light 📜
49.3K posts

light 📜
@lightcoin
p2p electronic cash enthusiast || 🏴🦔 @light__nh || ☿ he/they

The white hack drains have begun. I'm conflicted about this.




$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack. My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet. This part's nerdy, but here's what happened: Hackers discovered a vulnerability in the part of the hardware wallet code used to create seed phrases. This allowed them to use AI to brute force guessing seed phrases. I was at our cottage and heard about the hack today. "No way this affects me." I thought. I logged into Wasabi––software that lets me view my bitcoin wallets online. Right away I saw lines of red transaction–withdrawals–and I knew. From 9:36pm - 9:43pm on July 29th, every wallet I had had been emptied. 18.25245043 btc gone. That's just over $1.6 million dollars CAD. Perhaps the hardest part about this is that I did everything right. I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes. None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability. I'm filing a police report and a report with the Ontario Securities Commission. But I don't expect to recoup anything. A part of me is trying to make sense of what just happened. Or try to figure out a lesson in it. I'm struggling. $1.6 million is a staggering amount of money to have stolen. I guess all that I can think about right now is that I'm so damn happy that I'm an entrepreneur and that my earning potential is under my control. Mark my damn words. I'll recover.










An acquaintance of mine intentionally left a small amount of bitcoin in a ColdCard MK4 RNG created seed phrase (that was originally a "duress" wallet) to see when it might get swept. Last night it got swept to bc1qzm5pauxyv7t7vqstzpumqcn066wfjsmev34mf3. So at this point any RNG generated seedphrase on any ColdCard product is under active attack. Move quickly if you're exposed.

BULL working on: Migration tool where you import a seed and you put an destination xpub, it creates multiple transactions with different fingerprints and decoys, to sweep a wallet without aggregating utxos and leaving a trail (experimental) I wish we had done this long ago...












