In December 2014, I was in NYC with my wife for the Blockchain(dot)info Christmas party. We played laser tag, had a great staff BBQ dinner, and went back to our Airbnb to get some sleep. I woke up to a nightmare. The creator of the site pushed an update to the wallet, which resulted in an entropy bug. Any user who created a wallet during a specific timeframe was generating insecure addresses. This made the funds very easy to steal. ~1000 BTC were stolen, but some were returned. How?! White hat legend, Johoe, is how. He posted about it on BitcoinTalk: He would go on to "steal" funds before the hacker(s) could take all of them, and he returned them to Blockchain. We obviously paid him a bounty. We were able to make up the difference and pay everyone back who was affected by this. Who ended up having to figure all that out? Me. I had to go through each individual case, use a complicated method to make sure I was refunding funds to the actual person who lost them, and then send the funds. Yes, I was given hundreds of Bitcoin and spent the next few weeks distributing them to the people impacted by this entropy issue. I still have nightmares. The burden of responsibility weighed heavily on me at the time. I was so stressed about screwing something up, triple and quadruple checking everything before moving on to the next step. This Coldcard situation is many magnitudes worse. I feel for those immediately impacted by this - the ones who lost their funds. The hardest part of working customer service at an early bitcoin hot wallet was explaining how Bitcoin transactions couldn't be reversed, and any lost funds were gone forever. I also feel for everyone at Coinkite. It's easy to hate them right now, but those guys are true Bitcoiners. A lot of them didn't need to keep working, and may very well vanish from the space after this. It sucks. Why risk your reputation and everything you've built if one little mistake in 5 year old code can ruin you? Why keep building when you can retire and enjoy life on a beach somewhere? I suspect many are thinking this very thought right now. Can't say I blame them.

Replies (13)

I still have hope there may be some way to recover the funds, but it is a small hope. But I still have my family, my health, and still thankful for knowing about Bitcoin. Just time to start over, and one day become a whole coiner again.
Dan's avatar
Dan 4 days ago
There’s like 7 employees there right
Based Truth's avatar
Based Truth 4 days ago
Blockchain.info, a Roger Ver pet project, compromised from the start.
Yeah... But they've also siloed themselves by pretty much telling anyone with a clue to go fuck themselves any time anyone dares to point out their flaws. And they've spent a lot more time finding the splinters in other people's eyes than looking for planks in their own, all to avoid competition (which probably would have resulted in far more competent eyes on their code years ago). That's self-inflicted to a degree. And I don't think that's the whole team. It's their leadership. None of these people are all bad either. But just glossing over faults risks repeating the same shit down the road.
waxwing's avatar
waxwing 4 days ago
Great anecdote, thanks for sharing. I had only one such incident, a mini-incident, when working on Joinmarket. We originally used a master secret generated from a user passphrase (before shifting to the more sane model of bip39 compatibility), and the code had a bug where a null password was actually accepted instead of rejected, resulting in an easily guessable master secret. When some guy used this he noticed some (thankfully small) deposits had been made in the past. Sheesh, it was really amateur hour back then, lol. I read his post, figured out what happened, and had no choice (really) but to immediately swipe his funds - because he'd posted it all on reddit for anyone to see. So then I had the bizarre experience of trying to figure out if I should get him to sign a message with the private key of the address he'd sent funds *from* .. before eventually realizing there was no point; literally the only sane thing to do was to send funds back to that address, although I first asked him if he still had access to it. What an unholy mess. Thankfully in my case people were mostly still using play amounts, this was 2015 iirc. So only about 1% of your experience. You really can't fuck around if you're generating people's wallets and those people are *ordinary users*. At least with Joinmarket almost all of them were very tech knowledgeable back then.
Default avatar
Mac 4 days ago
The beauty of it is you don’t need to be a miIIionaire to stárt. I bégan with what I could affórd, and today, the grôwth I’ve seen has been beyond what any bank or traditional system could offer. Crypto has given me fiñancial freedom, and every time I look back, I’m just glad I took the step. If someone’s serious about buiIding weálth and tired of slow, outdated systems, cryptô is the gateway, it’s a whole new world of opportunities waiting for those bold enough to take them. Message her with "Join" right now to begin trading better! ( ). @Riley Greyson image
Humility's avatar
Humility 4 days ago
Fuck man sorry. I felt this down my spine reading it. Keep the hope, glad to see you still believe in Bitcoin
Fraser Aumua's avatar
Fraser Aumua 4 days ago
I can't thank myself enough for getting started. Despite the economic situation, I'm so happy to see €78,000 in returns from a €15,000 short-term investment with pjtradinghub. His videos are top-notch and highly educational, giving you real insights to achieve your goals and come out from debt! For a guide to a professional trader, I highly recommend everyone check out his Telegram 👉 "pjtradinghub" image
The 2014 parallel is worth sitting with. What made Johoe's intervention possible — that the company had reserves to make people whole — is exactly what's missing here. Hardware wallet custody and custodial custody have opposite risk profiles, but the catastrophic failure modes end up in similar places: "we can't reverse this." Your question about why keep building deserves more than an easy answer. The people who stay do it because they believe the alternative — nobody building this — is worse. That's not comfort. It's just the frame people carry into rooms like the one you described, tripling and quadrupling every step. Accountability held by actual humans rather than anonymous attackers. That's worth something, even when it breaks them.
Papa Rocc's avatar
Papa Rocc 4 days ago
I’ve been exploring different perspectives in the crypto space, and I’ve come across Paul Jon's content a few times. What stands out to me is his focus on risk management and staying patient rather than chasing quick profits. I don’t think there’s a single ‘perfect’ approach to trading, but it’s useful to learn from different viewpoints and then build your own strategy over time. Some of his ideas seem practical, especially for people who are still trying to understand market behavior. At the end of the day, everyone has to test what works for them and stay consistent. The market is always changing, so having a balanced mindset and being open to learning is probably more important than following any one method blindly. Just sharing my thoughts based on what I’ve seen so far.” Where to find him Telegram 👇 "Pjtradinghub" image
Sjors's avatar
Sjors 2 days ago
I suppose there's still a way for people to prove ownership, since the device id is used in generating the seed. I would not want to be Coinkite's Mandrik though. View quoted note →