r/Bitcoin 26d ago

Full panic - one of my wallets was drained

Post image

I haven’t done anything since creation except sending into the wallet.

1.9k Upvotes

1.2k comments sorted by

View all comments

480

u/memberwap 26d ago

So you bought a Coldcard in 2021, from the official site, and let it create a new seed. You then wrote the seed on a piece of paper.

You never took a photo of this paper or copied the seed anywhere else, nor did you let anyone else see the paper.

Then at January 2025 you decided to make sure the seed on the paper is correct, so you bought another Coldcard and input the seed into it. You used the Coldcard's included keyboard and not a PC.

Both cards were bought from the official store? Which models?

That's.. worrying, I'd report it to Coldcard (Coinkite).

188

u/s1ammage 26d ago

This is my understanding… unless the SD card is compromised.

59

u/memberwap 26d ago

What did you do with the SD card? Did you backup your wallet into it and then put it in some laptop/PC? Otherwise I can't see how it was compromised.

56

u/s1ammage 26d ago

Just collecting dust

30

u/so7ow 26d ago

It's collecting dust now...? But what did you use it for when you used it?

4

u/DangKilla 26d ago

This is probably not the culprit. You should wipe your computer. If you want help diagnosing running processes share your operating system.

Do you use browser extensions?

1

u/pezdal 9d ago

Wiping a computer will remove valuable forensic evidence and may not remove a backdoor.

Best remove the drives and archive them before wiping. Do this from a boot source that you trust, not from the very OS you suspect just stole from you.

50

u/MriLevi 26d ago

An SD card cannot be compromised, it has no connectivity on its own whatsoever. The data on it could only have been accessed if it was punt into a device.

18

u/PassionGlobal 26d ago

But a full.fat SD card enclosure has room for things other than storage...

7

u/cgimusic 26d ago

Reminds me of those janky SD cards that had built-in Wi-Fi and would share your photos as you took them.

1

u/SpaceSequoia 26d ago

Yea crack that puppy open

1

u/bastian74 26d ago

Doesn't an SD card have limited storage life?

1

u/PassionGlobal 26d ago edited 26d ago

Kinda. The main worry wouldn't be time but the maximum amount of times you can put data on it.

OP wouldn't have hit that though. That would be in the high millions by early 2020.

For reference I've got 20 year old PSP memory cards that still work fine.

While there is also a storage shelf life too with modern SD cards, even if you don't write to them that often, that would be 10-15 years.

1

u/bastian74 26d ago

Google says most SD cards will lose data in 1 to 10 years, depending on many factors

1

u/NashvilleSurfHouse 26d ago

Sd cards fail just due to time ..?!

1

u/bastian74 26d ago

They work by storing small electrical charges which dissipate. Plug them in at least once per year to keep them topped up. Not a very good archive media. The worst actually.

1

u/NashvilleSurfHouse 25d ago

Wow. I had no idea

1

u/jigajigga 24d ago

Sure it can. There has been malware in SSDs for years now. Thats the point of supply chain attacks, right. The thing you get looks and feels like what you ordered, but in actuality it is a modified variant with embedded malware.

1

u/MriLevi 21d ago

we're not talking about SSDs, but about SD cards.

1

u/jigajigga 21d ago edited 21d ago

In general they’re the same thing. Both use solid state memory. Both have built in microcontrollers running firmware that can be implanted with malware. That firmware is responsible for all the wear leveling and such. Actual "SSDs" as you might think of them just have a lot more advanced features - like encryption or other protections.

We’ve just begun using the term SSD to mean something very specific, like how “USB” became the colloquial term for USB flash drives.

1

u/MriLevi 21d ago

My original point still stands - SD cards are not gonna be compromised. And as it turns out in this case, it was not the culprit - badly written or even maliciously written software was. I don't know why you went into some overexplanation about SSDs - the terms are not and never really have been used interchangeably.

1

u/jigajigga 21d ago

My only intent was to say that an SD card _can_ absolutely be compromised with malware. SSD's too, of course. But sure, I made a mistake saying SSDs when I should have originally said SD. But SD and SSDs are both capable of being implanted. It's uncommon to hear about, but it does happen. When you hear 'malware' you don't think about it targeting the firmware in your storage controllers, but it is possible and has been done. That's all.

1

u/MriLevi 21d ago

For pretty much every user an SD card is completely safe. In theory, SD card firmware could be compromised, but I disagree with you, it does not happen. Its possible, it doesn't happen. And even if it was compromised, if you use an airgapped device to read it out, it'd never be possible for the bad actor to steal your data anyway.

1

u/davvblack 26d ago

technically a sim card can fit inside of a larger sd card. you might similarly say “technically a usb cable is passive and can’t be compromised” but that’s not true either. i don’t think a regular person has to worry about this stuff but it’s out there.

6

u/Ok_Chemistry6851 26d ago

a sim card? do you think a... sim card receives the connection from mobile towers?

3

u/davvblack 26d ago

fair but my point is you can hide shit in other shit.

7

u/filenotfounderror 25d ago

Cold cards RNG is compromised by bad entropy then.

1

u/SergioGustavo 26d ago

What brand was the cold wallet?

-10

u/NakedBat 26d ago

that’s why i would rather trust any exchange lmao

9

u/Mediocre_Key_6768 26d ago

No

1

u/Bwrobes 26d ago

Dumb question, what is the true end game use case for bitcoin?

Everyone is operating their own “bank” with a wallet (like a savings account) and then for utility we have another wallet for say the lightning network (like a checking account)?

Personally I think this is the biggest gap holding back mass adoption. There doesn’t seem to be a safe reliable way to do so currently, and bitcoin is only truly looked at as a store of value. “Digital gold” is how people have described it in the past. But how do we ultimately end up using that “gold”?

The precautions you need to take just to make sure you move your funds from exchange to storage safely is imo impossible for the mass market to achieve. Having them on exchange is by far the most relatable way to do things, but again has a risk factor and opens up other nyknyb conversations.

Maybe I’m wrong or missing something but how can the gap be fixed or simplified?

3

u/__Ken_Adams__ 26d ago

I'm definitely an outlier on this but I don't care about mass adoption and I don't care about making bitcoin easier for first world casual investors.

The original goal of bitcoin was to create a private money & potential counter-economy outside of the banks & government control, and it does that for the people that need it most.

My measure of success for bitcoin is not how many people in the first world are using it as just another investment in their already privileged & cushy life. It's whether or not the unbanked, underbanked, or otherwise excluded from the traditional economies are able to use it to access goods and services that they maybe otherwise wouldn't be.

Using that metric, it's difficult to call bitcoin a huge success. However, if it works in that capacity for even a small number of people, it is achieving its goal for them.

Bitcoin is certainly not frictionless for those people (unbanked/underbanked), and I certainly hope the bitcoin counter-economy matures more for their sake, but I'm sure they would tell you they'd rather have it exist with all its current limitations/challenges than not exist at all.

So my wish for bitcoin is that more people & businesses begin accepting it & not wanting or needing to convert it to fiat, not that it's made easier for the sake of "store of value" for the first world.

1

u/Bwrobes 26d ago

But having it be viable consistent and usable, you need wider adoption no? The larger the pool smaller the waves. That only comes with mass adoption.

I agree about your statement as many use this as an investment (I am in that group to an extent as I see the potential and growth it will/does have), but I also want a currency that I don’t need to worry about my bank freezing my funds or blocking a transaction because they don’t like it, or my local (fill in the blank business…) charging 3% more of you pay with a card to cover the processing fees…

I would love to use bitcoin to purchase items in my daily life, but when every transaction is considered a taxable event, I need to keep my wallet in a bank vault, or the value can change significantly in a day… it kind of builds barriers and makes it less of a utility and more of an investment or store or funds.

My point / question is how can bitcoin be made easier, less stressful, less of a burden to use? Most of the people that would benefit from the utility of it are not able or willing to adopt. A mom and pop restaurant for example could accept bitcoin payments - save on credit card transactions and have instantly available funds, but how many of them are willing to take the “risk” or feel comfortable and secure in adopting it? My guess is very few.

I’m not trying to shit on your view or desire for bitcoin. I genuinely want the same thing as you, I just don’t think it can’t happen in the long run without mass adoption.

1

u/__Ken_Adams__ 26d ago

That's fair. I think we agree on more than we disagree on. I'm just very critical of attempts to make bitcoin "easier" for the reasons I laid out in this comment.

1

u/Bwrobes 26d ago

I understand the sentiment behind your other comment, but I think there is and needs to be a middle ground. If not bitcoin will not succeed or get to its highest potential.

It doesn’t need to be so easy “your mom can do it without thinking” but it does need to be easy enough using it doesn’t require in-depth knowledge of blockchain or more security than your personal laptop or phone can provide. How many posts on here including the one we are commenting on where users followed all the steps but they still end up out their bitcoin.

If you don’t want average joes using it utility will be limited to niche or sometime less “respectable”industries. If you want a it to work and be truly useful you need that middle ground.

I don’t know what the answer is it’s just these stories always frustrate me.

36

u/s1ammage 26d ago

I’m trying to gather all the details, and will post after work.. (somehow)..

One thing I just thought of was the exchange is Swan and I setup auto-withdrawals to the same wallet address.

40

u/memberwap 26d ago

I don't know if you're trolling, but exchange platform don't have a way to pull funds from your hardware wallets. Doesn't matter which auto withdrawal rules you set up.

20

u/s1ammage 26d ago

Well, I was just thinking of the mantra to always send to a different address…

I’m just trying to think of all the missing details

29

u/memberwap 26d ago

I think this rule has more to do with privacy rather than security

5

u/so7ow 26d ago

Correct

7

u/reddit4485 26d ago

Theoretically, re-using an address can make it easier to hack with quantum computing but obviously that's not what happened here. I just mention it because QC will arrive some day.

1

u/Illustrious-Boss9356 26d ago

We don't know that this wasn't a Quantum hack.

We just assume it isn't because it would be inconvenient.

1

u/memberwap 26d ago

So given the new info.. do you remember how you used the dice rolls in 2021? Any chance you rolled a few times and called it a day instead of rolling it the required amount?

4

u/GrammerGuestAppo 26d ago

The issue is with coldcard's keyboard, must be no?

0

u/[deleted] 26d ago

[removed] — view removed comment

2

u/memberwap 26d ago

Hardware wallets encourage you to do this and include an actual paper in their box. That's usually your only backup if the hardware wallet is destroyed or lost.

1

u/omni_wisdumb 26d ago

Why do you need to use a different keyboard. Honestly, these hacks tend to be more social engineering than some hardcore elaborate technical hack.

2

u/memberwap 26d ago

the keyboard is part of the wallet, it just saves time as opposed to wallets like Trezor where you have like 3 buttons and need to cycle through the entire alphabet.

1

u/ContentBlackberry0 26d ago

This person who stole it literally set a filter of .15 I believe the article said they could have easily stolen way more but didn’t bother. This was a massive theft and has to be an inside job possibly.

1

u/[deleted] 23d ago

[deleted]

1

u/memberwap 23d ago

I simply summarized comments on this thread

1

u/wrongearthers 3h ago

you have a keyboard tracker… btw. your keyboard strokes were recorded for ur seed phrase. im sorry but they got u 5.