this is insane
claude code found the COLDCARD wallet vulnerability with a single prompt, in just 8 minutes of thinking
we're not ready for what's coming
Using Bitcoin on a Trezor or any hardware wallet is fine, but storing your trust in that device is not.
I wipe my Trezor device every time I use it. I re-enter my 24 words on my Trezor device every time I need to use it again.
Dear COLDCARD attackers,
Congratulations. You successfully found a bug, exploited, and have collectively gathered around 1,500 bitcoin.
Now you are sitting on one of the most blacklisted coin stacks in history. It will be nearly impossible for you to exchange for currency or deal with any institution. Every move you make will be highly scrutinized and tracked. Presumably for the rest of your lives, you will be looking over your shoulder.
I suggest you plea with CoinKite to return all stolen funds in return for an audit fee of 5% of the loot. This way your work is rewarded and you are able to enjoy the fruits of your labor.
Respectfully,
hodlers worldwide
I'm a software engineer with an MSc in Computer Science and 25+ years in the industry. Here's why Coinkite's Coldcard bug isn't an oopsy, it's disqualifying.
Coldcard's seed generation silently fell back to a non-cryptographic "random" number generator for 5 years. Not because crypto is hard, but because Coinkite violated the most basic rule of secure system design: fail closed, never open. When a security-critical path can't be verified, the system refuses to run and throws an error.
It does not quietly substitute something weaker and carry on. This code should have refused to produce a seed. Instead it produced a predictable one and continue silently. ☠️
A company that lets its most critical code path go unverified for half a decade cannot be trusted with your keys.
Throw away your Coldcards. Never buy one again.
🔥CZ: "Even hardware wallets can have bugs."
The Binance founder is urging holders to split funds across multiple wallets after the $70 MILLION Coldcard exploit.
"Nothing is 100%. Stay informed. Stay SAFU."
This is sad!
You may or may not know, @TrustWallet faced this exact same bug years ago, a pseudo-random number generator, ie, not truly random, $12m in losses. They covered every user.
Software will always have bugs. What matters is who’s behind it.
The thing is, with self custody, devs patching the bug won't fix previously generated wallets. And devs have no way to reach users on air-gapped devices. Your wallet stays open to hackers until you act.
I'm a believer in self custody, but it puts the burden on you.
🚨BREAKING:
“TRUMP INSIDER” WITH A 100% WIN RATE JUST OPENED A $30.6M $BTC SHORT AND $29.5M $ETH SHORT
HE IS BETTING AGAINST THE ENTIRE CRYPTO MARKET
HE DEFINITELY KNOWS SOMETHING