@theedeonaperry My heart couldn’t take it 😆 when laboral kutxa rolled in…I was chill. Then groupe crédit agricole, groupe bpce, rabobank, rewe group, zen-noh, amul, iffco, sistema unimed, international cooperative alliance!
UPDATE: Telegram has now been restored to the Apple App Store following its removal.
Telegram says the app has being reinstated and will soon be available to all users again.
They did not provided any explanation for why it was removed.
People are not appreciating one of the biggest takeaways from the COLDCARD hack.
Cybersecurity is now all about spend. Once AIs are doing all of the attacking, the simple question is how much money are you spending with frontier AIs scanning for vulnerabilities, compared to what attackers are spending?
The fact that Claude was able to find this in 8 minutes (and GLM in 20 minutes) tells you that these guys were doing basically nothing. Absolutely 0 AI hardening happening on releases.
COLDCARD is a minority vendor. They have probably ~2% market share within Bitcoin hardware wallets. The lesson: security-sensitive products (crypto wallets especially) are going to consolidate toward larger, better-funded players who can afford to do the security hardening, and small companies without meaningful funding are simply NGMI.
Second: we can now start standardizing reporting on the cost of discovering an attack, in order to understand how bad it was. Call it Cost of Discovery (CoD): how much it would cost a frontier model to discover the same vulnerability.
The linked Claude Code claim is a little suspect (it may have been contaminated by web search), so another poster turned off web access to GLM 5.2 and was able to rediscover the attack in 20 minutes.
Taking the @ZhipuAI API numbers ($1.40/M in, $4.40/M out, 35tps), given the kind of workload here (read-heavy agentic workload), Opus estimates the total Cost of Discovery on this bug was around $2.
$2 of AI hardening would've caught this bug.
There is no excuse for this.
In the future we should start reporting Cost of Discovery on these when vulnerabilities are independently replicated. (Companies should not necessarily publish the amount of money they are spending on AI-hardening, as that would imply to an attacker: if you spend more than X, you may find something.)
If you are a startup and building anything, you should be running AI-hardening on EVERY release. You should be spending AT LEAST in the thousands of dollars using a frontier-level model searching for crits, especially when the endpoint (recovering the key, or draining money out of a smart contract) is easily verifiable.
My heart goes out to anyone who lost money from this. AI is genuinely changing the game and many have not been able to adapt in time. But I do believe in the long run, AI is going to make us all better off security-wise than before.
We have no choice but to adapt.
Actually devastating because the people using Coldcards were the biggest most security conscious type of Bitcoin holder. They were the ones who believed so much in the mission of Bitcoin that they actually learned how to set up a Coldcard. The true believers got rugged. Very sad.
LATEST: Coldcard user lost C$1.6 MILLION in BTC despite doing “everything right.”
Jonathan Goodman says he is filing a police report, but does not expect to recover anything.
After hearing about the hack on July 29, he checked his wallet and found that all 18.25 $BTC had been drained.
He said the device had never touched the internet and had been stored inside a safety deposit box.
“I did everything right. None of it mattered.”
Coldcard confirmed a flaw caused some wallets to create seed phrases that were easier for hackers to guess.
Total Bitcoin stolen may now exceed $109.6M.
Last week’s Coldcard incident is a reminder of something the industry underrates: randomness is the foundation of self-custody. If it's weak, everything built on top of it is too.
Here’s what happened, and why Ledger devices are unaffected.
Trump sued Capital One to prove they closed his accounts over politics.
The bank’s answer, filed Friday: it was the anti-money-laundering desk.
Months of review.
Three hundred accounts.
He pulled that thread himself.