Hacker News new | ask | show | jobs
by Aurornis 3 hours ago
The Bitcoin communities seem to really be struggling with this hack. The people losing their coins in this case were following best practices. Typically when someone loses their coins there’s a big pile-on to victim blame them for making some mistake. I think it’s comforting to others to be able to identify a mistake someone else made and then convince yourself that you’re too smart to make the same mistake.

In this case, there isn’t much of a mistake to point out. I’ve seen a couple attempts from people trying the told-you-so routine using some arguments about multisig wallets as the only option, but mostly it looks like people are panicking and wondering if their choice of wallet has some undiscovered vulnerability waiting to be exploited. I mostly try to stay away from Bitcoin communities but in events like this it spills over everywhere. I feel sorry for anyone who lost coins, of course, but it’s also interesting to watch the communities grapple with reconciling their appreciation for irreversible key-based transactions with the realities of how this works when their money is on the line. The old ideas about having perfect OPSEC and being smarter than the other coiners are starting to get weakened with examples like this.

My guess is that the next phase is to revise history and form a consensus that Coldcard was never a recommended wallet and that it was obvious to everyone with good OPSEC at the time.

2 comments

5% of btc users use a hardware wallet and Cardkite wasn't even in the top 5 MFGs as far as i'm aware.

also as far as I care the btc community members who chose to go with one of the few hardware wallets that wasn't open source were not doing due their diligence.

>My guess is that the next phase is to revise history and form a consensus that Coldcard was never a recommended wallet and that it was obvious to everyone with good OPSEC at the time.

if that's a worry just search for things far before the exploit date; lots of unhappiness around cardkite for a while now -- but to be clear, it's nowhere near a revision.

> also as far as I care the btc community members who chose to go with one of the few hardware wallets that wasn't open source were not doing due their diligence.

Seems like part of the issue here is that it was open source in a way that from the discussion here (https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt) may have made vulnerabilities easier to spot for an attacker...?

> but to be clear, it's nowhere near a revision.

That’s how the retroactive victim blaming always works: It is retroactively determined that there were signs, which turns into victim blaming anyone who didn’t predict that those signs would lead to loss of their coins.

You are doing it.

> also as far as I care the btc community members who chose to go with one of the few hardware wallets that wasn't open source were not doing due their diligence.

I can’t tell if you’re confused about the details of this story or if you’re trying to make a point that isn’t landing. You may want to read up on the open source status of the wallet before doing the whole victim blaming song and dance.

Cold wallet was definitely recommended late 2025, along with the meme of using dice to generate the entropy. Ledger wasn't recommended by coldcard definitely was
> In this case, there isn’t much of a mistake to point out.

I don’t buy this. There is no $249 device that I would trust with even 1 BTC. These folks looked at the options to preserve $100,000 and picked a $249 device over an exchange. Or a bank. Or the DOW.

It is heartbreaking the loss that some have suffered. But it doesn’t benefit anyone to say “Who could have known?” Everyone knew: because not one person said “I have verified this product and it cannot possibly be vulnerable”. So “it’s open source and you can verify it yourself!” Ok. Nobody did! “Well maybe they did, they just didn’t find the exploit” - that’s the point!

> My guess is that the next phase is to revise history and form a consensus that Coldcard was never a recommended wallet and that it was obvious to everyone with good OPSEC at the time.

Yeah. I didn’t use it. I would never use it. The problem is that “everyone with good OPSEC” are “obviously just plants of Big Bank and the IRS”. The criminals that benefit from “normal” people “legitimizing” bitcoins have really good PR department.

> I don’t buy this. There is no $249 device that I would trust with even 1 BTC. These folks looked at the options to preserve $100,000 and picked a $249 device over an exchange. Or a bank. Or the DOW.

Bitcoin communities have been advocating for hardware wallets over exchanges for a long time. The phrase goes “not your wallet, not your coins”

Yeah. It’s propaganda. It ought to be “Not your code? Not hardware you designed and built? Not your coins.” But then like ten people could safely own BTC. BTC is a criminal conspiracy that requires fools for legitimacy.