First, there's no need for you to apologise. You yourself were a user of the product, you were happy with it, so there was no reason not to mention it or make reference to it in passing. You used generic terms like "cold storage" and "hardware wallet" just as often, if not more, iirc.
Secondly, agree on the quantum thing. This is just a small hint of how it will feel like when the first old coins start moving, assuming the community doesn't collectively "solve" the issue by doing something really foolish and short sighted (imo) like burn or freeze them.
I don't use a coldcard but it's just by chance really, when I moved away from ledger a few years ago it could easily have been to CC rather than Trezor, so I feel very fortunate. My heart goes out to those affected and I do personally know someone who has lost a big chunk, it is just devastating.
Thank you so much James for writing a piece about EMOTIONS and the emotional rollercoaster of the past weekend. And you've mentioned but didn't elaborate on my most heightened emotion this weekend, which was FEAR. I think the cortisol amongst very "ordinary" self-custody bitcoiners is going to be very high for awhile.
I'm devastated. I'm depressed. I've been hanging out in the studio like a refuge.
I also feel guilty. I recommended Coldcard to everyone I knew, and mentioned it on podcasts. I feel like a fucking idiot.
I had a horrible morning on Friday because I was exposed (I use the product too) starting at 5am driving like a nut through cities while unable to concentrate trying to get a wallet, get to my funds, make a new wallet/address and transfer funds with shaking hands.
What a fucking nightmare. And how the hell are people in my age group able to handle this? Or to move funds quickly? Or to have a clue about rolling dice ( not just ANY dice), or entropy.
I'm rethinking everything right now and so damn sad. Sad for the people who had that horrible, gut wrenching I'm going to throw up moment when they found everything gone. Sad because I felt this was the year I had gotten back to basics and those basics centered on running a node and self custody.
Thanks for sharing George, we have all felt this to some degree this week. Just a shocking breach of duty by Coinkite, and a devastating situation for far too many people.
The efforts of everyone working to help others is something we can be proud of, and many lessons will be learned such that this never happens again.
Not your fault George, you did the best to your knowledge like we all do. This is a time where we support the bitcoiners who have suffered losses and focus on strengthening the bitcoin network.
I don’t even know how this would possibly work, but would there be any way to start some sort of fund for the victims? As someone who used a coldcard and whose legitimate entire life savings was spared from early migration, I’d love nothing more than to somehow contribute to helping people recover from this. Great article Check
It's a tricky one since victims cannot prove their ownership using the private key as many attackers now have that. It will likely be a lengthy legal process, all TBC.
Makes sense, but I’d love for the smartest people in the industry to explore the idea when the dust settles. I imagine a lot of the victims have extensive UTXO history that could be extremely helpful. We owe it to people to at least try IMO
As soon as the news dropped I was at home and able to take swift action, I just feel awful for those that weren't so lucky and have been affected by this. It's gut wrenching.
ColdCard Q user since 2023, single sig, device generated the 24 word seed and, given this is my long term DCA cold storage wallet, there's plenty riding on this so I didn't trust it.
Without another HWW to hand, I updated the Q to the latest firmware release 1.5.0Q, generated a new 24 word seed with the 100 dice roll function, imported the new wallet to sparrow and carefully started to migrate my bitcoin across. Apparently, smarter folk than me have verified the dice roll entropy in CCQ to be correct and so far that appears to be the only vulnerability we know of.
Whilst I figure out what the best storage solution is for the future, which will take a few weeks and probably involved learning multi sig, would you be comfortable keeping this setup in the mean time? A friend has a Trezor model T that he's offered that I could also use as a stop gap...
G'day Stu. My understanding is that the dice roll feature is indeed sound. I would personally feel ok to sit tight for now, however I would also spend the time to prepare a more permanent solution.
So my read is, you're not at any immediate risk, but for the sake of your sleep long term, work towards a better solution in the relatively near term. You have bought yourself valuable breathing space to focus and do the requisite research and thinking.
Thanks James, keep up the good work. Once the dust settles, maybe a video or write up on security solutions and possible best practice we can all consider. I'm sure we're all busy expending plenty of mental bandwidth on solutions, let's turn it into a learning event.
James, I had a defective coldcard but was saved by a passphrase and consider myself lucky. I’ve since moved the funds to a trezor wallet.
How do you think about whether you continue using the coldcard? It seems like a dice-generated seed in a multi sig setup would be perfectly safe. Do you still plan to use your coldcard moving forward, or have you lost trust and support for the company that you don’t even plan to use your current device?
I love the coldcard. Such an awesome device. I wish a more reputable dev would take over the company. Jack Dorsey or some legendary dev with deep pockets and proven salt in the space. The defective code really seems like a coldcard leadership/ team issue more than anything.
Advice going forward should be offline dice rolls with printed BIP-39 word list. If it’s your life savings at stake, why not sleep soundly about your seed generation process, by taking several minutes to do it, rather than trusting some vendor.
'Thanx James. Following up to Stu's suggestion. In lame terms for beginners where pharses like Robust Multi-Signature or Multi-party custody and Covenants are not familiar. Hope you prepare a video that would educate us on how to store securely. Thanx
I have an issue with calling it a “hack” or an “exploit”. It was a catastrophic defect that their devices had from March 2021 onwards.
Incompetence on the highest level possible for a hww maker, and with hubris too.
A very fair terminology. No dispute there.
Just a gentle reminder for anyone who may have had funds stolen, please don’t destroy your Coldcard out of anger.
If there is any future outcome where the funds can be returned, it could help you re-claim them.
Thoughts and empathy with anyone who may be going through losses right now. Stay strong!
Thanks James..
First, there's no need for you to apologise. You yourself were a user of the product, you were happy with it, so there was no reason not to mention it or make reference to it in passing. You used generic terms like "cold storage" and "hardware wallet" just as often, if not more, iirc.
Secondly, agree on the quantum thing. This is just a small hint of how it will feel like when the first old coins start moving, assuming the community doesn't collectively "solve" the issue by doing something really foolish and short sighted (imo) like burn or freeze them.
I don't use a coldcard but it's just by chance really, when I moved away from ledger a few years ago it could easily have been to CC rather than Trezor, so I feel very fortunate. My heart goes out to those affected and I do personally know someone who has lost a big chunk, it is just devastating.
Anyone still here and holding after this bear deserves a win. FTX was a bigger % drop, but this one is tough.
There may yet be shoes (and prices) left to drop but, having said that, I am amazed that we're still slogging mostly sideways after this.
I feel very sorry for everyone affected by this.
Thank you so much James for writing a piece about EMOTIONS and the emotional rollercoaster of the past weekend. And you've mentioned but didn't elaborate on my most heightened emotion this weekend, which was FEAR. I think the cortisol amongst very "ordinary" self-custody bitcoiners is going to be very high for awhile.
100% agreed. Fear is the first response, and we all felt it to some degree upon hearing this news.
Well said.
I'm devastated. I'm depressed. I've been hanging out in the studio like a refuge.
I also feel guilty. I recommended Coldcard to everyone I knew, and mentioned it on podcasts. I feel like a fucking idiot.
I had a horrible morning on Friday because I was exposed (I use the product too) starting at 5am driving like a nut through cities while unable to concentrate trying to get a wallet, get to my funds, make a new wallet/address and transfer funds with shaking hands.
What a fucking nightmare. And how the hell are people in my age group able to handle this? Or to move funds quickly? Or to have a clue about rolling dice ( not just ANY dice), or entropy.
I'm rethinking everything right now and so damn sad. Sad for the people who had that horrible, gut wrenching I'm going to throw up moment when they found everything gone. Sad because I felt this was the year I had gotten back to basics and those basics centered on running a node and self custody.
I don't know what to say right now
Thanks for sharing George, we have all felt this to some degree this week. Just a shocking breach of duty by Coinkite, and a devastating situation for far too many people.
The efforts of everyone working to help others is something we can be proud of, and many lessons will be learned such that this never happens again.
Not your fault George, you did the best to your knowledge like we all do. This is a time where we support the bitcoiners who have suffered losses and focus on strengthening the bitcoin network.
We'll all get through it together.
I don’t even know how this would possibly work, but would there be any way to start some sort of fund for the victims? As someone who used a coldcard and whose legitimate entire life savings was spared from early migration, I’d love nothing more than to somehow contribute to helping people recover from this. Great article Check
It's a tricky one since victims cannot prove their ownership using the private key as many attackers now have that. It will likely be a lengthy legal process, all TBC.
Makes sense, but I’d love for the smartest people in the industry to explore the idea when the dust settles. I imagine a lot of the victims have extensive UTXO history that could be extremely helpful. We owe it to people to at least try IMO
Good evening folks,
As soon as the news dropped I was at home and able to take swift action, I just feel awful for those that weren't so lucky and have been affected by this. It's gut wrenching.
ColdCard Q user since 2023, single sig, device generated the 24 word seed and, given this is my long term DCA cold storage wallet, there's plenty riding on this so I didn't trust it.
Without another HWW to hand, I updated the Q to the latest firmware release 1.5.0Q, generated a new 24 word seed with the 100 dice roll function, imported the new wallet to sparrow and carefully started to migrate my bitcoin across. Apparently, smarter folk than me have verified the dice roll entropy in CCQ to be correct and so far that appears to be the only vulnerability we know of.
Whilst I figure out what the best storage solution is for the future, which will take a few weeks and probably involved learning multi sig, would you be comfortable keeping this setup in the mean time? A friend has a Trezor model T that he's offered that I could also use as a stop gap...
Honest thoughts appreciated...
G'day Stu. My understanding is that the dice roll feature is indeed sound. I would personally feel ok to sit tight for now, however I would also spend the time to prepare a more permanent solution.
So my read is, you're not at any immediate risk, but for the sake of your sleep long term, work towards a better solution in the relatively near term. You have bought yourself valuable breathing space to focus and do the requisite research and thinking.
Thanks James, keep up the good work. Once the dust settles, maybe a video or write up on security solutions and possible best practice we can all consider. I'm sure we're all busy expending plenty of mental bandwidth on solutions, let's turn it into a learning event.
That's in the pipeline. Great suggestion
James, I had a defective coldcard but was saved by a passphrase and consider myself lucky. I’ve since moved the funds to a trezor wallet.
How do you think about whether you continue using the coldcard? It seems like a dice-generated seed in a multi sig setup would be perfectly safe. Do you still plan to use your coldcard moving forward, or have you lost trust and support for the company that you don’t even plan to use your current device?
Thanks a ton. Huge fan of the newsletter.
Great result, happy to hear all safe and sound.
I love the coldcard. Such an awesome device. I wish a more reputable dev would take over the company. Jack Dorsey or some legendary dev with deep pockets and proven salt in the space. The defective code really seems like a coldcard leadership/ team issue more than anything.
Advice going forward should be offline dice rolls with printed BIP-39 word list. If it’s your life savings at stake, why not sleep soundly about your seed generation process, by taking several minutes to do it, rather than trusting some vendor.
'Thanx James. Following up to Stu's suggestion. In lame terms for beginners where pharses like Robust Multi-Signature or Multi-party custody and Covenants are not familiar. Hope you prepare a video that would educate us on how to store securely. Thanx
Great post thank you for your work in this space.
Thanks Check!
Sylvain Saurel who writes the "In bitcoin we trust" letter on Substack has a detailed report on the Coldcard hack. I can recommend it
https://inbitcoinwetrust.substack.com/?r=lh7f7&utm_campaign=pub&utm_medium=web