Update on the 8/1/26 Bitkey bug report. Team and I will be hopping on a spaces here at 5pm PT to talk through our analysis and answer questions from the community. https://t.co/AtTcjEc3jx
So many people stepping up these past couple days. Absolute gigachad VIPs like @Rob1Ham, @PortlandHODL and @w_s_bitcoin.
That is by no means everyone, but I wanted to give these guys props for helping so many people through this insane incident.
Things are moving quickly and I'm reading this report to share more information. Fed it into K3 and linked it to the coldcard firmware and dropped as a markdown file here for those who want to start investigating:
I have not personally peer reviewed all of this, but looking to get more eyes to analyze claims.
Raw dump of markdown file below.
You cannot blame someone for using singlesig when the UX around multisig is so atrocious, especially in the context of non-technical family members having to put all the different puzzle pieces together if you are incapacitated. None of this is well thought out to a degree I'm comfortable with.
I just checked Reddit, people are there telling people that the attackers aren't grinding passphrases.
THESE ARE BAD ACTORS. Passphrases are absolutely being grind! They are just trying to buy time to steal your coins.
if you are setting up a new wallet with a multi sig please understand this
you need to back up not only the seed phrases but also the full wallet descriptor
especially make sure you have all your xpubs (one per seed)
PUBLIC SERVICE ANNOUNCEMENT FOR @lianabitcoin USERS:
(more info coming soon in our complete article, it's taking time to go through every possible case)
If your setup is vulnerable (as in: Coldcard keys are sufficient to spend, no other key is needed to spend)
⚠️ Before transferring your funds, assess the risks. ⚠️
- If you transacted or refreshed in the past and use SEGWIT and ONLY Coldcards in your setup, transfer funds ASAP. Being too late will have your funds stolen, this is a race against the clock.
- In ANY other case (Either: you never transacted nor refreshed from your wallet, OR you use taproot, OR you don't only use Coldcards) the safest option is to wait for a Slipstream tool we will provide soon.
Or course if you wallet is not affected (for example your compromised Coldcard is only one key in a 2-of-3), you can transact normally.
Correction notice: clarification came that the key was originally created on an MK3 and migrated to MK4 so this is not yet confirmed that MK4 entropy is breached.
@notgrubles You can make a TEST SEED using the same dice rolls on public viewable software to know that the hardware correctly incorporated them. Then make your real seed only on the hardware.
@giacomozucco@darosior@coinjoined They tried to trust the best easy thing that their podcaster recommended. Right. The thing about vaults is that they let the best easy thing be actually good.
@giacomozucco@darosior@coinjoined The difference would have saved users because without additional skills, effort, or knowledge they could have had a secure wallet instead of single point of failure.
No. Stop.
For a user to have exceptional security if bitcoin had ctv+ccv requires no special action or understanding on their part. No extra seed to backup. No dice. No understanding of saving presigned transactions and statefulness. Literally just a wallet that has an undo feature like gmail. That's all they need to understand.
To use green requires setting policies, storing presigned txs, understanding rollover and timelocks and probably more.
It's relatively easy for a service to create an exceptional and secure wallet with ctv+ccv and then naïve users can benefit.
It's impossible to make an equally secure wallet without, and the ones that get close require much more of users.
@giacomozucco@darosior@coinjoined Jfc. Stop being retarded man.
The user can't use their funds until the timelock expires if the server fails. Totally different. I was a green user. I know the experience well and it's much worse than the vault ux.