This is worse than any previous Bitcoin exchange hack. It is arguably one of the worst things that could happen. The popular hardware wallet COLDCARD has a faulty random number generator (RNG). Funds are being drained from ordinary users’ hardware wallets as you read this. Users first reported to Block less than 24 hours ago that funds were moving out of their wallets. The exploit was most likely discovered with the help of AI. Block has confirmed that the RNG is broken. You know what that means. There are likely already multiple attackers competing for the affected BTC. Many more will join very soon. Nobody knows how much BTC is affected. Nobody knows how many users are affected. This attack has only just begun, and it will continue until all affected BTC has been drained unless users secure their funds first. Inevitably, many Bitcoiners will not hear about the incident early enough to respond in time. I am truly saddened for everyone affected, especially those who may have just lost their life savings. The worst part is that they did everything right.

Replies (62)

It is sad, but the lesson we learned is great: Roll your fucking seed and use a fucking passphrase!!! Any of this 2 would have been enough in this case. I’m sure that anyone who has been around have heard it a few times
What does “secure their funds first” even mean today? Would moving funds to a new wallet with a passphrase in it be enough?
Chris's avatar
Chris 1 week ago
It shocks me how many don’t get this from the beginning. I have zero tech background. Yet, when my son explained the cold storage process to me, it took 10 seconds to ask, “but how do we know the seed GIVEN to us is safe?” This is not a flaw of Bitcoin or cold storage. It’s a failure to think critically or sovereignly.
Chris's avatar
Chris 1 week ago
Calle was saying that the users did everything right, I think. But I don’t agree with that either. Not your entropy, not your coins!
Its blurred language from him. I agree that users are not at fault, they expect a secure product and I am truly sorry for their lost Bitcoin.
Multisig is ok. If all 3 keys are ColdCard, the funds should be moved out of an abundance of caution. If one of the keys is ColdCard, you’re good, but that key will need to be rotated out - the funds moved to a new multisig addy
This is truly the saddest part: "The worst part is that they did everything right." And please don't come back with "they should have used dice," "they should have used multisig," or any such bullshit. Many of the most security-conscious, hardcore Bitcoiners chose ColdCard because they believed it was one of the safest hardware wallets available. View quoted note →
Isn't the actual mistake here to _at all_ fall back to some other RNG, which (at least in this case) is known to rely on less entropy than the main RNG? I mean .. shouldn't the hardware wallet instead just print a message like "RNG failed .. no seed generation possible .. please update firmware."?
Completely understandable. Best is if you have a trusted friend who is nerd and can help you but even nerds are not that good with that. Also sharing information about your Bitcoin is not good, even with close friends ... Things that are essential can be learnt, step by step the things that are unclear, for example https://learnmeabitcoin.com/technical/keys/hd-wallets/mnemonic-seed/ but I understand its hard stuff. Another option as well is a trusted consultaion from a proven company in the space.
Whilst it sucks for those affected, its not as bad as: (1) Mtgox hack. 80% of global btc trading happened through gox and 6% of all bitcoins in circulation were stolen. BTC price collapsed roughly 50%. (2) Bitfinex Hack. 120000 btc stolen. All customers had to take an account balance haircut of 35%. BTC price collapsed 20%. To me this is similar - but worse than - the milksad bug. How bad it will be for the market will depend on (a) Coldcard's reaction to those who have lost funds and (b) how quickly Coldcard's customers move their funds to secure addresses.
Based Truth's avatar
Based Truth 1 week ago
COLDCARD's RNG failure is just the tip of the iceberg, courtesy of NSA-approved "secure" hardware.
Bitcoin is "unbackable" right ?? You know how much people will lost credibility after this ? And how many won't even try bitcoin ? Holding Sats/Bitcoin is becoming really stressful and you don't even know if in the future more attacks will come to the "secure wallets" , open source wallets with bug or back doors open as human greedy and corruption is the trending those days ! Fuck humanity men !
Chris's avatar
Chris 1 week ago
And at the same time….. By doing so, we are unnecessarily bringing TRUST back into a TRUSTLESS system. This sucks bad now for all those affected. But like every other hack/lesson in the past (Mt gox, etc) It strengthens the collective’s true understanding and knowledge. This will be SOOOO needed to hold one’s resolve in what’s to come. My 2 cents. Rant over. 🤪
Bitcoin is verifiable but to be able to do it a special knowledge is needed. So yes we put trust in those who have that knowledge because we are unable to do it ourselves. And there are ways to reduce the risk when couple different _independent_ verifiers do their work properly. Also the system needs to be kept as simple as possible to be secure. For example spammers, scammers, shitcoiners VCs that want to add complexity to Bitcoin is an attack on Bitcoin security, not just a spam that abuses Bitcoin's nodes and network.
this is way worse than exchange hacks because it affects self custody. and the milksad bug had way less bitcoin stolen (like 30 instead of >1000)
Why do we keep saying they did everything right when they still trusted the device to generate the seeds? And didn't use a passphrase that even with a 4 number PIN could have dodged this bullet? Everything right is being paranoid to the last consequences.
Are funds stored with casa, nunchuck or unchained safe in multisig if you use coldcard??
Chris's avatar
Chris 1 week ago
Agreed on the last paragraph. Not your first point about “special knowledge” and “trusting the experts”. This is antithetical to the whole purpose of the protocol. It takes a few hours to learn the whole process of sovereign entropy generation. From scratch. It’s important on MANY levels. Mostly metaphysical 🪬 This is why I stopped telling people years ago to BUY bitcoin. And instead tell them to STUDY Bitcoin. 👁️
By "special knowledge" I mean - know very good programming to verify the code, know very good security to verify if security exploits are present in the code, know very good Bitcoin's inner working to verify the implementation of the BIPs, know very good cryptography to be able to understand whether truly secure algorithms are used and I am sure I am missing other things too.
The Coldcard bug highlights that AI is the technological opposite of encryption. Where cryptography is a tool that gives those defending their privacy and property an asymmetric advantage, ever-more-intelligent LLMs give attackers their own asymmetric weapon to steal and surveil. To maintain sovereignty in the future will demand far greater personal responsibility and prudence. View quoted note →
If something can happen it will happen or often has already happened, you just don't know about it. This message should be internalized by the childlike mentalities in this sphere who just go silent on the chain being attacked with ___. Military intelligence likely has a quantum computer which could crack SHA-256 right now but if they used it they would reveal they have it. MI is about 30-50 years ahead of what they release to the public.
I agree. I think the root cause is this toxic culture of hardware wallet manufacturers promoting themselves as the convenience tool that lets people be lazy. Hardware wallet server purpose, but it has never been to create your seed nor has it been to keep it safe on your behalf. Fortunately, we convince people that they should keep and be responsible for a copy of their seed by themselves. Now we need to convince people that they should be responsible for the original entropy as well. My proposal is that we make it normal for hardware wallets to give people warnings if they ever choose to use a computer-generated seed and to recommend dice coins or any other good source of entropy that is not just a button click and magic happens. I don't think it's too much to ask honestly.
It did not affect self custody, it affected halfway-house self custody. This is the only way we can learn unfortunately. It's super sad, super unfortunate, very stressful and pretty disastrous. But those who told you how to avoid this type of situation we're being ignored and maybe even laughed at Probably more laughed at by the people who just kept their shit on exchanges but, still.
Default avatar
Pete 6 days ago
The beauty of it is you don’t need to be a miIIionaire to stárt. I bégan with what I could affórd, and today, the grôwth I’ve seen has been beyond what any bank or traditional system could offer. Crypto has given me fiñancial freedom, and every time I look back, I’m just glad I took the step. If someone’s serious about buiIding weálth and tired of slow, outdated systems, cryptô is the gateway, it’s a whole new world of opportunities waiting for those bold enough to take them. Message her with "Join" right now to begin trading better! ( ). @Riley Greyson image
This is so significant that it’s likely to change the industry’s seed generation standards. If you have funds on COLDCARD and its seed has been generated by the device and not dice entropy you need to ACT NOW. Feel free to reach out if you need any help. Self Custody is still the way, but this is a massive blow for the Bitcoin community and Bitcoin adoption. View quoted note →
Hofer99's avatar
Hofer99 6 days ago
Not many people recommend a passphrase up till now as it introduced complexity and probably wasnt deemed necessary.
"they did everything right" according to nvk who pays all the podcasts in the space. Obviously when you lose money, you did something wrong. To claim otherwise is childish. We have to learn from this what we could have done better.
Fraser Aumua's avatar
Fraser Aumua 6 days ago
I can't thank myself enough for getting started. Despite the economic situation, I'm so happy to see €78,000 in returns from a €15,000 short-term investment with pjtradinghub. His videos are top-notch and highly educational, giving you real insights to achieve your goals and come out from debt! For a guide to a professional trader, I highly recommend everyone check out his Telegram 👉 "pjtradinghub" image
Papa Rocc's avatar
Papa Rocc 6 days ago
I’ve been exploring different perspectives in the crypto space, and I’ve come across Paul Jon's content a few times. What stands out to me is his focus on risk management and staying patient rather than chasing quick profits. I don’t think there’s a single ‘perfect’ approach to trading, but it’s useful to learn from different viewpoints and then build your own strategy over time. Some of his ideas seem practical, especially for people who are still trying to understand market behavior. At the end of the day, everyone has to test what works for them and stay consistent. The market is always changing, so having a balanced mindset and being open to learning is probably more important than following any one method blindly. Just sharing my thoughts based on what I’ve seen so far.” Where to find him Telegram 👇 "Pjtradinghub" image
Tommy 's avatar
Tommy 6 days ago
I recommend Paul Jon to anyone who wants to build a sustainable trading career. His mentorship focuses on developing confidence through proper risk management, disciplined execution, and continuous learning. Where to find him TeleGram 👇 Pjtradinghub
bootlace's avatar
bootlace 6 days ago
Some folks may disagree with me, but trusting opaque hardware for generating entropy/seeds/keys is a single point of failure. Last night, I used AI to architect a zero-trust alternative. It bypasses silicon entirely by forcing 128 physical coin flips to generate the master seed. - Deterministic single-file HTML build - CSP locked / offline execution - Full BIP85 index derivation - Airgapped QR code export - Zero hardware trust (Physics only) Have your AI verify my AI: View quoted note →
bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r bc1qx76cae2706qd5q576feh7xq8rfcsjpf2htfhe3 bc1q8jy96fe5lf8vfugydnte3cguk92gpev7kwtp3q bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0
That phase "they did everything right" is super loaded. You are right. They should have not TRUSTED the device to make the key. They should have used a passphrase. They should not have TRUSTED NVK or the podcasters and "influencers". They should have looked at the code. They should have run AI on the code... They should not have treated being a bitcoinner as a religion. Complete with priests and doctrine and mantras. But this is the thing... There was too much. Too much for the regular human. Almost none of us understand 1/10th of the cryptography bitcoin uses. Most "plebs" can't explain how a RNG works. But we all know how to say things like "stay humble" and "nyknyc". That's what I think "everything right" means. They trusted the priests. They taped the mantras to their dashboards. And they got hurt. Bad. The good news is bitcoin survives this. And life goes on. Not everyone can "be their own bank". But what has always mattered is not that you have to (do everything right) but that you CAN. My heart goes out to those hurt by this. And beware priests who cannot step down from their pulpits for a moment... With TRUE humility. PEACE
Matt Makes's avatar
Matt Makes 6 days ago
If you're looking to recover your Bitcoin. Paul Jon is the best man to meet to guide you through every recovery process and I highly recommend everyone to check him out. He is the BEST 🌟