#ColdcardSeedAlert

2,2 M espectadores|907 publicación

About ColdcardSeedAlert

After the Coldcard firmware flaw was set off en masse on July 30, losses have risen to ~1,367 BTC, about $88.6M, the year's largest Bitcoin theft. Galaxy's Alex Thorn warned Aug 3 a suspected fourth wave is still underway. Root cause: the vendor misrouted seed generation to a software PRNG, a single-vendor flaw, not a self-custody failure. Best move: check affected models and firmware, migrate funds, spread risk. Until the fourth wave is contained, treat assets on affected devices as exposed.

Cripto relacionadas
BTC
-2,05 %

ColdcardSeedAlert Publicaciones populares

Bella Ryan
Bella Ryan
🚨 Un fallo de seguridad. Más de 40 millones de dólares en Bitcoin desaparecidos. Se informa que más de 40 millones de dólares en Bitcoin han sido robados tras el hackeo de la cartera de hardware Coldcard, lo que genera nuevas preocupaciones sobre la seguridad en las criptomonedas. El incidente es un recordatorio de que la autogestión no se trata solo de poseer una cartera de hardware, sino de asegurar cada parte del proceso, desde dónde compras el dispositivo hasta cómo proteges tu frase de recuperación. Ya sea que tengas 0.01 BTC o 100 BTC, la seguridad nunca debe ser una idea secundaria. A medida que surjan más detalles, este podría convertirse en uno de los incidentes con carteras de hardware más vigilados en los últimos años. 👀 ¿Crees que esto cambiará la forma en que la gente almacenará su Bitcoin en el futuro? #DailyOrbit
CRYPTO_NIGHTMARE🌑
CRYPTO_NIGHTMARE🌑
La mayor noticia cripto de hoy: ¡El ataque a la cartera hardware de Coldcard ha agotado ahora ~89 millones de dólares (1.367+ BTC) de más de 4.500 direcciones. El atacante nunca tocó los dispositivos: simplemente forzó bruscamente frases semilla débiles fuera de línea debido a un error de entropía del firmware. Primera oleada: 41 minutos y más de 1.000 BTC desaparecidos. Si tienes una Coldcard (especialmente Mk2/Mk3), actualiza el firmware AHORA, genera una nueva semilla y mueve tus fondos inmediatamente. La autocustodia está siendo atacada de nuevo. #Bitcoin #Coldcard #CryptoSecurity #BTC No te quedes esperando. Actúa ahora. 🛡️ $BTC
Felix.Crypto
Felix.Crypto
La falla en la semilla de Coldcard sacude la confianza mientras $BTC entra en una prueba crítica $BTC está entrando en una de sus pruebas de estrés más importantes de 2026. La falla en la semilla de Coldcard recientemente divulgada ha generado serias preocupaciones en todo el ecosistema de Bitcoin tras vincularse una vulnerabilidad de firmware en ciertas carteras de hardware Coldcard con robos masivos de fondos. Aunque se ha lanzado un parche de seguridad, las carteras creadas con el firmware afectado siguen siendo vulnerables a menos que los usuarios transfieran sus activos a frases semilla recién generadas. Esto es más que un problema de cartera de hardware: es una prueba importante de la confianza del mercado. En un momento en que $BTC ya está bajo una fuerte presión de venta, el incidente de seguridad ha añadido otra capa de incertidumbre para los inversores. Sin embargo, es importante entender que la vulnerabilidad no afecta a la red de Bitcoin en sí. El problema se limita al proceso de generación de la semilla de la cartera, mientras que el protocolo de Bitcoin permanece seguro e inalterado. La historia ha demostrado que eventos como este suelen desencadenar volatilidad a corto plazo pero también separan la convicción a largo plazo del miedo a corto plazo. Si los compradores continúan defendiendo niveles clave de soporte, la corrección actual podría evolucionar hacia una fase de acumulación saludable antes del próximo ciclo alcista. Por otro lado, no mantener el soporte podría acelerar el impulso a la baja y aumentar la volatilidad del mercado. Por ahora, los inversores deberían centrarse no solo en la acción del precio de $BTC sino también en la restauración de la confianza tras uno de los incidentes de seguridad de carteras de hardware más significativos en los últimos años. En el mundo de Bitcoin, proteger tus claves privadas es tan importante como tomar las decisiones de inversión correctas. #ColdcardSeedFlaw #BTCSecurityAlliance #OKXOrbitTopics $BTC
kangmin
kangmin
¿Y si la comunidad de Bitcoin se negara a dejar que los hackers ganaran? En lugar de esperar años por justicia, podríamos actuar ahora. Una propuesta para las víctimas de Coldcard: 🟠 Crea un fondo de BTC financiado por la comunidad para comprar las reclamaciones sobre las monedas robadas. 🐋 Las ballenas y los seguidores pueden contribuir. ⚡ Las víctimas recuperan su BTC inmediatamente en lugar de vivir en la incertidumbre. 🔒 Si los fondos robados se recuperan, las reclamaciones se devolven con el tiempo. Bitcoin siempre ha sido una cuestión de soberanía propia, pero también es una comunidad que se mantiene unida cuando importa. Estaría encantado de donar BTC para ayudar a arrancar esto. #DailyOrbit
isa⚡️
isa⚡️
🚨 Carteras de hardware Coldcard — Qué está pasando La versión corta: Varios dispositivos Coldcard (Mark 3, Mark 4, Mark 5 y Q) tenían una falla de seguridad donde la aleatoriedad usada para crear tus claves de Bitcoin era débil y predecible. Esto significa que los atacantes podrían ya conocer tu frase semilla — tu clave maestra de 12-24 palabras — y están trabajando para vaciar las carteras ahora mismo. ¿Estás seguro? Revisa estas 3 cosas Probablemente estés bien si hiciste alguna de estas cosas al configurar: ✅ Lanzaste dados al menos 50 veces para generar aleatoriedad extra ✅ Añadiste una frase de contraseña fuerte — es decir, palabras o caracteres verdaderamente aleatorios, no algo como "bitcoin" o una frase ✅ Generaste tu frase semilla en otro lugar y solo la importaste al Coldcard Si no hiciste nada de eso — ¿qué tan urgente es? Muévete inmediatamente — Cartera Coldcard única sin protección extra. Los atacantes ya están probando combinaciones. Es cuestión de tiempo. Muévete con urgencia — Añadiste algo de protección pero fue débil (menos de 50 lanzamientos de dados, o una frase de contraseña simple como una palabra o frase). Muévete pronto — Usas varios dispositivos juntos (multisig) y dos de ellos son Coldcards. Tus fondos aún no se han ido, pero el riesgo es real. Prioridad baja pero aún así arréglalo — Coldcard es solo una minoría de tu configuración y otros dispositivos son seguros. Tienes tiempo, pero reemplázalo. ¿A dónde deberías mover tus Bitcoins? Recomendaciones de Rob: - River — una empresa confiable solo de Bitcoin, incluso puedes congelar tus propios retiros - Bitkey (la cartera de Jack Dorsey, vendida en Best Buy) — amigable para principiantes - Casa — bueno para personas que quieren más control pero con ayuda - Unchained — bueno para custodia avanzada Conclusión Si tienes un Coldcard y no añadiste lanzamientos extra de dados o una frase de contraseña aleatoria fuerte cuando lo configuraste — trata esto como urgente y mueve tus Bitcoins a una nueva cartera ahora. ¿Tienes un Coldcard?
Rob Hamilton 🟥
Rob Hamilton 🟥
The most common question I am getting right now in the fall out of the news of COLD CARD MK3, MK4, MK5 and Q having compromised entropy, is: "Rob, what would you do right now if you were in my shoes? Where would you send your bitcoin to be safe?" I will share with you my list of what I would do, but first, there is AN URGENT SECURITY ADVISORY IN THE BITCOIN ECOSYSTEM. Below is my personal assessment of the situation. If you or someone you know: Uses an MK3, MK4, MK5, or Q in a single signature OR A multi signature wallet where the cold card devices can move the funds on their own (Example, 2 cold cards and a Ledger). Please continue reading. You may be in danger. If this does not apply to you, keep on reading if you like, but you are not impacted by this issue. If you are still here, there are three identified mitigations that protect you at the moment. They are all different forms in which you may have brought your own entropy. A: DICE - This is done by either rolling dice from the start, or adding dice rolls to the generated seed phrase. At least 50 dice rolls would be my threshold at 128 bits of entropy. OR B: PASSPHRASE - You used a passphrase of sufficient entropy (128 bits). 128 Bits of entropy pass phrase examples include RANDOM combinations of the following: - 12 BIP 39 seed words. - 10 common words in the english language - 25 mixed lower case letters and numbers - 20 if you use ASCII characters Note on pass phrases: This does not include the same word 12 times, 10 words in a sentence, etc. This combinations of characters/numbers OR words should never have been seen or spoken before in the total sum of all human knowledge and experiences. It needs to be RANDOM for it to be entropy. OR C: EXTERNAL ENTROPY - Your seed phrase was derived entirely outside of the cold card ecosystem. (It was imported into the cold card, not generated on it) Now, if you are still reading, and you do not have any of these mitigations in place, you need to move your funds. The urgency of circumstances are as follows: TIER 1: AS SOON AS POSSIBLE Scenario A: If you are in a signature wallet with an effected device, and did not use any of the mitigations listed above. You need to move funds right now. Find someone to help you, any moment your funds can be stolen. Scenario B: If you have an N of N (eg 2 of 2, 3 of 3, etc) multisig of just cold card devices that did not have mitigations listed above (dice and/or passphrase). Attackers will be grinding all of the combinations of compromised keys. They know all your seed phrases. You are compromised. It is just a matter of time for them to assemble the puzzle pieces together and steal your funds. If this scenario is you, I will have more below on how to mitigate risk when broadcasting your transaction. TIER 2: URGENTLY If you are in a single signature wallet with an effected device, and you used either less than 50 dice rolls OR a pass phrase less secure than what I shared above. The entire security of your bitcoin is reliant on how much of Dice AND Passphrases you applied to your wallet. Attackers know your seed phrase. Your entropy from dice or pass phrase is the only thing protecting you. Did you add a pass phrase of 'bitcoin'? You are basically in tier 1. Did you use 6 words? You are not at tier 1, but you aren't safe. You need to make plans to move funds quickly. TIER 3 SOON, BUT IMPORTANT CONTEXT: You have a multi signature wallet where the compromised devices have sufficient ability to move the funds. An example is a 2 of 3 multisig where you have 2 cold cards and another signer. The issue with Tier 3 is that an attacker may have already figured out your insecure seed phrases. This means when you broadcast your bitcoin transaction, an attacker in theory can then steal your funds. NOTE: IF YOU ARE IN THIS SITUATION, AND YOU HAVE REUSED ADDRESSES, ALL REUSED ADDRESSES PUT YOU RIGHT BACK AT THE TIER 1 MOVE RIGHT AWAY YOUR FUNDS ARE AT RISK AT THIS VERY MOMENT You should look into finding a way to use the @MARAFoundation_ slipstream service, which uses a private mempool. This means that by the time an attacker could see your attempted recovery, it is already in a block and not possible for them to steal funds. TIER 4: KEY ROTATION. This is where you have an insecure cold card(s) in your multisig quorum, and you know that the other keys in your quorum are not impacted by this bug. If there is a MK3,MK4,MK5 or Q in the quorum, BUT they either: 1. Rolled sufficient dice (50 min) 2. Have a strong pass phrase (as defined above). 3. Used entropy not sourced from the device, they are not impacted by this bug in the Cold Card (see notes earlier on mitigations). You are in a position where a minority of your keys are compromised. Funds are safe, but you are at reduced security. Make plans when you are able to remove the compromised device from your wallet. Now. With that security advisory out of the way, back to the question, what would I do in this situation? Below is just my opinion, but you should not rely on only my opinion, you will have to make your own choices based on what you feel is best for you. I want to be clear, if you are not on this list. It is not that I think your product/business is bad, insecure or at risk, I am directly answering the question of what I would do. This is my personal judgement given my decade of experience in bitcoin. First, a disclaimer: My bitcoin is at my company @AnchorWatch. I have full skin in the game in that if I'm offering a custody solution, there will never be another place I store large amounts of bitcoin long term for myself or my family, and it will be this way as long as I am here. I was the first bitcoin that went on our Trident Vault platform. If the day ever comes, I will be the last bitcoin to leave the platform. The years of what we built at AnchorWatch were for exactly moments like this. Avoiding catastrophic risk of ruin scenarios. We offer 2 products: 1. Our Flagship Product where you as the customer can hold 1 or 3 keys, and we act as a cosigner. We leverage bitcoin native smart contracts which allow for your bitcoin to have different ways it can be spent across time. 2. Multi Institution Custody, where we let you distribute your keys across 3 institutions of ourselves, @bitgo and @CoinCorner. 2 of the 3 institutions must sign off on the transaction, and you have to present a Yubikey signature before withdrawing to mitigate deepfake and compromised accounts. For both products as, since we are a cosigner, we are able to enforce rules like whitelisted addresses, and velocity controls (how much bitcoin can you send how often). You can even disable the send button on the platform if you so choose! We also offer 1:1 insurance backed by Lloyd's of London. If you want to learn more about what we do, hit up @_joerodgers or @BeccaAmilee to learn more, or check out our website. Now with that out of the way, places where I'd leave my bitcoin (besides @AnchorWatch) in no particular order: Custodian: I'd trust my life savings at @River under a duress situation. This is one of those times. @Leishman and the entire team at River are elite operators. It is my favorite bitcoin services business in the market today outside of my own. They own their own custody infrastructure, and at times like this, you want those who have extreme ownership and control over how their customer's money is being managed. @River does monthly proof of reserves, and you can turn on the force field feature which will freeze withdrawals of bitcoin. They have a world class custody team as well, and are making improvements regularly with a larger upgrade that has been planned for a long time, happening later this year. Collaborative Custody: 1. The @Bitkey is an incredible product with an elite team of engineers supported by the @BlockEng organization. They have exceptional bitcoin developers across @spiral_xyz and @CashApp teams who deeply understand Bitcoin. @jack has been a long time believer in bitcoin who has built an organization that has no peer in the resources they have not just understanding bitcoin, but building on bitcoin. You can pick it up a Bitkey at best buy today! I do want to add a disclaimer that all keys are managed within the Bitkey ecosystem. The Bitkey team has gone to great lengths to keep things secure, but in light of recent events, I want to call that out. At the moment, the Bitkey is my only exception to a purist ideal of multi vendor multisig (more below). 2. @CasaHODL - @Nneuman and @lopp have been on top of this incidence response, and have built a very clean user experience to let people be safe. You can either use a 2 of 3 or 3 of 5 multisig with a great mobile app. Casa is the best UX for soverign collaborative multisig that exists in the market today. 3. @uncahined - Unchained pioneered the collaborative custody model and the multi institution custody model. They have been working around the clock trying to support customers and have even been able to use slip stream going the extra mile on short notice to keep customers bitcoin safe. Self Custody: I have spent close to $5k on LLM tokens over the past 24 hours scanning over a hundred bitcoin related repositories. As of now, I have seen no vulnerability that has me concerned about any hardware device outside of the Cold Cards. Even so, you can't be sure. So I would follow the @mflaxman "Bitcoin 10x security guide". Its how I held my bitcoin before I founded @AnchorWatch, and even though the guide is 6 years old, the principles are timeless. I would remove his suggestion of using the cold card and replace it with any other hardware wallet. I would replace the cold card with a @Ledger at this time if it were my decision. You can pick up a Ledger up at Best Buy in the US. Michael pioneered multi vendor multisig as a concept, and if you want a fully sovereign solution, as of today there is no better mental model on how to think through this, he has advanced tabs to further increase the security. For his cold card guide he fairly calls out the added benefit of rolling dice, which would have saved you today. I think the future is combining the tech we use at @AnchorWatch to move beyond the single signature/ multi signature paradigm of custody, with the principles of @mflaxman's 10x security guide and the support of collaborative custody. More on that later, but I would check out @lianabitcoin from @Wizardsardine as well, they offer a fully open source wallet that enables these more advanced smart contracts and are security researchers in the bitcoin ecosystem. With that, I'm going to get back to work. I will post a followup reply if I have additional information or any corrections or clarifications to make.
Jordan retro
Jordan retro
Las pérdidas de Bitcoin $BTC en Coldcard han subido a 70 millones de dólares tras una vulnerabilidad en la cartera Galaxy Research informó que se trasladaron más de 1.000 BTC, valorados en aproximadamente 70 millones de dólares, desde casi 1.200 direcciones. Coinkite advirtió el jueves que las frases semilla creadas por dispositivos Coldcard Mk3 con firmware 4.0.1 o posterior podrían poner en riesgo fondos. Más tarde, Coinkite amplió la advertencia a ciertas versiones de firmware de Mk4, Mk5 y Coldcard Q y lanzó actualizaciones de firmware de emergencia. #OKXTraderVoices #NewHereStartHere #30YYieldAt19YHigh #SpaceXUnlockLooms #EarningsWeekAhead
sirkp
sirkp
El hackeo de Coldcard es una llamada de atención para los poseedores de Bitcoin Muchas personas creen que una vez que su Bitcoin está almacenado en una cartera de hardware, está completamente seguro. Este último incidente con Coldcard demuestra que la seguridad también depende de cómo la cartera genera tu frase semilla. A finales de julio de 2026, hackers explotaron una falla en el firmware que existía desde marzo de 2021. El error debilitaba la aleatoriedad usada para crear las frases semilla, permitiendo a los atacantes recrear esas frases fuera de línea y robar fondos sin siquiera tocar las carteras de hardware. El resultado fue devastador: alrededor de 1,367 $BTC, valorados en casi 89 millones de dólares, fueron robados de más de 4,500 carteras. Coinkite, la empresa detrás de Coldcard, reconoció el problema y lanzó actualizaciones de firmware de emergencia. Sin embargo, simplemente actualizar tu dispositivo no es suficiente si tu cartera fue creada usando el firmware vulnerable. Los usuarios necesitan generar una frase semilla completamente nueva en el firmware actualizado y transferir su Bitcoin a la nueva cartera. El hackeo ha sacudido la confianza en las carteras de hardware, con algunos usuarios incluso moviendo fondos de vuelta a exchanges centralizados a pesar del impulso hacia la autocustodia tras el colapso de FTX. Otros, incluyendo a CZ de Binance, han recordado a los usuarios que distribuir los activos entre múltiples métodos de almacenamiento suele ser el enfoque más seguro. La lección más importante es simple: la autocustodia sigue siendo una de las mejores formas de proteger tu Bitcoin, pero ninguna solución de seguridad es perfecta. Una fuerte aleatoriedad al crear tu frase semilla, usar una frase de contraseña y evitar un único punto de fallo pueden marcar una gran diferencia. La seguridad no es solo poseer una cartera de hardware, es usarla de la manera correcta. #EarningsWeekAhead #30YYieldAt19YHigh #KOSPISurges14%
AllEF
AllEF
Aviso para quienes gestionan su custodia con un Coldcard. Algunos clientes me han preguntado sobre la vulnerabilidad, así que aquí está la versión clara. El problema afecta a algunos dispositivos Coldcard Mk3. Las carteras que generaron frases semilla con el firmware desde marzo de 2021 en adelante tenían un fallo. Los atacantes podían recrear esas semillas sin conexión y vaciar los fondos sin tocar nunca tu dispositivo. Desde el 30 de julio, se han drenado cerca de 1.367 $BTC, valorados en aproximadamente 89 millones de dólares, desde más de 4.500 direcciones en tres oleadas. La última oleada apunta a saldos más pequeños, alrededor de 0,1 $BTC cada uno. Pequeño no significa seguro aquí. Contexto importante. Esto es específico para Coldcard Mk3. Ledger, Trezor, Bitkey y Jade no están afectados. Los modelos más nuevos de Coldcard como Mk4 y Q también parecen estar bien. La parte difícil. Si tu semilla fue creada en un Mk3 afectado, el problema está en la semilla misma, no en el firmware que uses ahora. Los investigadores dicen que la solución es mover tus monedas a una nueva cartera con una semilla generada en un entorno seguro. Usar una frase de contraseña, multisig o semillas generadas con dados reduce mucho el riesgo. Para los SMSF esto es diferente. Los fondos cripto deben estar a nombre del fondo, y esta semana se demostró que la autogestión no es automáticamente más segura. Como sea que lo gestiones, la custodia es parte de administrar el fondo. Trátalo con la misma seriedad que tu auditoría. He enlazado el desglose más claro en la respuesta. Si crees que podrías estar afectado, no esperes. #30YrYieldTopOrStart #30YrYieldTopOrStart #USIranBackToTalks $BEAT $ADA $SOL
Alex Thorn
Alex Thorn
🚨 PROBABLE CUARTA OLA ORGANIZADA DE ATAQUES COLDCARD OCURRIENDO AHORA MISMO AÚN HAY TRANSACCIONES SIMILARES EN EL MEMPOOL ESPERANDO SER CONFIRMADAS Y LAS TRANSACCIONES PREVIAMENTE CONFIRMADAS INDICAN RBF OPT-IN, REVISA TUS FONDOS Y PODRÍAS PODER SALIR DE ESTO USANDO RBF patrón identificado: bloques 960,778 - 960,792 (últimas ~2.5 horas, aún en curso): • 218 transacciones, 462 direcciones víctimas, 216 destinos nuevos. • 388.92748828 BTC • TODAS tienen entradas ZERO anteriores al límite del firmware Coldcard • Tasa 13.8 barridos/bloque vs 0.3/bloque en una ventana de control previa al incidente = ~45x elevado • La topología es 1:1 — un destino nuevo por víctima, solo UN destino recibió dos barridos. No hay embudo de colectores. • Algunos fondos ya han sido barridos hacia direcciones de segundo salto. estas SON PROBABLEMENTE víctimas de Coldcard -- coinciden con la forma de los utxos vulnerables de Coldcard y el patrón elevado de transacciones me da alta confianza de que son otra ola de ataques MUEVE TUS FONDOS FUERA DE LOS DISPOSITIVOS COLDCARD LO ANTES POSIBLE Y USA ALTAS COMISIONES DE TX más detalles a medida que esto se desarrolle
Marcus Corvinus1
Marcus Corvinus1
Un drenaje de 89 millones de dólares en la cartera fría acaba de poner a prueba toda la tesis de la autocustodia, y Bitcoin se negó a romperse. Un fallo de firmware que data de hace años en dispositivos Coldcard permitió a los atacantes barrer miles de direcciones. Esto no es un hackeo de intercambio ni un fallo de contrato inteligente. Es un fallo de entropía a nivel de hardware que afecta al almacenamiento puramente offline. La respuesta del mercado es la verdadera historia. $BTC sigue defendiendo la zona de los 63.000 dólares. Ese tipo de absorción bajo malas noticias genuinas muestra que la venta forzada ya ha terminado en gran medida y la liquidez restante es selectiva en lugar de presa del pánico. Las instituciones parecen conformarse con observar en lugar de venderse, mientras que los flujos de ETF se mantienen mixtos y el tono beligerante de la Fed mantiene retrasadas las esperanzas de recortes de tipos. $ETH mantiene su rango reciente. $SOL y $XRP muestran mejores ofertas relativas, y $ADA sigue liderando el potencial de alza de grandes capitalizaciones. $BNB, $DOGE, $TRX, $HYPE, $AVAX, $LINK, $DOT, $UNI, $ATOM y $NEAR siguen en su mayoría el mismo tono de riesgo cauteloso sin catalizadores separados. Mi opinión: episodios como este aceleran el cambio hacia soluciones de custodia institucional y envolvimientos de ETF. Al mismo tiempo, cualquier apalancamiento residual en nombres de beta superior permanecerá ajustado hasta el próximo punto de datos macro claro. Agosto ya suele entrecortado; El volumen escaso de fin de semana y el calendario regulatorio no resuelto solo contribuyen a eso. Mantente fijo en la grabación, respeta los rangos y deja que la acción del precio confirme el siguiente movimiento real.