▲ 167 r/BitcoinCA+1 crossposts

Plot Thickens with ColdCard Hack "No researcher I have spoken with has reproduced a seed for any of those 153 source addresses [containing 132.95 BTC]…"

https://x.com/PraveenPerera/status/2087936252230140278

>This post answers three questions:

>Why were these wallets vulnerable?

>What can be reconstructed from the blockchain?

>What does that reconstruction tell us about the attacker?

>I’m the developer of

>Cove

>, an open-source Bitcoin wallet for iOS and Android funded by

>OpenSats

>. This article goes through my investigation into Wave 1.

>This post was originally published on

>my blog

>Between 9:10 and 9:51 PM EDT on July 29 (01:10–01:51 UTC on July 30), an attacker swept 1,082.65 BTC from 1,195 traceable Bitcoin addresses.

>Galaxy Research reported

> the theft on July 31. I use Wave 1 throughout this post for that first sweep group.

>The sections follow that order. The post first explains the firmware defect, then reconstructs the theft from chain data, and then examines the attacker’s methods and the open gap.

>I set out to recreate the affected firmware’s seed-generation process and find as many weak seeds as I could behind those addresses. The sweep transactions became a second source of evidence. Patterns in their targets and spending show how the attacker searched the weak RNG state, selected victims, and built the sweep transactions.

>Galaxy listed four destination addresses. I grouped those destinations into three source branches and used them to build the transaction set for this analysis: 1,195 verified victim sweeps with 2,350 inputs containing 1,082.65318922 BTC.

>Once I had recreated the affected seed-generation process, I generated candidate seeds, derived their Bitcoin addresses, and compared those addresses with the Wave 1 transaction set. This linked 1,042 of the 1,195 sweep transactions to 328 reconstructed seeds. They account for 949.70395260 BTC, or 87.72% of the value. The final 153 transactions contain 132.94923662 BTC.

>No researcher I have spoken with has reproduced a seed for any of those 153 source addresses. That repeated failure may be the most useful clue about what the attacker knew or did differently. The last part of this post examines that gap.

continued on... https://x.com/PraveenPerera/status/2087936252230140278

x.com
u/Fiach_Dubh — 5 days ago

2026 Canadian Bitcoin Conference Postponed until 2027

>Hey everyone,
Unfortunately, due primarily to the ongoing bear market, we are postponing the Canadian Bitcoin Conference and Industry Day this year.
This was a difficult decision. With many companies and sponsors under pressure and conference attendance significantly down across the space, we don’t believe we could put on the high-quality event our community deserves.
If you have already purchased a ticket, you will be fully reimbursed in the coming days/weeks.
This bear market has been especially tough on Canadian Bitcoiners. We hope that when conditions improve we can bring everyone together again next year.
Thank you for your continued support.

Organizers for the Canadian Bitcoin Conference

https://x.com/CdnBitcoinConf/status/2087648940380549456

reddit.com
u/Fiach_Dubh — 7 days ago

"This FTX claims broker is now courting victims of a $155-million hack of a Canadian bitcoin firm" - The Globe and Mail

archive.ph
u/Fiach_Dubh — 12 days ago

PSA: Advice Regarding the Coldcard Bug - Exploit - Hack - Theft

I’m just going to write, this won’t be polished.

If you have/use a coldcard MK3 without a passphrase, that wasn’t setup with 100+ dice rolls, you need to move your funds out of that coldcard as soon as possible to safe harbor.

If you have/use a coldcard MK4/5/Q without a passphrase, that wasn’t setup with 100+ dice rolls, you need to move your funds out of that coldcard sooner then latter to safe harbor.

If you have/use a coldcard MK3/MK4/5/Q with a passphrase and/or that was setup with 100+ dice rolls, you have more time. It could very well be safe for the long term too, but you’d be wise to migrate to safer harbor eventually.

If you use any of these devices and forget what your setup is, you need to move to safe harbor as soon as possible.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

What is safe harbor at this point in time? For MK3’s with no passphrase/no dice – literally anything else. Hot wallets are better in this moment in time (blue wallet, sparrow wallet). Exchanges are also an option. Adding a 16 character passphrase on top of your Mk3 wallet is also an option and helps. Another hardware wallet from a different vendor is better too. Anything else is better at this moment. Your funds are at severe risk in a mk3 here. But none of these safe harbours are long term solutions, they’re short term safety nets for an extreme situation. Consider your safe harbour options carefully and pick the strongest one for your situation.

Safe harbor for the MK4/5/Q’s with no dice/no passphrase is the same situation to be honest. Get it off somewhere else, anywhere else.

Before moving to hot wallets/exchanges please consider if you have other more secure options available. A spare hardware wallet from another vendor, trezor, ledger etc might be better in this moment too.

Ideally for everyone else not in the extreme conditions, migrating away from coldcard eventually is probably wise here for several reasons I won’t get into yet, but are probably obvious. A 2/3 Multisig setup from multiple different hardware wallet brands is ideal long term, and guards against this attack/bug. Seedsigner, Krux, Trezor Model 5 Bitcoin only version, are good options to consider for such a multsig arrangement at this point in time. I don’t believe it wise to reuse coldcards for long term storage even if updated at this point in time. This article (link below) is a good follow up on entropy generation offline with analog methods. This guards against this coldcard attack/bug.

https://btcmaxis.com/article.html?id=7554e7cb-d8aa-45d5-95c8-adea8d87ea23

u/Fiach_Dubh — 18 days ago
▲ 1.7k r/BitcoinQRCodeMaker+3 crossposts

The Coldcard wallet exploit estimates have almost doubled to $70 million stolen of just over a thousand Bitcoins in 1,196 wallets drained in 41 minutes

"More than 1,000 bitcoin, worth about $70 million, was drained from 1,196 wallets in a 41-minute window on July 30, nearly double the amount reported when the theft first surfaced."

coindesk.com
u/BitcoinDove — 19 days ago