به Nostr بپیوندید
2026-08-01 22:29:03 UTC

Sooly⚡️سولي 🇱🇧🇧🇪🇦🇪🇦🇴 on Nostr: Non Technical Plain English Update: the Coldcard incident appears far bigger than ...

Non Technical Plain English Update: the Coldcard incident appears far bigger than first reported.

The early 594 BTC figure now looks like only the first visible wave.

The current observed on-chain estimate is about 1,367 BTC across 4,585 addresses in 3 waves.

That does not yet prove every case is tied to the same actor, or that every wallet has been publicly proven case by case. But the risk is clearly bigger than many first thought.

Plain English:

A hardware wallet is supposed to create a secret key so random that nobody can realistically guess it.

A firmware bug meant some Coldcards generated seeds with far less randomness than intended.

That allowed an attacker to calculate likely keys offline, compare them against Bitcoin addresses visible on-chain, and drain funds without touching the device.

If you use a Coldcard, the message is simple:
- Update to fixed firmware
- Do not trust the old seed
- Generate a completely new seed
- Verify backup, fingerprint, and receiving address
-Send a small test transaction
- Then migrate the rest carefully

Important:

Updating alone does not fix an old weak seed

A weak seed remains weak forever

50+ private dice rolls materially reduced this specific risk

A strong BIP39 passphrase helps, but migration is still the prudent move

Multisig helps only if enough keys were generated independently and securely

The hard lesson:

An air gap can protect a strong key.

It cannot rescue a weak key created at birth.

Share this with anyone using a Coldcard.