Remix.run Logo
84adam 6 hours ago

Just read an associate of mine lost 10 years worth of bitcoin he'd saved and mined from this Coldcard issue.

johng 5 hours ago | parent [-]

So for this to be exploited, all someone needs to know is that your address was generated on one of these vulnerable Coldcards? No physical access is needed, they just cycle through likely seed phrases and bam, they now have wallet control?

infofarmer 3 hours ago | parent [-]

They don't need to know that. Your low-entropy seed / private key will be compromised in the brute force enumeration.