Skip to content
Archive

Post

Back to deliverables

C zio1897
Ciccio ₿
@zio1897

if you were a victim of the Coldcard hack This would be a good start to recording your attack. I’d wager you’ll get your coins back in a year or so. If the Clarity Act passed and it will PASS. You’ll get DOJ and FBI finding the hacker(s) The hacker(s) would be far better off returning these funds & charging an audit of 5-10% exposing the vulnerability because if these coins get spent they’ll be tracked anyway

@

The COLDCARD RNG vulnerability may be worse than an exchange hack. It hit at the core of sovereign Bitcoin holders - it struck those who did all the research, understood why self-custody is important, and didn’t keep coins on exchanges. My heart goes out to everyone affected. It’s a horrible situation and the damage is irreparable. While I have many thoughts and criticisms about how we got here, I’ll hold back because I know nvk is devastated too. Self-custody is hard. If you advocate for self-custody, you should also be telling people to use a multi-vendor multisig setup. I’ve been saying this for years. Self-custody only works if you do it in a way that minimizes a single point of failure. Don’t trust any single vendor for hardware. Assume everyone is your adversary. As self-custody is hard, we should be less critical of people who chose to use custodians or hold BTC in ETFs or Bitcoin Treasury Companies. There isn’t a single right or wrong way to use Bitcoin and there are tradeoffs everywhere. Some people have contacted me about what to do. Here’s what I recommend: 1️⃣ Document everything. Write down all the facts and details you know (dates, addresses, firmware, etc.). 2️⃣ File a police report, as it creates an official record which is useful for a number of reasons. Even better if you can contact a cybercrime unit, national reporting portals (e.g., FBI IC3 in the US), or specialized crypto-crime task forces if they exist. 3️⃣ Watch for coordinated efforts to track movements of funds. 4️⃣ Do not destroy your COLDCARD and seed phrase. Hold onto them as there could be a chance that stolen funds reach an exchange, are frozen, and you need to prove ownership. Write down your PIN too, or note it in your documentation. When you stop using it for a long time, you may forget it. 5️⃣ This next point is very important: DO NOT share your personal details, seed phrase, or send any money to anyone claiming they can “help recover” the funds. Scammers will be targeting people who are desperate. Just know that almost everyone has lost coins for some reason at some point. Don’t do anything rash. Talk to someone if you need to. You can always rebuild, but only if you’re still here. For all of us developing wallets, software or hardware, security is the most important thing we provide. People are counting on us and we have to do better. 💔

· 154 Views

replies reposts likes
0 replies collected

No replies

X reports zero on this post too.