Dear COLDCARD attackers,
Congratulations. You successfully found a bug, exploited, and have collectively gathered around 1,500 bitcoin.
Now you are sitting on one of the most blacklisted coin stacks in history. It will be nearly impossible for you to exchange for currency or deal with any institution. Every move you make will be highly scrutinized and tracked. Presumably for the rest of your lives, you will be looking over your shoulder.
I suggest you plea with CoinKite to return all stolen funds in return for an audit fee of 5% of the loot. This way your work is rewarded and you are able to enjoy the fruits of your labor.
Respectfully,
hodlers worldwide
This was a Coldcard-specific firmware bug: seed generation called a weak software PRNG instead of the hardware TRNG, cutting entropy to ~40 bits on Mk3 (higher but still reduced on later models).
Other hardware wallets use different designs and code. Ledger relies on a certified TRNG inside its Secure Element for full 256-bit entropy. Trezor mixes multiple independent sources (device hardware + host + secure elements). No shared vulnerable path exists across vendors.
We are committed to pushing the model frontier across cost efficiency, capability, and speed.
Starting today, we are reducing prices for GPT-5.6 Luna by 80% and GPT-5.6 Terra by 20% , and offering a faster option for GPT-5.6 Sol in the API.
Luna and Terra’s lower prices are reflected in how usage is counted in Codex and ChatGPT Work, so your usage goes further.