This is worse than any previous Bitcoin exchange hack. It is arguably one of the worst things that could happen.
The popular hardware wallet COLDCARD has a faulty random number generator (RNG). Funds are being drained from ordinary users’ hardware wallets as you read this.
Users first reported to Block less than 24 hours ago that funds were moving out of their wallets. The exploit was most likely discovered with the help of AI. Block has confirmed that the RNG is broken. You know what that means.
There are likely already multiple attackers competing for the affected BTC. Many more will join very soon.
Nobody knows how much BTC is affected.
Nobody knows how many users are affected.
This attack has only just begun, and it will continue until all affected BTC has been drained unless users secure their funds first. Inevitably, many Bitcoiners will not hear about the incident early enough to respond in time.
I am truly saddened for everyone affected, especially those who may have just lost their life savings.
The worst part is that they did everything right.
Login to reply
Replies (62)
Welcome to bitcoin
How fast does one need to rush if using mk4 multi sig?
It is sad, but the lesson we learned is great:
Roll your fucking seed and use a fucking passphrase!!! Any of this 2 would have been enough in this case. I’m sure that anyone who has been around have heard it a few times
They didn't do "everything right", quite the opposite.
They had one job - to secure peoples Bitcoin.


Block Engineering Blog
Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware
How a disabled hardware-RNG path and 32-bit reseed constrain entropy in affected COLDCARD firmware and expose generated secrets.
This is absolutely devastating—people did everything by the book and still got hit, my heart goes out to anyone caught in this.
(Feel free to check our campaign if you wish to support my family in Gaza 🙏 https://chuffed.org/project/125341-urgent-appeal-help-the-family-of-aya-and-imad)
What does “secure their funds first” even mean today?
Would moving funds to a new wallet with a passphrase in it be enough?
there is no such thing as a RNG... such grifts depending on "theoreticals" precludes it being random.
…the firmware is open source. We all could have spotted it. We all failed.
he means the users - the victims - did everything right
I agree with that and I am truly sorry for them.
It shocks me how many don’t get this from the beginning.
I have zero tech background. Yet, when my son explained the cold storage process to me, it took 10 seconds to ask, “but how do we know the seed GIVEN to us is safe?”
This is not a flaw of Bitcoin or cold storage. It’s a failure to think critically or sovereignly.
Calle was saying that the users did everything right, I think.
But I don’t agree with that either.
Not your entropy, not your coins!
Its blurred language from him. I agree that users are not at fault, they expect a secure product and I am truly sorry for their lost Bitcoin.
Multisig is ok. If all 3 keys are ColdCard, the funds should be moved out of an abundance of caution. If one of the keys is ColdCard, you’re good, but that key will need to be rotated out - the funds moved to a new multisig addy
This is truly the saddest part: "The worst part is that they did everything right."
And please don't come back with "they should have used dice," "they should have used multisig," or any such bullshit.
Many of the most security-conscious, hardcore Bitcoiners chose ColdCard because they believed it was one of the safest hardware wallets available.
View quoted note →
If self custody is vulnerable. What is the pitch? The power of self custody looks weak and vulnerable. Maybe even…
View quoted note →
Isn't the actual mistake here to _at all_ fall back to some other RNG, which (at least in this case) is known to rely on less entropy than the main RNG?
I mean .. shouldn't the hardware wallet instead just print a message like "RNG failed .. no seed generation possible .. please update firmware."?
Completely understandable. Best is if you have a trusted friend who is nerd and can help you but even nerds are not that good with that. Also sharing information about your Bitcoin is not good, even with close friends ... Things that are essential can be learnt, step by step the things that are unclear, for example https://learnmeabitcoin.com/technical/keys/hd-wallets/mnemonic-seed/ but I understand its hard stuff. Another option as well is a trusted consultaion from a proven company in the space.
Whilst it sucks for those affected, its not as bad as:
(1) Mtgox hack. 80% of global btc trading happened through gox and 6% of all bitcoins in circulation were stolen. BTC price collapsed roughly 50%.
(2) Bitfinex Hack. 120000 btc stolen. All customers had to take an account balance haircut of 35%. BTC price collapsed 20%.
To me this is similar - but worse than - the milksad bug. How bad it will be for the market will depend on (a) Coldcard's reaction to those who have lost funds and (b) how quickly Coldcard's customers move their funds to secure addresses.
COLDCARD's RNG failure is just the tip of the iceberg, courtesy of NSA-approved "secure" hardware.
Bitcoin is "unbackable" right ?? You know how much people will lost credibility after this ? And how many won't even try bitcoin ? Holding Sats/Bitcoin is becoming really stressful and you don't even know if in the future more attacks will come to the "secure wallets" , open source wallets with bug or back doors open as human greedy and corruption is the trending those days ! Fuck humanity men !
And at the same time…..
By doing so, we are unnecessarily bringing TRUST back into a TRUSTLESS system.
This sucks bad now for all those affected. But like every other hack/lesson in the past (Mt gox, etc)
It strengthens the collective’s true understanding and knowledge.
This will be SOOOO needed to hold one’s resolve in what’s to come.
My 2 cents. Rant over. 🤪
Bitcoin is verifiable but to be able to do it a special knowledge is needed.
So yes we put trust in those who have that knowledge because we are unable to do it ourselves.
And there are ways to reduce the risk when couple different _independent_ verifiers do their work properly.
Also the system needs to be kept as simple as possible to be secure. For example spammers, scammers, shitcoiners VCs that want to add complexity to Bitcoin is an attack on Bitcoin security, not just a spam that abuses Bitcoin's nodes and network.
YES

this is way worse than exchange hacks because it affects self custody. and the milksad bug had way less bitcoin stolen (like 30 instead of >1000)
Why do we keep saying they did everything right when they still trusted the device to generate the seeds? And didn't use a passphrase that even with a 4 number PIN could have dodged this bullet?
Everything right is being paranoid to the last consequences.
Are funds stored with casa, nunchuck or unchained safe in multisig if you use coldcard??
Time will tell. Let's see what Mr Market thinks about this all.
Agreed on the last paragraph. Not your first point about “special knowledge” and “trusting the experts”. This is antithetical to the whole purpose of the protocol.
It takes a few hours to learn the whole process of sovereign entropy generation. From scratch.
It’s important on MANY levels. Mostly metaphysical 🪬
This is why I stopped telling people years ago to BUY bitcoin. And instead tell them to STUDY Bitcoin. 👁️
market not that affected because basically nobody self custodies
By "special knowledge" I mean - know very good programming to verify the code, know very good security to verify if security exploits are present in the code, know very good Bitcoin's inner working to verify the implementation of the BIPs, know very good cryptography to be able to understand whether truly secure algorithms are used and I am sure I am missing other things too.
The Coldcard bug highlights that AI is the technological opposite of encryption. Where cryptography is a tool that gives those defending their privacy and property an asymmetric advantage, ever-more-intelligent LLMs give attackers their own asymmetric weapon to steal and surveil.
To maintain sovereignty in the future will demand far greater personal responsibility and prudence.
View quoted note →
Has there been any more transactions out of people’s wallets since last night?
"they did everything right"
No, they relied on computer RNG instead of rolling dice.
calle is a retarded lying deep state glowie, that's why
yep happening right now
That’s terrifying. Glad I moved them last night
"I didn't know"
View quoted note →
If something can happen it will happen or often has already happened, you just don't know about it.
This message should be internalized by the childlike mentalities in this sphere who just go silent on the chain being attacked with ___.
Military intelligence likely has a quantum computer which could crack SHA-256 right now but if they used it they would reveal they have it. MI is about 30-50 years ahead of what they release to the public.
“The worst part is that they did everything right.”
View quoted note →
I agree. I think the root cause is this toxic culture of hardware wallet manufacturers promoting themselves as the convenience tool that lets people be lazy. Hardware wallet server purpose, but it has never been to create your seed nor has it been to keep it safe on your behalf.
Fortunately, we convince people that they should keep and be responsible for a copy of their seed by themselves. Now we need to convince people that they should be responsible for the original entropy as well.
My proposal is that we make it normal for hardware wallets to give people warnings if they ever choose to use a computer-generated seed and to recommend dice coins or any other good source of entropy that is not just a button click and magic happens.
I don't think it's too much to ask honestly.
It did not affect self custody, it affected halfway-house self custody.
This is the only way we can learn unfortunately. It's super sad, super unfortunate, very stressful and pretty disastrous. But those who told you how to avoid this type of situation we're being ignored and maybe even laughed at Probably more laughed at by the people who just kept their shit on exchanges but, still.
The beauty of it is you don’t need to be a miIIionaire to stárt. I bégan with what I could affórd, and today, the grôwth I’ve seen has been beyond what any bank or traditional system could offer. Crypto has given me fiñancial freedom, and every time I look back, I’m just glad I took the step.
If someone’s serious about buiIding weálth and tired of slow, outdated systems, cryptô is the gateway, it’s a whole new world of opportunities waiting for those bold enough to take them.
Message her with "Join" right now to begin trading better! (
). @Riley Greyson


WhatsApp.com
Riley D Greyson
Business Account

I feel ya
This is so significant that it’s likely to change the industry’s seed generation standards.
If you have funds on COLDCARD and its seed has been generated by the device and not dice entropy you need to ACT NOW.
Feel free to reach out if you need any help.
Self Custody is still the way, but this is a massive blow for the Bitcoin community and Bitcoin adoption.
View quoted note →
Not many people recommend a passphrase up till now as it introduced complexity and probably wasnt deemed necessary.
"they did everything right" according to nvk who pays all the podcasts in the space.
Obviously when you lose money, you did something wrong. To claim otherwise is childish. We have to learn from this what we could have done better.
which pubkeys did the funds get moved to?
someone shoudl reveal that.
otherwise it sounds like social media gossip
I can't thank myself enough for getting started. Despite the economic situation, I'm so happy to see €78,000 in returns from a €15,000 short-term investment with pjtradinghub. His videos are top-notch and highly educational, giving you real insights to achieve your goals and come out from debt! For a guide to a professional trader, I highly recommend everyone check out his Telegram 👉 "pjtradinghub"


I’ve been exploring different perspectives in the crypto space, and I’ve come across Paul Jon's content a few times. What stands out to me is his focus on risk management and staying patient rather than chasing quick profits. I don’t think there’s a single ‘perfect’ approach to trading, but it’s useful to learn from different viewpoints and then build your own strategy over time. Some of his ideas seem practical, especially for people who are still trying to understand market behavior. At the end of the day, everyone has to test what works for them and stay consistent. The market is always changing, so having a balanced mindset and being open to learning is probably more important than following any one method blindly. Just sharing my thoughts based on what I’ve seen so far.”
Where to find him
Telegram 👇
"Pjtradinghub"


I recommend Paul Jon to anyone who wants to build a sustainable trading career. His mentorship focuses on developing confidence through proper risk management, disciplined execution, and continuous learning.
Where to find him
TeleGram 👇
Pjtradinghub
Some folks may disagree with me, but trusting opaque hardware for generating entropy/seeds/keys is a single point of failure.
Last night, I used AI to architect a zero-trust alternative. It bypasses silicon entirely by forcing 128 physical coin flips to generate the master seed.
- Deterministic single-file HTML build
- CSP locked / offline execution
- Full BIP85 index derivation
- Airgapped QR code export
- Zero hardware trust (Physics only)
Have your AI verify my AI:
View quoted note →
GitHub
GitHub - ghscuuo/airgap-coinflip: A zero-trust, mathematically reproducible, offline deterministic wallet and BIP85 engine.
A zero-trust, mathematically reproducible, offline deterministic wallet and BIP85 engine. - ghscuuo/airgap-coinflip
bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r
bc1qx76cae2706qd5q576feh7xq8rfcsjpf2htfhe3
bc1q8jy96fe5lf8vfugydnte3cguk92gpev7kwtp3q
bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0
That phase "they did everything right" is super loaded. You are right. They should have not TRUSTED the device to make the key. They should have used a passphrase. They should not have TRUSTED NVK or the podcasters and "influencers". They should have looked at the code. They should have run AI on the code...
They should not have treated being a bitcoinner as a religion. Complete with priests and doctrine and mantras.
But this is the thing... There was too much. Too much for the regular human. Almost none of us understand 1/10th of the cryptography bitcoin uses. Most "plebs" can't explain how a RNG works. But we all know how to say things like "stay humble" and "nyknyc".
That's what I think "everything right" means. They trusted the priests. They taped the mantras to their dashboards.
And they got hurt. Bad.
The good news is bitcoin survives this. And life goes on.
Not everyone can "be their own bank".
But what has always mattered is not that you have to (do everything right) but that you CAN.
My heart goes out to those hurt by this.
And beware priests who cannot step down from their pulpits for a moment...
With TRUE humility.
PEACE

COLDCARD
COLDCARD Mk5 - Coinkite's Ultra-Secure and Affordable Bitcoin Hardware Wallet
COLDCARD Mk5 is a secure and affordable Bitcoin hardware wallet that is easy to use and comes in a variety of colours.
If you're looking to recover your Bitcoin. Paul Jon is the best man to meet to guide you through every recovery process and I highly recommend everyone to check him out. He is the BEST 🌟
I'll buy one off anyone (without the counter run up) for 33k sats. mk4 I'll do 15k. You pay postage.
Massive wake up call
View quoted note →
Wait really? Lol.