Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Who would ever trust the built-in seed generation of a wallet? Diceware, write them down, then enter them into the wallet.
  • Because it's a hardware wallet. Usually these are designed to provide security by generating their own private keys and never letting the private key leave the hardware wallet. If you input the private key, you don't have the same security level.
  • the thief appears sloppy in how they stole the coins. multiple waves, linking outputs together etc.
  • would be interesting to see what happens to them when they're found, shame we'll never know.
  • Yep, also greedy. If he only emptied a few large wallets and sent them to different addresses each also not all at the same time the vulnerability may not have been discovered so quickly.

    Most would have blamed the card holder as was seen in the initial few posts that showed up on reddit.

  • The bigger disaster is awaiting. hackers are now reviewing source code of everything crypto related for entropy or other misconfiguration bugs, automated with leading AI models , which will spot errors humans missed. We're talking wallets dating back to 2010 when btc was founded, and then for all the altcoins. Ppl don't realize how bad this will get when exploit detection can be done at scale with LLMs. Ai can review a codebase in minutes, which would take humans days, if ever. Coldcard is a tiny wallet service. A bigger one would have losses in excess of billions. A hacker will first find the vulnerability and then exhaust the keyspace and download the blockchain to cue up the keys and do it all at once .
  • Better now than later. It would have been even better a decade ago, but here we are.