انضم إلى نوستر
2026-08-01 18:23:48 UTC

mleku on Nostr: someone should build a dragnet for people to run a bitcoin mempool client that tracks ...

someone should build a dragnet for people to run a bitcoin mempool client that tracks the propagation of transaxtions spendinf these coins and attempt to determine the physical locarion of this scumbag and pool and publish the data. and run a massive number of tor nodes to catch them. ifMIT, i think it was, caufht Ross this way, we can do it too. and bring these pigs to justice. i am sure i know who is involved but hard data would allow a full prosecution of the whole gang.
⚡️🚨 RESUME - Nearly 1,200 Coldcard cold wallets were emptied, and $70 million in Bitcoin was stolen in just 41 minutes.

Yet the culprit never gained access to the victims’ devices, recovery phrases, or computers. He simply managed to reconstruct their seeds......

On July 30, an individual stole 1,082.65 $BTC—approximately $70 million—from 1,196 Coldcard wallets.

The funds were transferred in several batches to four addresses.
An attack carried out entirely offline
The attacker did not need physical access to the devices, as the problem stemmed from the way certain seed phrases had been generated.

A flaw in certain versions of the Coldcard firmware resulted in seed phrases that were far too predictable.

The firmware was supposed to use a hardware random number generator. Due to a misconfiguration, some devices used a software generator based, in particular, on the chip’s serial number and data related to its internal clock.
This information appeared random, but could in fact be reproduced or limited to a much smaller number of possibilities.

The attacker could generate millions of candidate seeds on their own machines and then calculate the associated Bitcoin addresses.
When a match was found, they obtained the same private key as the owner and could sign a valid transaction.

The compromised wallets used several Bitcoin address formats, primarily native SegWit.

Several generations of Coldcard devices may be affected, including the Mk2, Mk3, Mk4, Mk5, and Q, depending on the firmware used when the seed was generated.

The attacker reportedly left a trail by using a paid account with a blockchain data provider to verify addresses during the attack.
The recorded queries reportedly matched exactly the number, order, and timing of the drained wallets. This information has reportedly been shared with the authorities.

Coldcard confirms the vulnerability and recommends immediately transferring funds to another wallet.