomness

The flaw in Coldcard Mk3 firmware, present in versions 4.0.1 and later, introduced in March 2021, caused the device’s random number generator to produce weak, predictable outputs. The seeds it created were not actually random, which meant an attacker with enough computing power could enumerate possible seeds offline and match them to real addresses on the blockchain, sweeping funds from single-signature addresses without ever needing physical access to the device.

Block’s engineering team is credited with first surfacing the RNG issue publicly. Coinkite, the company behind Coldcard, issued an advisory approximately 30 hours after the initial sweeps began.

Coldcard Mk4, Q, and Mk5 devices do not appear to be affected by the same flaw. Users holding funds on compromised Mk3 wallets are being urged to generate entirely new seeds on those newer models rather than simply transferring balances within the same hardware generation.

What this means for hardware wallet security and investors

The fee behavior in the attacks is also worth noting. The hardcoded 30 sat/vB rate used in the first two waves was between 30 and 75 times the median fee at the time, according to Galaxy’s findings. Attackers were clearly willing to pay a premium to ensure rapid confirmation.

For active Bitcoin holders, the immediate question is exposure. Anyone using a Coldcard Mk3 device running firmware from version 4.0.1 onward should treat their current seed as potentially compromised and migrate funds to a freshly generated wallet on unaffected hardware. Checking firmware version history and cross-referencing with Coinkite’s advisory is the first practical step.

(http://www.autoadmit.com/thread.php?thread_id=5888518&forum_id=2],#50039820)



Reply Favorite

Date: August 2nd, 2026 9:08 PM
Author: in minecraft

Claude discovered the vulnerability after thinking about it for 8 minutes:

https://i.4cdn.org/biz/1785704474691984.jpg

(http://www.autoadmit.com/thread.php?thread_id=5888518&forum_id=2],#50041736)



Reply Favorite

Date: August 2nd, 2026 9:13 PM
Author: Kenneth Play (emotional girth)



(http://www.autoadmit.com/thread.php?thread_id=5888518&forum_id=2],#50041738)



Reply Favorite

Date: August 2nd, 2026 9:13 PM
Author: Kenneth Play (emotional girth)

you think this will happen to bank accounts anytime soon?

(http://www.autoadmit.com/thread.php?thread_id=5888518&forum_id=2],#50041739)



Reply Favorite

Date: August 2nd, 2026 9:16 PM
Author: Roblox

The whole point of crypto is super fast movement of money without any checks. So these guys got just that.

Banks have checks before you can move money. Traditional financial systems are definitely slower and deliberate.

(http://www.autoadmit.com/thread.php?thread_id=5888518&forum_id=2],#50041740)



Reply Favorite

Date: August 3rd, 2026 5:37 AM
Author: Long PlayroomPoon Clown Conniption ( )

but but but my DeFi! he lisped

(http://www.autoadmit.com/thread.php?thread_id=5888518&forum_id=2],#50042085)



Reply Favorite

Date: August 2nd, 2026 9:17 PM
Author: ,.,..,.,..,.,.,.,..,.,.,,..,..,.,,..,.,,.


banks can unilaterally freeze or revert transactions, so, it wouldn't be done in the same way.

(http://www.autoadmit.com/thread.php?thread_id=5888518&forum_id=2],#50041743)