🚨 I lost what almost anyone would call a ton of bitcoin to this very sad event, so trust me. I'm in no mood to be generous.
But, "Throw away your Coldcards" now, may not be great engineering at this point. The current firmware has the fail-closed guard that many other devices in the industry still don't have.
A Mk4 on 5.6.0, the new upgraded firmware, is now more scrutinized than any competitor's device — every serious researcher spent this week reading that codebase. Discarding it for an unaudited alternative may not be the upgrade you think it is.
The answer is structural: multi-vendor multisig. One vendor being wrong should cost you one key.
Rotating to a different single vendor just moves the bet.
My remaining 2 Sats.
Coldcard issue, explained simply
Imagine every possible 24-word seed phrase in a giant bag. How many are in there? So many that the number of possibilities is 78 digits long. For comparison, a billion has only 10 digits, and a trillion has 13. It’s effectively impossible to guess which seed phrase you pulled out.
Coldcard hardware generated seed phrases from a much smaller bag of possibilities—a bag so small that attackers are currently guessing their way through it. We expect the entire bag to be searched in the coming days.
If you generated your seed phrase on a Coldcard, move your funds as soon as possible.
Keep it simple: move them somewhere you’re already familiar with, such as another hardware wallet or an exchange you already trust.
There is now no painless route back to affordable housing in Australia. Either house prices must stagnate for a decade or more while wages catch up, prices must fall substantially, or Australia must produce far more housing while restraining the credit, spending and population pressures that continually push demand ahead of supply. Under the present settings, governments are only managing the affordability crisis, they certainly aren’t reversing it.
1960 ████ 4.2
1970 ████ 3.8
1980 ███ 3.2
1990 ████ 3.6
2000 ████ 3.7
2010 ██████ 5.8
2020 ███████ 6.8
2026 ███████████ 11.2
Thanks to a generous credit of tokens from @PPQdotAI , Kimi K3 and an ape with a laptop (me) have conducted the following analysis of a bunch of projects / companies wallet softwares. @Coinkite , @OPENDIME , @SeedSigner , @Bitkey , @bluewalletio , @PhoenixWallet , @SparrowWallet , @Trezor , @Blockstream , @Ledger , @BitBoxSwiss , @SpecterDIY , @ElectrumWallet , @SamouraiWallet
🟡 Yellow ≠ broken. None of the nine Yellow products has a confirmed fund-loss-by-default flaw. Yellow means at least one of: (a) something security-critical sits outside independent verification. i.e., closed firmware or secure-element code (Opendime, Ledger, open source please!), vendor-run recovery infrastructure (Phoenix/ACINQ, Jade's oracle, Bitkey's WSM); (b) a real but bounded weakness, such as a zero-work-factor KDF (BlueWallet), weak legacy KDFs on a hot wallet (Electrum), no-SE DIY hardware with thin maintenance (SpecterDIY), a just-patched vulnerability awaiting its report (Bitkey); or (c) a dead/unmaintained product whose crypto reviewed clean (free Samourai!). In every case the entropy/key-generation path itself was reviewed and found sound unless the cell says otherwise.
1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
The COLDCARD RNG vulnerability may be worse than an exchange hack. It hit at the core of sovereign Bitcoin holders - it struck those who did all the research, understood why self-custody is important, and didn’t keep coins on exchanges.
My heart goes out to everyone affected. It’s a horrible situation and the damage is irreparable. While I have many thoughts and criticisms about how we got here, I’ll hold back because I know nvk is devastated too.
Self-custody is hard. If you advocate for self-custody, you should also be telling people to use a multi-vendor multisig setup. I’ve been saying this for years. Self-custody only works if you do it in a way that minimizes a single point of failure. Don’t trust any single vendor for hardware. Assume everyone is your adversary.
As self-custody is hard, we should be less critical of people who chose to use custodians or hold BTC in ETFs or Bitcoin Treasury Companies. There isn’t a single right or wrong way to use Bitcoin and there are tradeoffs everywhere.
Some people have contacted me about what to do. Here’s what I recommend:
1️⃣ Document everything. Write down all the facts and details you know (dates, addresses, firmware, etc.).
2️⃣ File a police report, as it creates an official record which is useful for a number of reasons. Even better if you can contact a cybercrime unit, national reporting portals (e.g., FBI IC3 in the US), or specialized crypto-crime task forces if they exist.
3️⃣ Watch for coordinated efforts to track movements of funds.
4️⃣ Do not destroy your COLDCARD and seed phrase. Hold onto them as there could be a chance that stolen funds reach an exchange, are frozen, and you need to prove ownership. Write down your PIN too, or note it in your documentation. When you stop using it for a long time, you may forget it.
5️⃣ This next point is very important: DO NOT share your personal details, seed phrase, or send any money to anyone claiming they can “help recover” the funds. Scammers will be targeting people who are desperate.
Just know that almost everyone has lost coins for some reason at some point. Don’t do anything rash. Talk to someone if you need to. You can always rebuild, but only if you’re still here.
For all of us developing wallets, software or hardware, security is the most important thing we provide. People are counting on us and we have to do better.
💔
@jimmysong This looks like a pretty simple system but those 16 sided hex dice aren't common. Where do you get them? There's no link for them in the simplestbitcoinbook slides.
Just woke up to this Coldcard shitshow. It's unbelievable.
The people affected by this have done everything right - studied Bitcoin, took the right precautions, separated their money from the state, invested in a hardware wallet & now wake up to the reality that their life savings have gone.
That's just sickening. I feel really sorry for those affected.
This is also another win for 'Big Bitcoin'.
This is a story that'll be referred to for multiple cycles. New Bitcoiners will hear stories of lost funds from the likes of Ledger & Coldcard and think "I'm safer to just buy IBIT".
This is hugely damaging to the people who believe that 8 billion people will hold their Bitcoin in cold storage in the future.
That dream is over. Done.
Will Coldcard be reimbursing the stolen funds to the victims of the theft?
An apology & online statements ain't going to cut it.
I hope this means multisig with multiple hardware vendors becomes more popular. N-of-n additive security ftw.
Also if you're going to use dice get two 16-sided dice and 1 8-sided die.
The Coldcard bug explained in simple terms:
Normally, a hardware wallet generates your 12 word seed phrase using true randomness.
Think of it like a lottery with roughly 340 undecillion possible tickets (that’s a 340 followed by 36 zeros). Every ticket has an equal chance of being picked, making the odds of guessing your seed essentially zero.
The bug didn’t shorten the 2,048-word BIP-39 word list. It changed how the wallet picked the words.
Instead of choosing from the entire lottery, the wallet kept picking from the same tiny corner because the “random” numbers were partially predictable from things like the device’s ID and timing.
Imagine that instead of 340 undecillion possible combinations, your wallet accidentally chose from only a few billion. That’s still a huge number, but astronomically smaller than what Bitcoin’s security is designed to provide.
Your seed phrase still looked completely normal. The words came from the same 2,048-word list. Nothing looked suspicious.
But for an attacker, the search space became millions of trillions of trillions of times smaller.
I hope this means multisig with multiple hardware vendors becomes more popular. N-of-n additive security ftw.
Also if you're going to use dice get two 16-sided dice and 1 8-sided die.
I've been watching this BIP-110 debate and I think people are getting way too wrapped up in picking a side and not enough in appreciating what we're actually watching.
Bitcoin doesn't have a CEO who gets to settle this. There isn't a board meeting where somebody takes a vote and sends out the new rules Monday morning.
People are going to disagree. Developers will write code, miners will make decisions, node operators will decide what they're willing to run, and the economic network will ultimately decide what Bitcoin it values.
That's not Bitcoin failing, that is this entire experiment working.
What concerns me most is watching people become so convinced that they're "protecting Bitcoin" that they start believing everyone else should be forced to accept their version of it. That's where I think we've lost the plot.
I don't know exactly how BIP-110 plays out, and neither does anyone else. Maybe it gains support. Maybe it goes nowhere. Maybe we get some ugly disagreement along the way.
Good.
Bitcoin was never supposed to protect us from disagreement. It was supposed to remove the need for someone with authority to settle it for us.
Run your node. Understand the rules you're choosing. Make your decision.
Then we'll find out where consensus actually lives.
That's Bitcoin to me.
I love this question, and how you framed it. Thanks for the nice words, buddy.
I've been busy today but getting round to this now.
So. First off, I actually think BIP-110 will get adopted. The BIP is really pretty cool. For instance. I think all soft forks in the future should use this scenario:
Temporary. 55% support for miner activation threshold because the mining side is captured and concentrated in 6 players. Smart.
And the BIP is simple in just a few lines of code, easy to understand, and the author flexible to criticism with changes incorporated as it progressed.
Restores OP_RETURN to where it was for the majority of the last decade. Who would argue about that?
Limits script. Again, doesn't affect multi sig (less than 7 levels I believe), Lightning... in fact in onchain analysis, it didn't affect any actual transactions.
Removes OP_IF. Do you know that 99% of ALL data at the end of OP_IF is now a JPEG. Who really cares if it is removed?
Everything is grandfathered in. Smart move.
Says up front in the BIP, "You can't stop spam." But accurately makes a case for creating more friction and cost to spam.
In fact, some critics will point to "ready" software from all the spammers to implement as soon as it passes. But they don't tell you that the new protocols are less effecient, and more costly.
The actual soft fork movement makes apparent to spammers/scammers that most Bitcoiners want Bitcoin to be money. Good. Basically, "You are not welcome here."
The Bitcoin protocol itself supports and was built to incorporate grass root efforts like you are seeing. Just like it also strengthens the network when the day comes from a malicious soft fork proposal. More nodes. More Bitcoin psychopaths who will form a URSF.
And look who is opposing this? Do we really want influencers and developers who have scammed/spammed plebs using NFT's, ordinals, and shitcoins to have a voice in this? Will you follow them?
Do you think the actors in this consortum really will put Bitcoin's future before their own incentives and agendas?
Now, to the last part.
If you follow me, please listen. When the activation block is mined, do not move any Bitcoin onchain for 48-72 hours. Let's see how this works out.
Because I really don't know. I will tell you that I personally do not have my panties in a wad. I'm pretty relaxed. I'll keep running BIP-110 regardless of the outcome for some time. But at some point I will indeed be able to see if BIP-110 was successful in activation.
This movement is a net positive in so many ways. I wish more people would see it that way.
And I hope that more people will understand that many voices in this Bitcoin community are compromised. And conflicted. And not to be trusted.
I love you, Dylan. Always will.