If your bitcoin was stolen in the Coldcard exploit, (deconflict_) put together a step-by-step guide on how to collect evidence and report it to the proper authorities.
Don't assume your case is too small or too late.
TFTC
tftc@primal.net
npub1sk7m...jraw
Truth for the Commoner. A media company focused on #Bitcoin, freedom, and truth in the digital age.
"Do people believe that this war is about Iran and its nuclear program, or is it part of a larger change happening around the world?"
Anas Alhajji connects the dots on energy dominance.
Tech stocks just saw their largest 5-week inflow in history.


Coinkite has halted all Coldcard shipments and destroyed remaining inventory with affected firmware.
Customers with in-transit orders have been contacted directly with migration steps.


Users are reporting that Coldcard's emergency firmware update is bricking some devices.
These reports are anecdotal and have not been confirmed by Coinkite, but if you're planning to update, move your funds off the device first.
A security researcher (1440000bytes) flagged a vulnerability in Bitkey's inheritance setup flow.
The team responded within hours, confirming no funds were at risk thanks to their defense-in-depth architecture.
A patch was submitted to both app stores and they hosted a public X Space to walk through the technical details with the community.


Galaxy Research is tracking the Coldcard hack in real time.
They've identified three waves of sweeps so far: 1,367 BTC (~$88.6M) drained from 4,585 addresses.
The first wave hit 1,196 addresses in a 41-minute window, all paying an identical 30 sat/vB fee. Automated key scanning, not owners moving funds.
Galaxy notes "the loss profile is dominated by sub-1 BTC addresses in count, but by larger addresses in value. This appears to be the shape of individual self-custody, not institutional holdings."
Not one coin taken was created before the vulnerable firmware shipped in March 2021.


.Kevin Loaec 🧙♂️🐟 from Wizard Sardine just published a full technical breakdown of a critical Coldcard vulnerability.
Every seed generated on the device since 2021 is compromised. Wallets are being drained right now.
The chip has a perfectly working hardware random number generator. Nobody was calling it.
"The Coldcard replaces MicroPython's randomness module with its own, deemed more conservative. To do so, it disables the original one... The catch is that MicroPython does not remove rng_get() when that flag is 0. It replaces it with a software imitation."
The result: "a Coldcard seed no longer held a single bit of physical randomness."
A compile-time safety check should have caught this but used `ifndef` instead of `if`. "One character stood between that safeguard and its purpose." It passed on every build for 5+ years.
Seeds from 50+ dice rolls or pre-2021 are safe. Everyone else: move funds now.


Wizardsardine - a team of bitcoiners with a passion for security
Critical Coldcard flaw: what happened, who is affected, and what to do
Coldcard devices had an entropy bug since 2021, MK2, MK3, MK4, MK5 and Q wallets are being drained right now. Here is what happened in the code, ex...

As much as this hurts.
The network will grow stronger from it.
Don't give up.


TFTC 778 w/ (hot_town): "The playing field is being leveled. It's no longer limited by technical ability. This opens up whole new economies."
We discuss:
⚡ Building with AI agents
⚡ Bitcoin & the agent economy
⚡ Why open source wins
Conner Brown of Matthew Boyer urges Coldcard victims not to destroy compromised devices after the firmware flaw that drained tens of millions in BTC.
“If you have a Coldcard that was compromised, do not throw away or destroy the device.”


Hyperscale Data sells 100 Bitcoin, establishes BTC-backed credit facility to accelerate Michigan AI campus.


"Even the smart guys screwed up self-custody. How can we expect anybody will comfortably self-custody after this?"
(jamesob) on the second-order effects of the COLDCARD vulnerability, why every hardware wallet maker has had a fatal misstep, and why the only categorical fix may be covenants.
"Security by obscurity is going to zero rapidly."
(jamesob) and other researchers independently reproduced the COLDCARD vulnerability by pointing an AI model at the firmware history.
This is the new reality for open-source security.
"You screw up one thing, the wrong one thing, and it's toast."
@MartyBent and (jamesob) on the COLDCARD vulnerability, what it means for self-custody, and why you should be reaching out to anyone you've ever recommended a COLDCARD to.
Coinbase Chief Policy Officer on CLARITY Act progress: "We've got ethics nailed down, we've got nominations nailed down, we've got a bipartisan bill on the substance, we should be good to go."
TFTC 777 w/ (jamesob): "If you're single-sig with no passphrase or dice rolls, you need to drive home and migrate your funds. These wallets are dangling in the wind."
We discuss:
⚡ The flaw exposed overnight
⚡ How to check your risk
⚡ Why self-custody still wins
Coldcard founder (nvk) says the reports of drained wallets are not a device vulnerability.
The thefts are part of a wider attack affecting 500 private keys across different wallet types, not just Coldcard.


Sen. Cynthia Lummis says the CLARITY Act remains on track for a Senate vote before the August recess: “Sen. Thune has kept a place for the CLARITY ACT on the agenda...and I believe he does intend to go through with it...We will be moving forward.”
Sen. Cynthia Lummis: “This doesn’t come back next year… The realistic next chance at market structure legislation is likely 2030.”
She urged passage of the CLARITY Act, adding the window to lead “is wide open.”