#coldcard — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #coldcard, aggregated by home.social.
-
(more Linux and FOSS news in previous posts of thread)
Lemonade 11.6 Integrates Muse-Glimmer 30B, Experimental TheNoise ROCm Image Generation:
https://www.phoronix.com/news/Lemonade-SDK-11.6AMD GAIA 0.23 Delivers Ability To Install/Run AI Agents From The Terminal:
https://www.phoronix.com/news/AMD-GAIA-0.23FastFlowLM 1.0 Released Now As Part Of The AMD ROCm Umbrella:
https://www.phoronix.com/news/FastFlowLM-1.0Overshared to an AI? Proton's Tool Will Give You a Reality Check:
https://feed.itsfoss.com/link/24361/17418931/proton-ai-paper-trailopenJiuwen’s Agent Swarm: When AI Agents Finally Work as a Team:
https://feed.itsfoss.com/link/24361/17411448/openjiuwens-agent-swarm
(Oh yeah, just teach AI agents to team up. Surely they can't cause any trouble, right? RIGHT?)The Coldcard Exploit Explained: Who Lost Bitcoin and Who's at Risk:
https://news.bitcoin.com/featured/the-coldcard-exploit-explained-who-lost-bitcoin-and-whos-at-risk/Wireshark 4.6.8 Improves Protocol and Capture File Support, Fixes More Bugs:
https://9to5linux.com/wireshark-4-6-8-improves-protocol-and-capture-file-support-fixes-more-bugsRoundcube Webmail Patches 11 Critical Vulnerabilities in Emergency 1.6.18 and 1.7.3 Updates:
https://www.linuxcompatible.org/story/roundcube-patches-11-critical-vulnerabilities-in-emergency-1618-and-173-update/Zed v1.15.0 Lands with Self-Hosted AI Predictions, Git Baseline Toggle, and Wayland Drag-and-Drop:
https://www.linuxcompatible.org/story/zed-editor-v1150-adds-selfhosted-ai-predictions-git-diff-baseline-and-wayland-support/Flutter 3.47 introduces standalone UI packages and Impeller for desktop:
https://alternativeto.net/news/2026/8/flutter-3-47-introduces-standalone-ui-packages-and-impeller-for-desktop/Podman 6.1 introduces volume renaming, restart command, and robust bugfixes:
https://alternativeto.net/news/2026/8/podman-6-1-introduces-volume-renaming-restart-command-and-robust-bugfixes/PHP 8.4.25 and 8.5.10 release candidates drop with serious stack-overflow hardening:
https://www.linuxcompatible.org/story/php-8425-and-8510-release-candidates-ship-with-stack-hardening/PHP 8.6.0 Beta 1 Lands With Partial Function Application, Native Polling API, and a Hard Shift Toward Strict Errors:
https://www.linuxcompatible.org/story/php-860-beta-1-partial-function-application-native-polling-and-stricter-error-handling/PostgreSQL 19 Beta 3 and Critical Security Patches Released; PG 14 EOL Notice Issued:
https://www.linuxcompatible.org/story/postgresql-19-beta-3-and-critical-security-patches-released-pg-14-eol-notice-issued/GCC 17 Compiler Adding "-m128bit-atomic" For 128-bit Atomic Memory Operations:
https://www.phoronix.com/news/GCC-Git-m128bit-atomic(more FOSS news in comments)
#WeeklyNews #FOSSNews #AI #Zed #Flutter #PHP #Podman #PostgreSQL #Dev #AMDGAIA #FastFlowLM #Coldcard #Bitcoin #Wireshark #GCC #ArtificialIntelligence #LLM #AgenticAI #Programming #Development #Coding #IDE #DBMS #SQL #FosseryTech
-
(more Linux and FOSS news in previous posts of thread)
Lemonade 11.6 Integrates Muse-Glimmer 30B, Experimental TheNoise ROCm Image Generation:
https://www.phoronix.com/news/Lemonade-SDK-11.6AMD GAIA 0.23 Delivers Ability To Install/Run AI Agents From The Terminal:
https://www.phoronix.com/news/AMD-GAIA-0.23FastFlowLM 1.0 Released Now As Part Of The AMD ROCm Umbrella:
https://www.phoronix.com/news/FastFlowLM-1.0Overshared to an AI? Proton's Tool Will Give You a Reality Check:
https://feed.itsfoss.com/link/24361/17418931/proton-ai-paper-trailopenJiuwen’s Agent Swarm: When AI Agents Finally Work as a Team:
https://feed.itsfoss.com/link/24361/17411448/openjiuwens-agent-swarm
(Oh yeah, just teach AI agents to team up. Surely they can't cause any trouble, right? RIGHT?)The Coldcard Exploit Explained: Who Lost Bitcoin and Who's at Risk:
https://news.bitcoin.com/featured/the-coldcard-exploit-explained-who-lost-bitcoin-and-whos-at-risk/Wireshark 4.6.8 Improves Protocol and Capture File Support, Fixes More Bugs:
https://9to5linux.com/wireshark-4-6-8-improves-protocol-and-capture-file-support-fixes-more-bugsRoundcube Webmail Patches 11 Critical Vulnerabilities in Emergency 1.6.18 and 1.7.3 Updates:
https://www.linuxcompatible.org/story/roundcube-patches-11-critical-vulnerabilities-in-emergency-1618-and-173-update/Zed v1.15.0 Lands with Self-Hosted AI Predictions, Git Baseline Toggle, and Wayland Drag-and-Drop:
https://www.linuxcompatible.org/story/zed-editor-v1150-adds-selfhosted-ai-predictions-git-diff-baseline-and-wayland-support/Flutter 3.47 introduces standalone UI packages and Impeller for desktop:
https://alternativeto.net/news/2026/8/flutter-3-47-introduces-standalone-ui-packages-and-impeller-for-desktop/Podman 6.1 introduces volume renaming, restart command, and robust bugfixes:
https://alternativeto.net/news/2026/8/podman-6-1-introduces-volume-renaming-restart-command-and-robust-bugfixes/PHP 8.4.25 and 8.5.10 release candidates drop with serious stack-overflow hardening:
https://www.linuxcompatible.org/story/php-8425-and-8510-release-candidates-ship-with-stack-hardening/PHP 8.6.0 Beta 1 Lands With Partial Function Application, Native Polling API, and a Hard Shift Toward Strict Errors:
https://www.linuxcompatible.org/story/php-860-beta-1-partial-function-application-native-polling-and-stricter-error-handling/PostgreSQL 19 Beta 3 and Critical Security Patches Released; PG 14 EOL Notice Issued:
https://www.linuxcompatible.org/story/postgresql-19-beta-3-and-critical-security-patches-released-pg-14-eol-notice-issued/GCC 17 Compiler Adding "-m128bit-atomic" For 128-bit Atomic Memory Operations:
https://www.phoronix.com/news/GCC-Git-m128bit-atomic(more FOSS news in comments)
#WeeklyNews #FOSSNews #AI #Zed #Flutter #PHP #Podman #PostgreSQL #Dev #AMDGAIA #FastFlowLM #Coldcard #Bitcoin #Wireshark #GCC #ArtificialIntelligence #LLM #AgenticAI #Programming #Development #Coding #IDE #DBMS #SQL #FosseryTech
-
Wie der vermeintlich sicherste Bitcoin-Tresor geknackt wurde (Coinkite Coldcard)
-
🔒🎲 Oh joy, COLDCARD's "random" numbers turned out to be anything but! A simple oversight meant that from March 2021, your ultra-secure, hacker-proof, high-tech #wallet was about as secure as a paper bag in a hurricane! 🌪️💸 But hey, at least we all learned that their build guard checks were as useful as a screen door on a submarine! 🚪🤦♂️
https://coldcard.rip/ #COLDCARD #Security #Vulnerability #HackerNews #TechNews #CyberSecurity #HackerNews #ngated -
🔒🎲 Oh joy, COLDCARD's "random" numbers turned out to be anything but! A simple oversight meant that from March 2021, your ultra-secure, hacker-proof, high-tech #wallet was about as secure as a paper bag in a hurricane! 🌪️💸 But hey, at least we all learned that their build guard checks were as useful as a screen door on a submarine! 🚪🤦♂️
https://coldcard.rip/ #COLDCARD #Security #Vulnerability #HackerNews #TechNews #CyberSecurity #HackerNews #ngated -
COLDCARD's Random Numbers Weren't
Comments: https://news.ycombinator.com/item?id=49186715
#HackerNews #COLDCARD #RandomNumbers #Security #Cryptocurrency #Privacy
-
COLDCARD's Random Numbers Weren't
Comments: https://news.ycombinator.com/item?id=49186715
#HackerNews #COLDCARD #RandomNumbers #Security #Cryptocurrency #Privacy
-
TIL that the Coldcard fiasco - where large amounts of cryptocurrency were lost - was caused by a coding oversight in a library called "libNgU"
Why NgU? "Number go Up". Oops.
Coldcard postmortem from MicroPython's perspective — https://github.com/orgs/micropython/discussions/19588
-
TIL that the Coldcard fiasco - where large amounts of cryptocurrency were lost - was caused by a coding oversight in a library called "libNgU"
Why NgU? "Number go Up". Oops.
Coldcard postmortem from MicroPython's perspective — https://github.com/orgs/micropython/discussions/19588
-
Rogue #ScreenConnect RMM cluster using a fake COLDCARD domain to lure crypto wallet owners 💰 into downloading a fake DocuSign MSI which drops ScreenConnect 🖱️🖥️
⛓️ Attack Chain:
Threat actor domain ➡️ GitHub repo ➡️ ScreenConnect🔍 Fake #COLDCARD domain with opendir:
hardware-data .com ➡️ Tucows Domains 🇺🇸⚙️ Rogue GitHub user with 19 code repositories:
https://github.com/kaswareteam/🔌 ScreenConnect RMM botnet C2s (Port 8041 TCP):
🇺🇸 DeltaHost :
hitpanels .com ➡️ 185.174.101.132
hitspanels .com ➡️ 185.174.101.132🇺🇸 1337 Services GmbH:
vicspanel .com ➡️ 155.2.192.94
hitstp .com ➡️ 155.2.192.235
vps133panel .com ➡️ 203.159.90.31🦊 IOCs on ThreatFox:
https://threatfox.abuse.ch/browse/tag/ScreenConnect/🏠 Payload delivery URLs on URLhaus:
https://urlhaus.abuse.ch/browse/tag/screenconnect/ -
Rogue #ScreenConnect RMM cluster using a fake COLDCARD domain to lure crypto wallet owners 💰 into downloading a fake DocuSign MSI which drops ScreenConnect 🖱️🖥️
⛓️ Attack Chain:
Threat actor domain ➡️ GitHub repo ➡️ ScreenConnect🔍 Fake #COLDCARD domain with opendir:
hardware-data .com ➡️ Tucows Domains 🇺🇸⚙️ Rogue GitHub user with 19 code repositories:
https://github.com/kaswareteam/🔌 ScreenConnect RMM botnet C2s (Port 8041 TCP):
🇺🇸 DeltaHost :
hitpanels .com ➡️ 185.174.101.132
hitspanels .com ➡️ 185.174.101.132🇺🇸 1337 Services GmbH:
vicspanel .com ➡️ 155.2.192.94
hitstp .com ➡️ 155.2.192.235
vps133panel .com ➡️ 203.159.90.31🦊 IOCs on ThreatFox:
https://threatfox.abuse.ch/browse/tag/ScreenConnect/🏠 Payload delivery URLs on URLhaus:
https://urlhaus.abuse.ch/browse/tag/screenconnect/ -
A cryptocurrency hack that allowed bad actors to fleece bitcoin investors of an estimated $130 million by exploiting a software flaw in a "safe" offline hardware wallet is testing the faith of the devoted. https://www.japantimes.co.jp/business/2026/08/07/tech/bitcoin-hack-safety-cryptocurrencies/?utm_medium=Social&utm_source=mastodon #business #tech #cryptocurrencies #bitcoin #coldcard #coinkite #cybersecurity #hacking
-
A cryptocurrency hack that allowed bad actors to fleece bitcoin investors of an estimated $130 million by exploiting a software flaw in a "safe" offline hardware wallet is testing the faith of the devoted. https://www.japantimes.co.jp/business/2026/08/07/tech/bitcoin-hack-safety-cryptocurrencies/?utm_medium=Social&utm_source=mastodon #business #tech #cryptocurrencies #bitcoin #coldcard #coinkite #cybersecurity #hacking
-
CRYPTO · Bitcoin's volunteer hackers find 85 flaws with AI help
After the Coldcard wallet theft, a volunteer team used AI to scan 390 Bitcoin projects and found 85 critical security bugs.
Read the rest at: https://thedailyfathom.com/crypto/2026-08-06/
-
CRYPTO · Bitcoin's volunteer hackers find 85 flaws with AI help
After the Coldcard wallet theft, a volunteer team used AI to scan 390 Bitcoin projects and found 85 critical security bugs.
Read the rest at: https://thedailyfathom.com/crypto/2026-08-06/
-
Hackers steal over $130M by exploiting bug in offline hardware wallets
-
Hackers steal over $130M by exploiting bug in offline hardware wallets
-
Coinkite advises their customers to move Bitcoin funds away from Coldcard-based wallets, after it was found that the firmware used pseudorandom number generators
https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582
- - -
Coinkite avise sa clientèle de bouger les fonds Bitcoin loin des portefeuilles à base Coldcard, après qu’il a été trouvé que le microgiciel utilisait des générateurs de nombres pseudoaléatoireshttps://ici.radio-canada.ca/nouvelle/2273388/coinkite-coldcard-vol-bitcoins-crypto
#Bitcoin #Coldcard #Coinkite #InfoSec #InformationSecurity #Cybersécurité
-
Coinkite advises their customers to move Bitcoin funds away from Coldcard-based wallets, after it was found that the firmware used pseudorandom number generators
https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582
- - -
Coinkite avise sa clientèle de bouger les fonds Bitcoin loin des portefeuilles à base Coldcard, après qu’il a été trouvé que le microgiciel utilisait des générateurs de nombres pseudoaléatoireshttps://ici.radio-canada.ca/nouvelle/2273388/coinkite-coldcard-vol-bitcoins-crypto
#Bitcoin #Coldcard #Coinkite #InfoSec #InformationSecurity #Cybersécurité
-
Ich habe mich heute am See mit dem ColdCard Fall beschäftigt, bei dem Aufgrund einer falschen Konfiguration bei Hardware Bitcoin Wallets über 1400 Bitcoin gestohlen wurden. Der Bug bestand seit 2021 und wurde über das Wochenende ausgenutzt.
Ich bin selbst ziemlich kritisch gegenüber #AI - aber ich finde es grob fahrlässig, sicherheitsrelevanten Code nicht zumindest durch LLMs analysieren zu lassen. Angreifer machen es sowieso. Das ersetzt natürlich kein professionelles Review - der Bug bei der ColdCard Firmware hätte meiner Meinung nach auffallen müssen.Ledger, ein Konkurrent von ColdCard, bietet hier einen spannenden Einblick in ihren Agenten-Workflow:
https://donjon.ledger.com/blog/ai-security-harness-cerberus/
-
Ich habe mich heute am See mit dem ColdCard Fall beschäftigt, bei dem Aufgrund einer falschen Konfiguration bei Hardware Bitcoin Wallets über 1400 Bitcoin gestohlen wurden. Der Bug bestand seit 2021 und wurde über das Wochenende ausgenutzt.
Ich bin selbst ziemlich kritisch gegenüber #AI - aber ich finde es grob fahrlässig, sicherheitsrelevanten Code nicht zumindest durch LLMs analysieren zu lassen. Angreifer machen es sowieso. Das ersetzt natürlich kein professionelles Review - der Bug bei der ColdCard Firmware hätte meiner Meinung nach auffallen müssen.Ledger, ein Konkurrent von ColdCard, bietet hier einen spannenden Einblick in ihren Agenten-Workflow:
https://donjon.ledger.com/blog/ai-security-harness-cerberus/
-
Coldcard Exploit: Bitcoin Wallet Users Lose Nearly $89 Million - https://www.redpacketsecurity.com/coldcard-users-lose-89m-after-bitcoin-wallet-is-hacked/
-
Coldcard Exploit: Bitcoin Wallet Users Lose Nearly $89 Million - https://www.redpacketsecurity.com/coldcard-users-lose-89m-after-bitcoin-wallet-is-hacked/
-
📢⚠️ Researchers link weak seeds generated by affected COLDCARD firmware to suspected Bitcoin thefts totaling 1,367.05 BTC, worth nearly $89 million. Meanwhile, Coinkite warns that updates do not repair existing seeds.
Listen/Read: https://hackread.com/coldcard-seed-generation-flaw-bitcoin-theft/
-
📢⚠️ Researchers link weak seeds generated by affected COLDCARD firmware to suspected Bitcoin thefts totaling 1,367.05 BTC, worth nearly $89 million. Meanwhile, Coinkite warns that updates do not repair existing seeds.
Listen/Read: https://hackread.com/coldcard-seed-generation-flaw-bitcoin-theft/
-
A #BITCOIN #COLDCARD MAJOR ZERO DAY
#zeroday #0day @COLDCARDwallet @vxunderground #btx
https://blog.coinkite.com/entropy-technical-backgrounder/
-
A #BITCOIN #COLDCARD MAJOR ZERO DAY
#zeroday #0day @COLDCARDwallet @vxunderground #btx
https://blog.coinkite.com/entropy-technical-backgrounder/
-
Des millions en bitcoins volés pour une raison complètement stupide
https://mac4ever.com/197429
#Mac4Ever #bitcoins #Coldcard -
Des millions en bitcoins volés pour une raison complètement stupide
https://mac4ever.com/197429
#Mac4Ever #bitcoins #Coldcard -
The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M
Comments: https://news.ycombinator.com/item?id=49146372
#HackerNews #Coldcard #Disaster #Hack88.6M #Cryptocurrency #Security #Vulnerability #Cybersecurity
-
The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M
Comments: https://news.ycombinator.com/item?id=49146372
#HackerNews #Coldcard #Disaster #Hack88.6M #Cryptocurrency #Security #Vulnerability #Cybersecurity
-
Bitcoin attack: Some Bitcoin wallet didn't use good random numbers and now people's money is being stolen
https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million
#malfeasance #negligence #coldcard #security #bitcoin #crypto #dumb #- -
Bitcoin attack: Some Bitcoin wallet didn't use good random numbers and now people's money is being stolen
https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million
#malfeasance #negligence #coldcard #security #bitcoin #crypto #dumb #- -
#COLDCARD flaw may have exposed #Bitcoin wallet seeds for years
https://nerds.xyz/2026/07/coldcard-firmware-flaw-bitcoin-wallet-seeds/
-
#COLDCARD flaw may have exposed #Bitcoin wallet seeds for years
https://nerds.xyz/2026/07/coldcard-firmware-flaw-bitcoin-wallet-seeds/
-
Beacause of the #Coldcard hack people are saying open source is more vulnerable but I couldn't disagree more.
Back in the day people would point out that open source means nothing because nobody bothers to actually read the code, now anyone with a GPU can burn energy at vetting it.
I'm pretty AI critical, but if anything it seems like after a painful 'disruptive' period, open code will be the only thing that actually survives.
-
A 2021 COLDCARD build error shrank seed entropy from 128 bits to 40, letting attackers drain 594 BTC from 500 wallets in just 15 minutes.
#COLDCARD #Bitcoin #HardwareWallet #CryptoSecurity #SeedPhrase
-
When your BTC goes poof in the night!
Random secret generator firmware mis-config resulted in wallets defaulting to seeding keys from the chip's serial number and clock registers in Coldcard hardware based wallets.
~594 bitcoin, worth about $38 million, was extracted out of around 500 separate wallets between 01:31 and 01:56 UTC. https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep #Crypto #CryptoHeist #CryptoWallet #CryptoCrime #BTC #BitCoin #BlockChain #ColdCard #Hack #WalletKeys #KeySeeding
-
Hardware Wallet Rivals Offer Discounts in Wake of Ledger New Product Controversy - In response to the latest controversy related to hardware wallet specialist Ledger and it... - https://cryptonews.com/news/hardware-wallet-rivals-offer-discounts-wake-of-ledger-new-product-controversy.htm #blockchainnews #coldcard #hardware #ledger #trezor #wallet
-
Coinkite Launches Its New Flagship Bitcoin Hardware Wallet Coldcard Q1
https://bitcoinmagazine.com/business/coinkite-new-bitcoin-wallet-coldcard-q1
#BitcoinHardware #Hardwarewallet #BitcoinWallets #Coinkite #coldcard #Business #News