home.social

#coldcard — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #coldcard, aggregated by home.social.

fetched live
  1. (more Linux and FOSS news in previous posts of thread)

    Lemonade 11.6 Integrates Muse-Glimmer 30B, Experimental TheNoise ROCm Image Generation:
    phoronix.com/news/Lemonade-SDK

    AMD GAIA 0.23 Delivers Ability To Install/Run AI Agents From The Terminal:
    phoronix.com/news/AMD-GAIA-0.23

    FastFlowLM 1.0 Released Now As Part Of The AMD ROCm Umbrella:
    phoronix.com/news/FastFlowLM-1

    Overshared to an AI? Proton's Tool Will Give You a Reality Check:
    feed.itsfoss.com/link/24361/17

    openJiuwen’s Agent Swarm: When AI Agents Finally Work as a Team:
    feed.itsfoss.com/link/24361/17
    (Oh yeah, just teach AI agents to team up. Surely they can't cause any trouble, right? RIGHT?)

    The Coldcard Exploit Explained: Who Lost Bitcoin and Who's at Risk:
    news.bitcoin.com/featured/the-

    Wireshark 4.6.8 Improves Protocol and Capture File Support, Fixes More Bugs:
    9to5linux.com/wireshark-4-6-8-

    Roundcube Webmail Patches 11 Critical Vulnerabilities in Emergency 1.6.18 and 1.7.3 Updates:
    linuxcompatible.org/story/roun

    Zed v1.15.0 Lands with Self-Hosted AI Predictions, Git Baseline Toggle, and Wayland Drag-and-Drop:
    linuxcompatible.org/story/zed-

    Flutter 3.47 introduces standalone UI packages and Impeller for desktop:
    alternativeto.net/news/2026/8/

    Podman 6.1 introduces volume renaming, restart command, and robust bugfixes:
    alternativeto.net/news/2026/8/

    PHP 8.4.25 and 8.5.10 release candidates drop with serious stack-overflow hardening:
    linuxcompatible.org/story/php-

    PHP 8.6.0 Beta 1 Lands With Partial Function Application, Native Polling API, and a Hard Shift Toward Strict Errors:
    linuxcompatible.org/story/php-

    PostgreSQL 19 Beta 3 and Critical Security Patches Released; PG 14 EOL Notice Issued:
    linuxcompatible.org/story/post

    GCC 17 Compiler Adding "-m128bit-atomic" For 128-bit Atomic Memory Operations:
    phoronix.com/news/GCC-Git-m128

    (more FOSS news in comments)

    #WeeklyNews #FOSSNews #AI #Zed #Flutter #PHP #Podman #PostgreSQL #Dev #AMDGAIA #FastFlowLM #Coldcard #Bitcoin #Wireshark #GCC #ArtificialIntelligence #LLM #AgenticAI #Programming #Development #Coding #IDE #DBMS #SQL #FosseryTech

  2. (more Linux and FOSS news in previous posts of thread)

    Lemonade 11.6 Integrates Muse-Glimmer 30B, Experimental TheNoise ROCm Image Generation:
    phoronix.com/news/Lemonade-SDK

    AMD GAIA 0.23 Delivers Ability To Install/Run AI Agents From The Terminal:
    phoronix.com/news/AMD-GAIA-0.23

    FastFlowLM 1.0 Released Now As Part Of The AMD ROCm Umbrella:
    phoronix.com/news/FastFlowLM-1

    Overshared to an AI? Proton's Tool Will Give You a Reality Check:
    feed.itsfoss.com/link/24361/17

    openJiuwen’s Agent Swarm: When AI Agents Finally Work as a Team:
    feed.itsfoss.com/link/24361/17
    (Oh yeah, just teach AI agents to team up. Surely they can't cause any trouble, right? RIGHT?)

    The Coldcard Exploit Explained: Who Lost Bitcoin and Who's at Risk:
    news.bitcoin.com/featured/the-

    Wireshark 4.6.8 Improves Protocol and Capture File Support, Fixes More Bugs:
    9to5linux.com/wireshark-4-6-8-

    Roundcube Webmail Patches 11 Critical Vulnerabilities in Emergency 1.6.18 and 1.7.3 Updates:
    linuxcompatible.org/story/roun

    Zed v1.15.0 Lands with Self-Hosted AI Predictions, Git Baseline Toggle, and Wayland Drag-and-Drop:
    linuxcompatible.org/story/zed-

    Flutter 3.47 introduces standalone UI packages and Impeller for desktop:
    alternativeto.net/news/2026/8/

    Podman 6.1 introduces volume renaming, restart command, and robust bugfixes:
    alternativeto.net/news/2026/8/

    PHP 8.4.25 and 8.5.10 release candidates drop with serious stack-overflow hardening:
    linuxcompatible.org/story/php-

    PHP 8.6.0 Beta 1 Lands With Partial Function Application, Native Polling API, and a Hard Shift Toward Strict Errors:
    linuxcompatible.org/story/php-

    PostgreSQL 19 Beta 3 and Critical Security Patches Released; PG 14 EOL Notice Issued:
    linuxcompatible.org/story/post

    GCC 17 Compiler Adding "-m128bit-atomic" For 128-bit Atomic Memory Operations:
    phoronix.com/news/GCC-Git-m128

    (more FOSS news in comments)

    #WeeklyNews #FOSSNews #AI #Zed #Flutter #PHP #Podman #PostgreSQL #Dev #AMDGAIA #FastFlowLM #Coldcard #Bitcoin #Wireshark #GCC #ArtificialIntelligence #LLM #AgenticAI #Programming #Development #Coding #IDE #DBMS #SQL #FosseryTech

  3. 🔒🎲 Oh joy, COLDCARD's "random" numbers turned out to be anything but! A simple oversight meant that from March 2021, your ultra-secure, hacker-proof, high-tech #wallet was about as secure as a paper bag in a hurricane! 🌪️💸 But hey, at least we all learned that their build guard checks were as useful as a screen door on a submarine! 🚪🤦‍♂️
    coldcard.rip/ #COLDCARD #Security #Vulnerability #HackerNews #TechNews #CyberSecurity #HackerNews #ngated

  4. 🔒🎲 Oh joy, COLDCARD's "random" numbers turned out to be anything but! A simple oversight meant that from March 2021, your ultra-secure, hacker-proof, high-tech #wallet was about as secure as a paper bag in a hurricane! 🌪️💸 But hey, at least we all learned that their build guard checks were as useful as a screen door on a submarine! 🚪🤦‍♂️
    coldcard.rip/ #COLDCARD #Security #Vulnerability #HackerNews #TechNews #CyberSecurity #HackerNews #ngated

  5. TIL that the Coldcard fiasco - where large amounts of cryptocurrency were lost - was caused by a coding oversight in a library called "libNgU"

    Why NgU? "Number go Up". Oops.

    Coldcard postmortem from MicroPython's perspective — github.com/orgs/micropython/di

    #coldcard #MicroPython

  6. TIL that the Coldcard fiasco - where large amounts of cryptocurrency were lost - was caused by a coding oversight in a library called "libNgU"

    Why NgU? "Number go Up". Oops.

    Coldcard postmortem from MicroPython's perspective — github.com/orgs/micropython/di

    #coldcard #MicroPython

  7. Rogue #ScreenConnect RMM cluster using a fake COLDCARD domain to lure crypto wallet owners 💰 into downloading a fake DocuSign MSI which drops ScreenConnect 🖱️🖥️

    ⛓️ Attack Chain:
    Threat actor domain ➡️ GitHub repo ➡️ ScreenConnect

    🔍 Fake #COLDCARD domain with opendir:
    hardware-data .com ➡️ Tucows Domains 🇺🇸

    ⚙️ Rogue GitHub user with 19 code repositories:
    github.com/kaswareteam/

    🔌 ScreenConnect RMM botnet C2s (Port 8041 TCP):

    🇺🇸 DeltaHost :
    hitpanels .com ➡️ 185.174.101.132
    hitspanels .com ➡️ 185.174.101.132

    🇺🇸 1337 Services GmbH:
    vicspanel .com ➡️ 155.2.192.94
    hitstp .com ➡️ 155.2.192.235
    vps133panel .com ➡️ 203.159.90.31

    🦊 IOCs on ThreatFox:
    threatfox.abuse.ch/browse/tag/

    🏠 Payload delivery URLs on URLhaus:
    urlhaus.abuse.ch/browse/tag/sc

  8. Rogue #ScreenConnect RMM cluster using a fake COLDCARD domain to lure crypto wallet owners 💰 into downloading a fake DocuSign MSI which drops ScreenConnect 🖱️🖥️

    ⛓️ Attack Chain:
    Threat actor domain ➡️ GitHub repo ➡️ ScreenConnect

    🔍 Fake #COLDCARD domain with opendir:
    hardware-data .com ➡️ Tucows Domains 🇺🇸

    ⚙️ Rogue GitHub user with 19 code repositories:
    github.com/kaswareteam/

    🔌 ScreenConnect RMM botnet C2s (Port 8041 TCP):

    🇺🇸 DeltaHost :
    hitpanels .com ➡️ 185.174.101.132
    hitspanels .com ➡️ 185.174.101.132

    🇺🇸 1337 Services GmbH:
    vicspanel .com ➡️ 155.2.192.94
    hitstp .com ➡️ 155.2.192.235
    vps133panel .com ➡️ 203.159.90.31

    🦊 IOCs on ThreatFox:
    threatfox.abuse.ch/browse/tag/

    🏠 Payload delivery URLs on URLhaus:
    urlhaus.abuse.ch/browse/tag/sc

  9. A cryptocurrency hack that allowed bad actors to fleece bitcoin investors of an estimated $130 million by exploiting a software flaw in a "safe" offline hardware wallet is testing the faith of the devoted. japantimes.co.jp/business/2026 #business #tech #cryptocurrencies #bitcoin #coldcard #coinkite #cybersecurity #hacking

  10. A cryptocurrency hack that allowed bad actors to fleece bitcoin investors of an estimated $130 million by exploiting a software flaw in a "safe" offline hardware wallet is testing the faith of the devoted. japantimes.co.jp/business/2026 #business #tech #cryptocurrencies #bitcoin #coldcard #coinkite #cybersecurity #hacking

  11. CRYPTO · Bitcoin's volunteer hackers find 85 flaws with AI help

    After the Coldcard wallet theft, a volunteer team used AI to scan 390 Bitcoin projects and found 85 critical security bugs.

    Read the rest at: thedailyfathom.com/crypto/2026

    #Crypto #BitcoinRedTeam #Coldcard #OpenSats #TheDailyFathom

  12. CRYPTO · Bitcoin's volunteer hackers find 85 flaws with AI help

    After the Coldcard wallet theft, a volunteer team used AI to scan 390 Bitcoin projects and found 85 critical security bugs.

    Read the rest at: thedailyfathom.com/crypto/2026

    #Crypto #BitcoinRedTeam #Coldcard #OpenSats #TheDailyFathom

  13. Coinkite advises their customers to move Bitcoin funds away from Coldcard-based wallets, after it was found that the firmware used pseudorandom number generators

    cbc.ca/news/world/bitcoin-coin
    - - -
    Coinkite avise sa clientèle de bouger les fonds Bitcoin loin des portefeuilles à base Coldcard, après qu’il a été trouvé que le microgiciel utilisait des générateurs de nombres pseudoaléatoires

    ici.radio-canada.ca/nouvelle/2

    #Bitcoin #Coldcard #Coinkite #InfoSec #InformationSecurity #Cybersécurité

  14. Coinkite advises their customers to move Bitcoin funds away from Coldcard-based wallets, after it was found that the firmware used pseudorandom number generators

    cbc.ca/news/world/bitcoin-coin
    - - -
    Coinkite avise sa clientèle de bouger les fonds Bitcoin loin des portefeuilles à base Coldcard, après qu’il a été trouvé que le microgiciel utilisait des générateurs de nombres pseudoaléatoires

    ici.radio-canada.ca/nouvelle/2

    #Bitcoin #Coldcard #Coinkite #InfoSec #InformationSecurity #Cybersécurité

  15. Ich habe mich heute am See mit dem ColdCard Fall beschäftigt, bei dem Aufgrund einer falschen Konfiguration bei Hardware Bitcoin Wallets über 1400 Bitcoin gestohlen wurden. Der Bug bestand seit 2021 und wurde über das Wochenende ausgenutzt.
    Ich bin selbst ziemlich kritisch gegenüber #AI - aber ich finde es grob fahrlässig, sicherheitsrelevanten Code nicht zumindest durch LLMs analysieren zu lassen. Angreifer machen es sowieso. Das ersetzt natürlich kein professionelles Review - der Bug bei der ColdCard Firmware hätte meiner Meinung nach auffallen müssen.

    Ledger, ein Konkurrent von ColdCard, bietet hier einen spannenden Einblick in ihren Agenten-Workflow:

    donjon.ledger.com/blog/ai-secu

    #bitcoin #coldcard #security

  16. Ich habe mich heute am See mit dem ColdCard Fall beschäftigt, bei dem Aufgrund einer falschen Konfiguration bei Hardware Bitcoin Wallets über 1400 Bitcoin gestohlen wurden. Der Bug bestand seit 2021 und wurde über das Wochenende ausgenutzt.
    Ich bin selbst ziemlich kritisch gegenüber #AI - aber ich finde es grob fahrlässig, sicherheitsrelevanten Code nicht zumindest durch LLMs analysieren zu lassen. Angreifer machen es sowieso. Das ersetzt natürlich kein professionelles Review - der Bug bei der ColdCard Firmware hätte meiner Meinung nach auffallen müssen.

    Ledger, ein Konkurrent von ColdCard, bietet hier einen spannenden Einblick in ihren Agenten-Workflow:

    donjon.ledger.com/blog/ai-secu

    #bitcoin #coldcard #security

  17. Oops 🫣

    > A software bug in popular hardware wallet #Coldcard that led to the theft to this point of nearly 600 #bitcoin worth roughly $38 million is prompting questions about security and whether managing private keys has become too risky for everyday investors.

    coindesk.com/business/2026/07/

  18. 📢⚠️ Researchers link weak seeds generated by affected COLDCARD firmware to suspected Bitcoin thefts totaling 1,367.05 BTC, worth nearly $89 million. Meanwhile, Coinkite warns that updates do not repair existing seeds.

    Listen/Read: hackread.com/coldcard-seed-gen

    #Bitcoin #COLDCARD #Cybersecurity #Vulnerability #Crypto

  19. 📢⚠️ Researchers link weak seeds generated by affected COLDCARD firmware to suspected Bitcoin thefts totaling 1,367.05 BTC, worth nearly $89 million. Meanwhile, Coinkite warns that updates do not repair existing seeds.

    Listen/Read: hackread.com/coldcard-seed-gen

    #Bitcoin #COLDCARD #Cybersecurity #Vulnerability #Crypto

  20. #bitcoin really is like a #cult. Re #coldcard #hack

    People are walking around with metal rods in a thunderstorm and when one of them gets struck by lightning they say, "Well he obviously did something wrong to displease god."

  21. #bitcoin really is like a #cult. Re #coldcard #hack

    People are walking around with metal rods in a thunderstorm and when one of them gets struck by lightning they say, "Well he obviously did something wrong to displease god."

  22. Beacause of the #Coldcard hack people are saying open source is more vulnerable but I couldn't disagree more.

    Back in the day people would point out that open source means nothing because nobody bothers to actually read the code, now anyone with a GPU can burn energy at vetting it.

    I'm pretty AI critical, but if anything it seems like after a painful 'disruptive' period, open code will be the only thing that actually survives.

  23. When your BTC goes poof in the night!

    Random secret generator firmware mis-config resulted in wallets defaulting to seeding keys from the chip's serial number and clock registers in Coldcard hardware based wallets.

    ~594 bitcoin, worth about $38 million, was extracted out of around 500 separate wallets between 01:31 and 01:56 UTC. coindesk.com/tech/2026/07/31/m

  24. Hardware Wallet Rivals Offer Discounts in Wake of Ledger New Product Controversy - In response to the latest controversy related to hardware wallet specialist Ledger and it... - cryptonews.com/news/hardware-w #blockchainnews #coldcard #hardware #ledger #trezor #wallet