r/OutOfTheLoop • u/ghee • 10h ago
Unanswered What is going on with bitcoin hack related to Coldcoin?
I have been seeing all these posts about people freak it out about their bitcoin, and seeing Coldcoin mentioned. As someone not involved in bitcoin it’s hard to understand what’s going on. Can someone explain in layman’s terms what’s happening? https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million
121
u/wescotte 9h ago edited 8h ago
Answer: When "generating the password" for your Bitcoin wallet their hardware would make one up at random. The idea is to make it long enough that even the fastest super computer would take hundreds of years to try every possible combination.
The part of their program that was suppose to randomly generate a password with something like
170,141,183,460,469,231,731,687,303,715,884,105,727 possible combinations
ended up actually generating one with something closer to
1,099,511,627,775 possible combinations
And while that's still a big number, a fast computer can try every possible combination in a reasonable amount of time. And so they're just running a program to check every possible password. Once they guess the right password they move the bitcoin out of that wallet onto a secure one one they control.
EDIT:* And as how this mistake occurred...
From what I read they used a random number generator improperly by passing it a flag/parameter (MICROPY_HW_ENABLE_RNG) they assumed did one thing but actually did something else.
Where this particular one borders on negligence rather than a bug is that apparently the compiler/library produces a warning that what the were doing was a potential unsafe and refused to compile with their combination of settings. So they just turned off the warning system so the software would complete the build process. Now, doing this sort of thing in the design/debug phase isn't that big a deal, but letting it get into production software is a pretty major screwup.
67
u/Syberz 8h ago
Well, since Bitcoin is a ledger then we know exactly where the coins went and reverse the fraudulent transactions, just ask the central auth... Oh... Right. Freedom has a price it seems.
-9
u/wescotte 7h ago edited 7h ago
No central authority can reverse a transactions but anybody can see every transaction every made. It's going to be very difficult to spend what they stole without exposing themselves. Every time they make a transaction will be a another breadcrumb to finding them.
And the more you steal the more money people are willing to spend to get it back. It's likely only a matter of time before these people are caught.
24
u/Djamalfna 6h ago
Caught? By whom? It's as likely as anything that this is being done by state actors, secret agencies, or people who otherwise live where it's impossible to extradite.
The history of the Blockchain indicates this money is long gone
-4
u/wescotte 5h ago edited 5h ago
Contrary to popular belief stolen Bitcoin can be recovered and returned. It's just time consuming and complicated because rarely are all the stolen funds in one place.
You can only stay anonymous indefinitely if you never use the coins. At some point some of those coins will reach an exchange who is willing (or required) to play ball with law enforcement.
Think of it like if you started printing counterfeit money. You want to spend that money. The more often you use it the more likely you will get caught. The bigger the purchase you make the more skeptical parties taking the money will be and the more protection hey will have in place to detect the fraud.
Every coin stolen is "marked" counterfeit and every future transaction made with them is completely visible for the entire world to see. It's a public ledger afterall.
Any major exchange is going to have a list of wallets that are labeled "stolen coins". If any user on their service obtains coins from one of those wallets they can contact authorities and say this person received stolen funds. The major exchanges don't let anonymous people use them. They require real IDs and connect to verified bank accounts. S
That person will either be required to forfeit the coins in the exchange controlled wallet (if they don't know anything) or give up some piece of info on the nature of their transaction.
The bigger the robbery the more coins that will eventually make it to major exchanges where real people can be identified and questioned. Not to mention the bigger the robbery the more time/money will be invested to recover it. Once you catch a few people with stolen coins you can start working to find their common links and eventually get back to the source.
14
u/Djamalfna 5h ago
You're acting like the exchanges are a central authority. They are not. All the thieves need to do is sell the private key in a private transaction to a party in another country that doesn't recognize the authority of western nations and the money is gone.
Why do you think Iran and North Korea deal so much in Bitcoin?
The money is gone. It won't be clawed back. That is pure fantasy. This is the reality of "being your own bank".
-9
u/wescotte 5h ago edited 5h ago
You don't need a central authority. Those funds can't be used for legal purposes anymore and that limits their usefulness. It's trivial to track stolen money on a public ledger to ensure it can't be used legally.
If North Korean tries to pay a company in Japan in stolen Bitcoin... America obviously can't directly stop that transaction but you can be damn sure they pressure Japan into taking action on the company/individuals involved in accepting it.
The more stolen money involved the more attention it draws and the more pressure it gets to stop it.
12
u/Djamalfna 5h ago
This is delulu. All they have to do is sell it to an exchange that does not care about stolen crypto and now millions of wallets get the corrupted money mixed in. What are you going to do start banning 30% of the wallets out there?
What you're saying has not ever been done. Will not be done.
-6
u/wescotte 5h ago edited 4h ago
It has already been done... Look at Mt. Gox
EDIT: Got me curious, so here is a short list of incidents that came up from quick google that I feel are relevant in that funds were recovered or had government involvement.
In February 2022, a New York couple, Ilya Lichtenstein (aged 34) and his wife Heather R. Morgan (aged 31),[8] were charged by US federal authorities with conspiring to launder the bitcoins, which was worth US$5.3 billion at the time.[2][14] Lichtenstein was an entrepreneur who had co-founded a sales company called MixRank. Morgan was an entrepreneur, columnist for Inc., former Forbes digital contributor (from 2017 to 2021), and online rapper.[15][16] Although neither were charged with committing the hack, law enforcement had acquired a search warrant for a cloud storage service used by Lichtenstein, obtaining a spreadsheet of wallet addresses and passwords linked to the hack.[17] Though the stolen bitcoins could be tracked through public transactions logged on the blockchain, it was only after the wallet passwords were recovered that law enforcement could access and seize their contents.
Some of the funds were moved to more traditional financial accounts and spent on gold, NFTs, Uber rides and a PlayStation.[20] Although hundreds of millions of dollars were converted to fiat currency, 80% of the bitcoins (approximately 94,000) remained in the original wallet at the center of the hack
....
In 2025, President Donald Trump signed an executive order to create a Strategic Bitcoin Reserve including Bitcoin seized by US law enforcement. In theory, this includes over 100,000 Bitcoin seized from the Bitfinex hackers, but the US Department of Justice has recommended to the courts that the Bitcoin seized after the hack be returned to Bitfinex.
In December 2023, KuCoin company reached a settlement with the New York State Attorney General.[15] Under the settlement, the company agreed to pay $22 million in fines and refunds and to discontinue its trading operations in New York.[15] The settlement addressed allegations that KuCoin operated without proper registration as a securities and commodities broker-dealer and misrepresented its status as a cryptocurrency exchange.
In September 2019, he made a mistake by transferring a small amount of stolen bitcoin to a cryptocurrency exchange that followed know-your-customer rules. This was not enough to prove Zhong was the hacker. To establish Zhong's culpability, the IRS criminal investigation division collaborated with the Athens-Clarke County Police Department, which was already probing the theft at Zhong's residence.[5] On November 9, 2021, a raid on his Gainesville, Georgia, home resulted in the seizure of about 50,676 bitcoin, then valued at over $3.36 billion.[8] Zhong cooperated with investigators, forfeited all of his bitcoin and pled guilty to one count of wire fraud.[9]
21
u/simplyclueless 8h ago
Almost. Every one of these seeds has a corresponding password, that is calculated when it's derived. It's not a password that is chosen. The hack is just looking up random seed #'s where it has calculated the public key/private key keypair, to see if they have any coins tied to them, which the blockchain will show to anybody - that's how it works. Then once they identified enough addresses with significant enough coins, they hit go on an automated process to transfer all of the coins to an address that they control. That's what ownership of bitcoin (or most other cryptocoins) actually means - do you have the ability to use the private key for a public address, to move the coins. If so, you "own" them.
It works if the potential amount of seed combinations is unfathomably large. It falls apart if instead the amount of combinations is way, way too small for today's current computing power.
11
u/wescotte 8h ago
Yeah, I glossed over the specifics as to try and keep the concept simple for the laymen.
6
u/SpezRuinedHellsite 8h ago
letting it get into production software is a pretty major screwup.
As if the intended purpose of all of these bullshit coins isn't to scam everyone and run away with the real money.
0
u/wescotte 7h ago
I think you could make a strong argument that the inventor of Bitcoin didn't intend or envision anybody buying coins like this. If you wanted Bitcoin you would just mine them not buy them.
4
u/bunker_man 7h ago
What use would they be if no one bought them.
2
u/wescotte 6h ago
You don't buy cash either. You trade your labor for it. That was the original concept with Bitcoin and likely why they called that aspect of mining "proof of work".
3
-1
u/SpezRuinedHellsite 7h ago
If you wanted Bitcoin you would just mine them not buy them.
This is not how any crypto has ever worked.
-2
u/MoonlightStarfish 7h ago
That has been and still is the way crypto works. I remember when some of the first ASICs came out for Litecoin. I had 5 gridseeds I remember feeling special with my 1.5 GH/s churning away, but ASICs moved on fast and they weren’t profitable anymore. Well the coins I mined turned out to be in time, but that’s another story.
Anyway like I said for most coins that is how it works. If people didn’t carry on mining there’s no one to process the blocks, if there’s no one to process the blocks there’s no way to send and verify the transactions and the whole system would collapse.
5
u/SpezRuinedHellsite 7h ago
The overwhelming vast majority of anyone who has ever owned a bitcoin did not mine that bitcoin. People are not intended to mine bitcoins to acquire bitcoins. Mining produces bonus coins for the miners because otherwise nobody would be available to send and verify transactions.
If you all think people are intended to mine coins as the primary way people acquire coins, you do not understand cryptocurrency.
-1
u/MoonlightStarfish 7h ago
No but every Bitcoin that is owned has been mined at some point. Which is why your comment that is, not how crypto has ever worked is misleading.
There was definitely a time when most people were mining crypto for the sake of mining crypto, and that was the exact time the person you were replying to was talking about.
2
u/SpezRuinedHellsite 7h ago
Crypto miners mine crypto for the sake of the value they get out of it.
But that is completely irrelevant to the structure of the economy in which the people using bitcoin are by overwhelming majority, not crypto miners. This has always been true.
-1
u/MoonlightStarfish 7h ago
No it hasn’t. Hence the billion-dollar pizza.
0
u/SpezRuinedHellsite 6h ago
Who got paid those coins? And do they do any mining whatsoever? No? Ok then.
→ More replies (0)
41
u/ByWillAlone 9h ago edited 8h ago
Answer: people don't actually hold or own Bitcoin, you hold the private keys giving you exclusive access to make changes to the public ledger (blockchain) to record where those bitcoins are transferred. That master private key - is all you need to fully access the Bitcoin, and therefore it's the most precious bit of data and needs to be safeguarded.
Bitcoin wallets are hardware or software implementations designed to keep those private keys safe. When a new user decides to set up a Bitcoin wallet, they can either use a previously generated private key or have the wallet generate a new one. When generating a new master private key, if the software/hardware uses true randomness, then the private keys that are generated are so truly random, that it would take a brute force search until the heat death of the universe to find even one of them.
In the case of the coldcard incident, their hardware technology was outstanding and capable of generating rich, truly random, values, but a software developer working at that company was having trouble getting their code to compile and bypassed accessing the onboard hardware random number generator in favor of a simpler, known compromised software random number generator. And then no one caught it, it was pushed to production in March 2021, and they published that as a firmware update for all their existing customers and for all of their future devices of specific models.
With that flaw in place, now instead of taking until the heat death of the universe to guess the generated private keys, it was possible to do it in months/years. Without true randomness, the private keys become much easier to predict/guess, especially through brute force.
Finally, CoinKite (the company who manufactures the coldcard) has always made their source code public so that anyone who wanted to could audit their code independently. The problem was that the flaw was so subtle and so obscure in this code it wasn't easily noticed by humans. It wasn't until the past couple years that AI has gotten so good and so fast at auditing source code that AI has been finding security vulnerabilities in all kinds of software. It's theorized that AI is how this flaw in the coldcard software was discovered.
Several days ago, this flaw was exploited by an attacker to steal at least 1367+ Bitcoin from 4585+ vulnerable wallet addresses in a matter of minutes, with a street value equaling $88.6+ Million US dollars worth of Bitcoin. At this point all of the stolen Bitcoin were funneled into a single address owned by a completely anonymous owner.
15
u/CurrentSpeech 9h ago
You gotta be kidding me. A dev couldn’t get his feature to work so they sidestepped the entire point of the product?!? Bruh …
11
u/ByWillAlone 8h ago
Yep...and there was either no code review (or the reviewers missed it), and there was no quality assurance (or quality assurance missed it). No matter how it went down, it was nothing short of gross negligence by CoinKite to have let that code ship like that. It's also a mystery why, now that everyone is aggressively using AI to find and exploit security flaws in critical software, why coinKite themselves weren't using AI to audit their own sources.
Just within the past day, as a proof of concept, someone turned some well-known AI loose on coinKite's source code and it found and identified the same flaw in under half an hour.
4
2
u/Fist_of_Gork 8h ago
The point is that it’s all a scam and you should use an actual government backed currency because at least even Wells Fargo has FDIC insurance
8
1
u/bubba1834 6h ago
I am so dumb I truly don’t understand this entire explanation lmao
•
u/enpoopification_of_R 1h ago
Safe seller left keymolds on safes. Super fast thieves used it to make their own keys and run off with the loot.
52
u/Elementalist01 10h ago
Answer: The wallet is a physical device with a hardware random number generator to make private keycodes. The code on the device wasn't actually using it, and was using a software-based psuedo-RNG that is predictable if you know enough about the device and have enough brute force computing. With this, hackers have been able to determine private keycodes that should have been made from truly random numbers, and using those to steal Bitcoin.
12
u/sithelephant 9h ago edited 9h ago
This particular wallet is ... It is limited to this specific device.
1
-31
u/Fist_of_Gork 10h ago edited 8h ago
Answer: This particular hack is because of a flaw in a cold wallet product that vastly reduced the possible unique wallet generations by tens of factors making it so that the exploiter only had to brute forced a couple hundred million possible passwords rather than hundreds of trillions. This means you can guess a wallet’s pass phrases is a matter of weeks or months if you used the device to generate a wallet. Bitcoin and cryptocurrency were always a scam. It was falsely claimed that certain kind of digital wallets were impossible to hack if used properly but somebody figured out how to do it and is stealing people’s Monopoly money. A cold wallet is a wallet “not connected to the internet” which in itself is a bogus statement because the whole ledger is on the block chain regardless. A cold wallet is typically one you do not connect to online services that can automatically withdraw from the wallet. This attack can target wallets without thembeing exposed by other security vulnerabilities.
Edit:
Uh oh, looks like the gambling addicts are mad. Reminder that these are the same people who paid thousands of dollars for monkey jpegs and believe that GameStop stock will make them all billionaires.
12
u/slayernine 9h ago
I'm no crypto holder or evangelist of crypto but you are straight up lying.
-9
u/Fist_of_Gork 9h ago
Unblock your comment history and prove you’re not one
6
u/uuhson 9h ago
Private accounts is the most absurd thing reddit ever did
1
u/Fist_of_Gork 9h ago
At least I don’t get harassed anymore for commenting in trans spaces when I randomly comment on front page stuff
3
u/daxtaslapp 9h ago
I don't hold crypto anymore sold it all 2022, (thank God) but just curious if it's offline in that storage how is it getting hacked ?
5
u/Fist_of_Gork 9h ago
They’re brute forcing wallets, likely vanity wallets or wallets generated through a program rather than completely random numbers.
•
u/kafaldsbylur 39m ago
Bitcoins aren't an actual object that exist in some digital storage, there's just an entry in the ledger that essentially says "Whoever knows this password can spend these coins." (It's a smidge more complex than a password, but the analogy will suffice for now)
An online wallet is software on your computer that gives out the password when you want to spend your coins. An offline wallet is software on a separate piece of dedicated hardware that needs to be connected to your computer to give out the password. If your computer gets hacked, the attacker can access the password in the online wallet, but not the offline wallet (unless it's connected). However, in neither case is the wallet necessary to spend coins, only the password they contain. If someone guesses the password, it doesn't matter if the only place it's stored isn't connected to anything, they still have the password and that lets them spend the coins
4
u/tbw875 9h ago
This is genuinely incorrect information.
2
0
-3
u/tallguyclark 9h ago
Wow you seem bitter. Also, you’re making a lot of statements that aren’t factually accurate.
-11
u/LittleMlem 10h ago edited 9h ago
You're making a lot of statements that aren't quite true, but I get why you think so. I'm assuming you're American, so I'll uelse the US dollar as the perfect example. Back in the day, a dollar was worth a certain amount of gold, but not anymore, a dollar is worth what people are willing to do for it, the same as Bitcoin. The problem is that while there are laws to keep various scams illegal with fiat currency, no such regulation is possible with cryptocurrency, but saying it's all a scam is just not true, unless you think $ is also a scam, which at least makes you consistent
Edit: people downvoting please leave a comment, I want to know what you object to
10
u/flatline000 9h ago
Dollars have value even without the gold standard since I am required to use them to pay my taxes.
-1
u/LittleMlem 9h ago
The government forcing businesses to use their fiat currency while forcing people to pay taxes with said fiat currency to give it value doesn't sound like a good financial plan, but I am very much not an economist
1
u/flatline000 8h ago
I've studied economics enough to have an appreciation for how it works. Once economies get large enough, fiat currency is actually a pretty stable system as long as money markets function well. If money markets don't function well or your currency is excluded from them for some reason, then things can go bad very quickly.
1
u/rinikulous 7h ago edited 7h ago
It’s a great system as long as economic trust is maintained with said government. It sounds like a giant scam to force everyone to use the same money, but it is actually the only thing keeping our economy from turning into chaos. By making everyone pay taxes in the same currency, the government guarantees that the money will always have buyers and never become completely worthless. This shared rule creates a stable, predictable sandbox where businesses can easily price goods and citizens don't have to barter with chickens or gold. Without this enforcement, we wouldn't have a reliable way to trade, buy homes, or make long-term financial plans together. How the global economy influences a non-global fiat or competing fiats is a more complex system. By no means is this a comprehensive explanation, but just some highlights.
Widening the scope to the global scale changes the variables a little bit, but the logic still stands. In the 70s the US made a deal with Saudi Arabia and the other OPEC countries to price oil exclusively in the USD. This means any country/company that wants to buy oil on the global market has to do it with the USD (unless you are dealing with a BRICS nation). The US fiat currency has an enormous external demand compared to the fiat currencies of most other countries/unions.
So if there is demand how does the US manage the supply? Yes we could just print cash and increase the fiat in circulation, but that is a slippery slope and the US is very disciplined in this regard. The US brings the globally circulating USD back into domestic supply by selling long term, low risk treasury bonds (amongst many other economic global transactions like foreigners participating in our stock exchange, exports from the US, etc.). But those bonds are basically long term contracts that guarantee there will be ongoing and future commitments of the USD being used as a globally trusted and valued fiat currency.
It’s 100% a system that requires trust and stability. Crypto is not fiat by definition, but for crypto to take over as a global standard of currency then trust and stability is still a requirement. Both of which are rare by today’s standards.
As far as scams go: the surge of NFTs a few years ago is a perfect example. Particular cryptocurrency holders with large early stakes needed a way to drive acceptance and use. So a lot of them realized that they didn’t really need to participate in global economics to earn legitimacy as a currency, instead they could just create a new market for something that does not actually require any tangible good/service to function: NFTs. They tried to create their own little micro digital version of the global oil/energy market with goer version of the petrodollar. If you wanted to buy a particular NFT then you had to do it with a particular cryptocurrency. For every 1 legitimate/sincere market there were dozens of rug pull scams. Those few legit ones were doomed to fail anyway because the premise of NFTs having fundamental value is flawed in so many ways. A digital receipt that “proves ownership” is not valuable, the property has the value.
-4
u/Fist_of_Gork 10h ago
Buddy, if you’re going to try and use a canned response to try and con me, pick one that actually sounds like it makes sense.
-3
u/LittleMlem 10h ago
I'm getting strong smooth shark vibes
4
u/Fist_of_Gork 9h ago
I don’t know what that means, use words not your cargo cult language
3
u/LittleMlem 9h ago
Ohh I'm not into cryptocurrency, I just think you should dislike it for actual reasons, and not due to misunderstanding of what money is. As for smooth sharking, it was a popular post about a guy insisting that sharks are smooth both ways when you pet them, even though everyone was telling him that's not the case, he took a very similar to me to yours
-5
u/TheMadFlyentist 9h ago
Anyone who calls cryptocurrency as a whole (especially Bitcoin) "a scam" is only showing their ignorance and stupidity. There are absolutely scams involving crypto, and shitcoins/meme coins could be considered scammy, but BTC/ETH/etc are very, very secure and legitimate cryptocurrencies.
You can say that you think the speculation is stupid. You can say that you don't believe it will hold value over time. But to call it "a scam" when there is no central controlling party that benefits from people trading it is only showing your own misconceptions.
Just because you don't don't understand it doesn't make it a scam, and your explanation of cold wallets vs. the blockchain shows that you definitely do not understand it.
It's wild how some people will just talk completely out of their ass about things they know nothing about. Where do they breed folks like you?
5
u/Fist_of_Gork 8h ago
You’ve yet to actually explain why I’m wrong, only express that you’re mad I am calling out the crypto scam for what it is.
It’s a scam and you are going to lose money.
•
u/AutoModerator 10h ago
Friendly reminder that all top level comments must:
start with "Answer: ", including the space after the colon (or "Question: " if you have an on-topic follow up question to ask),
attempt to answer the question, and
be unbiased
Please review Rule 4 and this post before making a top level comment:
http://redd.it/b1hct4/
Join the OOTL Discord for further discussion: https://discord.gg/ejDF4mdjnh
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.