
#ColdcardSeedAlert
About ColdcardSeedAlert
After the Coldcard firmware flaw was set off en masse on July 30, losses have risen to ~1,367 BTC, about $88.6M, the year's largest Bitcoin theft. Galaxy's Alex Thorn warned Aug 3 a suspected fourth wave is still underway. Root cause: the vendor misrouted seed generation to a software PRNG, a single-vendor flaw, not a self-custody failure. Best move: check affected models and firmware, migrate funds, spread risk. Until the fourth wave is contained, treat assets on affected devices as exposed.
Populares
Mais recentes
ColdcardSeedAlert Publicações populares
🚨 Uma falha de segurança. Mais de 40 milhões de dólares em Bitcoin desaparecidos.
Mais de 40 milhões de dólares em Bitcoin foram supostamente roubados após o hack da carteira de hardware Coldcard, levantando novas preocupações sobre a segurança das criptomoedas.
O incidente é um lembrete de que a autocustódia não se trata apenas de possuir uma carteira de hardware — trata-se de proteger cada parte do processo, desde onde compra o dispositivo até como protege a sua frase de recuperação.
Quer esteja a guardar 0,01 BTC ou 100 BTC, a segurança nunca deve ser uma reflexão tardia.
À medida que mais detalhes surgem, este poderá tornar-se um dos incidentes com carteiras de hardware mais observados nos últimos anos.
👀 Acha que isto vai mudar a forma como as pessoas vão guardar o seu Bitcoin daqui para a frente?
#DailyOrbit
A maior notícia cripto de hoje: O ataque à carteira de hardware Coldcard já drenou cerca de 89 milhões de dólares (~1.367 BTC) de mais de 4.500 endereços!
O atacante nunca tocou nos dispositivos — simplesmente usou força bruta em frases-semente fracas offline devido a um bug de entropia no firmware. Primeira onda: 41 minutos e mais de 1.000 BTC desaparecidos.
Se possui uma Coldcard (especialmente Mk2/Mk3) — atualize o firmware AGORA, gere uma nova semente e mova os seus fundos imediatamente!
A custódia própria está sob ataque novamente.
#Bitcoin #Coldcard #CryptoSecurity #BTC
Não fique parado a esperar. Aja agora. 🛡️$BTC


Falha na semente do coldcard abala a confiança à medida que $BTC entra num teste crítico
$BTC está a entrar num dos seus testes de stress mais importantes de 2026.
A recentemente divulgada Falha de Semente do Coldcard levantou sérias preocupações em todo o ecossistema Bitcoin após uma vulnerabilidade de firmware em certas carteiras de hardware Coldcard ter sido associada a um roubo de fundos em larga escala. Embora tenha sido lançado um patch de segurança, as carteiras criadas com o firmware afetado continuam vulneráveis, a menos que os utilizadores transfiram os seus ativos para frases semente recentemente geradas.
Isto é mais do que uma questão de carteira de hardware — é um grande teste à confiança do mercado.
Numa altura em que a $BTC já está sob forte pressão de venda, o incidente de segurança acrescentou mais uma camada de incerteza para os investidores. No entanto, é importante perceber que a vulnerabilidade não afeta a própria rede Bitcoin. A questão limita-se ao processo de geração de sementes da carteira, enquanto o protocolo Bitcoin permanece seguro e inalterado.
A história mostrou que eventos como este frequentemente desencadeiam volatilidade a curto prazo, mas também separam a condenação a longo prazo do medo a curto prazo. Se os compradores continuarem a defender níveis-chave de suporte, a correção atual poderá evoluir para uma fase saudável de acumulação antes do próximo ciclo de alta. Por outro lado, a falha em manter o suporte pode acelerar o impulso descendente e aumentar a volatilidade do mercado.
Por agora, os investidores devem focar-se não só na movimentação do preço da $BTC, mas também na restauração da confiança após um dos incidentes de segurança de carteiras de hardware mais significativos dos últimos anos. No mundo do Bitcoin, proteger as suas chaves privadas é tão importante quanto tomar as decisões de investimento corretas.
#ColdcardSeedFlaw
#BTCSecurityAlliance
#OKXOrbitTopics
$BTC
E se a comunidade Bitcoin se recusasse a deixar os hackers vencerem?
Em vez de esperar anos pela justiça, poderíamos agir agora.
Uma proposta para as vítimas do Coldcard:
🟠 Criar um fundo comunitário de BTC para comprar as reivindicações sobre as moedas roubadas.
🐋 Baleias e apoiantes podem contribuir.
⚡ As vítimas recuperam o seu BTC imediatamente em vez de viverem na incerteza.
🔒 Se os fundos roubados forem alguma vez recuperados, as reivindicações são reembolsadas ao longo do tempo.
O Bitcoin sempre foi sobre auto-soberania—mas também sobre uma comunidade que se une quando é importante.
Ficaria feliz em doar BTC para ajudar a iniciar isto.
#DailyOrbit

🚨 Carteiras de Hardware Coldcard — O Que Está Acontecendo
A versão curta: Vários dispositivos Coldcard (Mark 3, Mark 4, Mark 5 e Q) tinham uma falha de segurança onde a aleatoriedade usada para criar as suas chaves Bitcoin era fraca e previsível. Isto significa que os atacantes podem já conhecer a sua frase-semente — a sua chave mestra de 12-24 palavras — e estão a trabalhar para esvaziar carteiras neste momento.
Está Seguro? Verifique Estas 3 Coisas
Provavelmente está seguro se fez alguma destas coisas ao configurar:
✅ Lançou dados pelo menos 50 vezes para gerar aleatoriedade extra
✅ Adicionou uma frase-passe forte — significando palavras ou caracteres verdadeiramente aleatórios, não algo como "bitcoin" ou uma frase
✅ Gerou a sua frase-semente noutro local e apenas a importou para o Coldcard
Se Não Fez Nenhuma Dessas Coisas — Quão Urgente É?
Mude imediatamente — Carteira Coldcard única sem proteção extra. Os atacantes já estão a tentar combinações. É uma questão de tempo.
Mude com urgência — Adicionou alguma proteção mas foi fraca (menos de 50 lançamentos de dados, ou uma frase-passe simples como uma palavra ou frase).
Mude em breve — Usa vários dispositivos em conjunto (multisig) e dois deles são Coldcards. Os seus fundos ainda não desapareceram, mas o risco é real.
Prioridade mais baixa mas ainda assim corrija — Coldcard é apenas uma minoria da sua configuração e outros dispositivos são seguros. Tem tempo, mas substitua-o na mesma.
Para Onde Deve Mover o Seu Bitcoin?
Recomendações do Rob:
- River — uma empresa confiável só para Bitcoin, pode até congelar os seus próprios levantamentos
- Bitkey (a carteira de Jack Dorsey, vendida na Best Buy) — amigável para iniciantes
- Casa — bom para quem quer mais controlo mas com ajuda
- Unchained — bom para auto-custódia avançada
Conclusão
Se tem um Coldcard e não adicionou lançamentos extra de dados ou uma frase-passe forte e aleatória quando o configurou — trate isto como urgente e mova o seu Bitcoin para uma nova carteira agora.
Tem um Coldcard?
The most common question I am getting right now in the fall out of the news of COLD CARD MK3, MK4, MK5 and Q having compromised entropy, is:
"Rob, what would you do right now if you were in my shoes? Where would you send your bitcoin to be safe?"
I will share with you my list of what I would do, but first, there is AN URGENT SECURITY ADVISORY IN THE BITCOIN ECOSYSTEM.
Below is my personal assessment of the situation.
If you or someone you know:
Uses an MK3, MK4, MK5, or Q in a single signature
OR
A multi signature wallet where the cold card devices can move the funds on their own (Example, 2 cold cards and a Ledger).
Please continue reading. You may be in danger. If this does not apply to you, keep on reading if you like, but you are not impacted by this issue.
If you are still here, there are three identified mitigations that protect you at the moment. They are all different forms in which you may have brought your own entropy.
A: DICE - This is done by either rolling dice from the start, or adding dice rolls to the generated seed phrase. At least 50 dice rolls would be my threshold at 128 bits of entropy.
OR
B: PASSPHRASE - You used a passphrase of sufficient entropy (128 bits).
128 Bits of entropy pass phrase examples include RANDOM combinations of the following:
- 12 BIP 39 seed words.
- 10 common words in the english language
- 25 mixed lower case letters and numbers
- 20 if you use ASCII characters
Note on pass phrases: This does not include the same word 12 times, 10 words in a sentence, etc. This combinations of characters/numbers OR words should never have been seen or spoken before in the total sum of all human knowledge and experiences. It needs to be RANDOM for it to be entropy.
OR
C: EXTERNAL ENTROPY - Your seed phrase was derived entirely outside of the cold card ecosystem. (It was imported into the cold card, not generated on it)
Now, if you are still reading, and you do not have any of these mitigations in place, you need to move your funds. The urgency of circumstances are as follows:
TIER 1: AS SOON AS POSSIBLE
Scenario A: If you are in a signature wallet with an effected device, and did not use any of the mitigations listed above. You need to move funds right now. Find someone to help you, any moment your funds can be stolen.
Scenario B: If you have an N of N (eg 2 of 2, 3 of 3, etc) multisig of just cold card devices that did not have mitigations listed above (dice and/or passphrase).
Attackers will be grinding all of the combinations of compromised keys. They know all your seed phrases. You are compromised. It is just a matter of time for them to assemble the puzzle pieces together and steal your funds.
If this scenario is you, I will have more below on how to mitigate risk when broadcasting your transaction.
TIER 2: URGENTLY
If you are in a single signature wallet with an effected device, and you used either less than 50 dice rolls OR a pass phrase less secure than what I shared above. The entire security of your bitcoin is reliant on how much of Dice AND Passphrases you applied to your wallet.
Attackers know your seed phrase. Your entropy from dice or pass phrase is the only thing protecting you. Did you add a pass phrase of 'bitcoin'? You are basically in tier 1. Did you use 6 words? You are not at tier 1, but you aren't safe. You need to make plans to move funds quickly.
TIER 3 SOON, BUT IMPORTANT CONTEXT:
You have a multi signature wallet where the compromised devices have sufficient ability to move the funds. An example is a 2 of 3 multisig where you have 2 cold cards and another signer.
The issue with Tier 3 is that an attacker may have already figured out your insecure seed phrases. This means when you broadcast your bitcoin transaction, an attacker in theory can then steal your funds.
NOTE: IF YOU ARE IN THIS SITUATION, AND YOU HAVE REUSED ADDRESSES, ALL REUSED ADDRESSES PUT YOU RIGHT BACK AT THE TIER 1 MOVE RIGHT AWAY YOUR FUNDS ARE AT RISK AT THIS VERY MOMENT
You should look into finding a way to use the @MARAFoundation_ slipstream service, which uses a private mempool. This means that by the time an attacker could see your attempted recovery, it is already in a block and not possible for them to steal funds.
TIER 4: KEY ROTATION. This is where you have an insecure cold card(s) in your multisig quorum, and you know that the other keys in your quorum are not impacted by this bug.
If there is a MK3,MK4,MK5 or Q in the quorum, BUT they either: 1. Rolled sufficient dice (50 min) 2. Have a strong pass phrase (as defined above). 3. Used entropy not sourced from the device, they are not impacted by this bug in the Cold Card (see notes earlier on mitigations).
You are in a position where a minority of your keys are compromised. Funds are safe, but you are at reduced security. Make plans when you are able to remove the compromised device from your wallet.
Now. With that security advisory out of the way, back to the question, what would I do in this situation?
Below is just my opinion, but you should not rely on only my opinion, you will have to make your own choices based on what you feel is best for you.
I want to be clear, if you are not on this list. It is not that I think your product/business is bad, insecure or at risk, I am directly answering the question of what I would do. This is my personal judgement given my decade of experience in bitcoin.
First, a disclaimer:
My bitcoin is at my company @AnchorWatch. I have full skin in the game in that if I'm offering a custody solution, there will never be another place I store large amounts of bitcoin long term for myself or my family, and it will be this way as long as I am here.
I was the first bitcoin that went on our Trident Vault platform. If the day ever comes, I will be the last bitcoin to leave the platform.
The years of what we built at AnchorWatch were for exactly moments like this. Avoiding catastrophic risk of ruin scenarios.
We offer 2 products:
1. Our Flagship Product where you as the customer can hold 1 or 3 keys, and we act as a cosigner. We leverage bitcoin native smart contracts which allow for your bitcoin to have different ways it can be spent across time.
2. Multi Institution Custody, where we let you distribute your keys across 3 institutions of ourselves, @bitgo and @CoinCorner. 2 of the 3 institutions must sign off on the transaction, and you have to present a Yubikey signature before withdrawing to mitigate deepfake and compromised accounts.
For both products as, since we are a cosigner, we are able to enforce rules like whitelisted addresses, and velocity controls (how much bitcoin can you send how often). You can even disable the send button on the platform if you so choose!
We also offer 1:1 insurance backed by Lloyd's of London.
If you want to learn more about what we do, hit up @_joerodgers or @BeccaAmilee to learn more, or check out our website.
Now with that out of the way, places where I'd leave my bitcoin (besides @AnchorWatch) in no particular order:
Custodian:
I'd trust my life savings at @River under a duress situation. This is one of those times. @Leishman and the entire team at River are elite operators. It is my favorite bitcoin services business in the market today outside of my own.
They own their own custody infrastructure, and at times like this, you want those who have extreme ownership and control over how their customer's money is being managed.
@River does monthly proof of reserves, and you can turn on the force field feature which will freeze withdrawals of bitcoin. They have a world class custody team as well, and are making improvements regularly with a larger upgrade that has been planned for a long time, happening later this year.
Collaborative Custody:
1. The @Bitkey is an incredible product with an elite team of engineers supported by the @BlockEng organization. They have exceptional bitcoin developers across @spiral_xyz and @CashApp teams who deeply understand Bitcoin.
@jack has been a long time believer in bitcoin who has built an organization that has no peer in the resources they have not just understanding bitcoin, but building on bitcoin.
You can pick it up a Bitkey at best buy today!
I do want to add a disclaimer that all keys are managed within the Bitkey ecosystem. The Bitkey team has gone to great lengths to keep things secure, but in light of recent events, I want to call that out. At the moment, the Bitkey is my only exception to a purist ideal of multi vendor multisig (more below).
2. @CasaHODL - @Nneuman and @lopp have been on top of this incidence response, and have built a very clean user experience to let people be safe. You can either use a 2 of 3 or 3 of 5 multisig with a great mobile app. Casa is the best UX for soverign collaborative multisig that exists in the market today.
3. @uncahined - Unchained pioneered the collaborative custody model and the multi institution custody model. They have been working around the clock trying to support customers and have even been able to use slip stream going the extra mile on short notice to keep customers bitcoin safe.
Self Custody:
I have spent close to $5k on LLM tokens over the past 24 hours scanning over a hundred bitcoin related repositories. As of now, I have seen no vulnerability that has me concerned about any hardware device outside of the Cold Cards.
Even so, you can't be sure. So I would follow the @mflaxman "Bitcoin 10x security guide". Its how I held my bitcoin before I founded @AnchorWatch, and even though the guide is 6 years old, the principles are timeless. I would remove his suggestion of using the cold card and replace it with any other hardware wallet. I would replace the cold card with a @Ledger at this time if it were my decision. You can pick up a Ledger up at Best Buy in the US.
Michael pioneered multi vendor multisig as a concept, and if you want a fully sovereign solution, as of today there is no better mental model on how to think through this, he has advanced tabs to further increase the security. For his cold card guide he fairly calls out the added benefit of rolling dice, which would have saved you today.
I think the future is combining the tech we use at @AnchorWatch to move beyond the single signature/ multi signature paradigm of custody, with the principles of @mflaxman's 10x security guide and the support of collaborative custody.
More on that later, but I would check out @lianabitcoin from @Wizardsardine as well, they offer a fully open source wallet that enables these more advanced smart contracts and are security researchers in the bitcoin ecosystem.
With that, I'm going to get back to work. I will post a followup reply if I have additional information or any corrections or clarifications to make.

As perdas de Bitcoin $BTC na Coldcard aumentaram para 70 milhões de dólares após uma vulnerabilidade na carteira
A Galaxy Research reportou que mais de 1.000 BTC, no valor aproximado de 70 milhões de dólares, foram movidos de quase 1.200 endereços. A Coinkite alertou na quinta-feira que frases-semente criadas por dispositivos Coldcard Mk3 com a versão de firmware 4.0.1 ou posterior poderiam colocar fundos em risco. Mais tarde, a Coinkite expandiu o alerta para certas versões de firmware dos Mk4, Mk5 e Coldcard Q e lançou atualizações de firmware de emergência.
#OKXTraderVoices #NewHereStartHere #30YYieldAt19YHigh #SpaceXUnlockLooms #EarningsWeekAhead
O Hack da Carteira Coldcard é um Aviso para os Detentores de Bitcoin
Muitas pessoas acreditam que, uma vez que o seu Bitcoin está armazenado numa carteira de hardware, está completamente seguro. Este último incidente com a Coldcard mostra que a segurança também depende de como a carteira gera a sua frase-semente.
No final de julho de 2026, hackers exploraram uma falha no firmware que existia desde março de 2021. O bug enfraqueceu a aleatoriedade usada para criar frases-semente, permitindo aos atacantes recriar essas frases offline e roubar fundos sem nunca tocar nas carteiras de hardware.
O resultado foi devastador: cerca de 1.367 $BTC, no valor de quase 89 milhões de dólares, foram roubados de mais de 4.500 carteiras.
A Coinkite, a empresa por trás da Coldcard, reconheceu o problema e lançou atualizações de firmware de emergência. No entanto, simplesmente atualizar o seu dispositivo não é suficiente se a sua carteira foi criada usando o firmware vulnerável. Os utilizadores precisam de gerar uma nova frase-semente completamente nova no firmware atualizado e transferir o seu Bitcoin para a nova carteira.
O hack abalou a confiança nas carteiras de hardware, com alguns utilizadores até a mover fundos de volta para exchanges centralizadas, apesar do impulso para a autocustódia após o colapso da FTX. Outros, incluindo o CZ da Binance, lembraram os utilizadores que espalhar ativos por vários métodos de armazenamento é frequentemente a abordagem mais segura.
A maior lição é simples: a autocustódia continua a ser uma das melhores formas de proteger o seu Bitcoin, mas nenhuma solução de segurança é perfeita. Uma forte aleatoriedade ao criar a sua frase-semente, usar uma frase-passe e evitar um ponto único de falha pode fazer uma grande diferença.
A segurança não é apenas possuir uma carteira de hardware, é usá-la da forma correta.
#EarningsWeekAhead #30YYieldAt19YHigh #KOSPISurges14%
Aviso para quem estiver a auto-guardar-se com um Coldcard.
Já tive alguns clientes a perguntar sobre o exploit, por isso aqui está a versão limpa.
O problema está em alguns dispositivos Coldcard Mk3. Carteiras que geravam frases seed no firmware a partir de março de 2021 tinham uma falha. Os atacantes podiam recriar essas seed offline e varrer fundos sem nunca tocar no seu dispositivo.
Desde 30 de julho, cerca de 1.367 $BTC no valor próximo de 89 milhões de dólares foram drenados de mais de 4.500 endereços distribuídos em três ondas. A vaga mais recente está a direcionar-se a saldos mais pequenos, cerca de 0,1 $BTC cada. Pequeno não significa seguro aqui.
Contexto importante. Isto é específico do Coldcard Mk3. Ledger, Trezor, Bitkey e Jade não são afetados. Modelos mais recentes do Coldcard como o Mk4 e o Q também têm bom aspeto.
A parte difícil. Se a tua seed foi feita num Mk3 afetado, o problema é a seed em si, não o firmware que usas agora. Os investigadores dizem que a solução é mover as tuas moedas para uma nova carteira com uma seed gerada num ambiente seguro. Usar uma palavra-passe, multisig ou sementes de lançamento de dados reduz bastante o risco.
Para SMSFs, isto é diferente. As criptomoedas do fundo devem ser mantidas em nome do fundo, e esta semana provou que a autocustódia não é automaticamente mais segura. Seja qual for a sua responsabilidade, a custódia faz parte da gestão do fundo. Trate-a com a mesma seriedade que a sua auditoria.
Liguei a explicação mais clara na resposta. Se acha que pode ser afetado, não espere.
#30YrYieldTopOrStart #30YrYieldTopOrStart #USIranBackToTalks $BEAT $ADA $SOL

🚨 PROVÁVEL 4.ª ONDA ORGANIZADA DE ATAQUES COLDCARD A OCORRER AGORA MESMO
AINDA HÁ TXS SIMILARES NO MEMPOOL À ESPERA DE CONFIRMAÇÃO E AS TXS ANTERIORMENTE CONFIRMADAS INDICAM RBF OPT-IN, VERIFIQUE OS SEUS FUNDOS E PODE SER QUE CONSIGA USAR RBF PARA SAIR DISTO
padrão identificado:
blocos 960,778 - 960,792 (últimas ~2,5 horas, ainda em curso):
• 218 transações, 462 endereços vítimas, 216 destinos novos.
• 388.92748828 BTC
• TODOS têm ZERO inputs anteriores ao limite do firmware Coldcard
• Taxa 13,8 varreduras/bloco vs 0,3/bloco numa janela de controlo pré-incidente = ~45x elevado
• Topologia é 1:1 — um destino novo por vítima, apenas UM destino recebeu duas varreduras. Sem funil coletor.
• Alguns fundos já foram varridos para endereços de 2.º salto.
estes SÃO PROVÁVEIS vítimas Coldcard -- correspondem ao padrão de utxos vulneráveis Coldcard e o padrão elevado de transações dá-me grande confiança de que são mais uma onda de ataques
MOVA OS SEUS FUNDOS FORA DOS DISPOSITIVOS COLDCARD O MAIS RÁPIDO POSSÍVEL E USE TAXAS DE TX ALTAS
mais detalhes virão à medida que isto se desenvolve
Um esvaziamento de cold-wallet de $89 milhões acabou de testar toda a tese de autocustódia, e o Bitcoin recusou-se a ceder.
Uma falha de firmware que remonta a anos em dispositivos Coldcard permitiu que atacantes limpassem milhares de endereços. Isto não é um hack de exchange nem uma falha de smart contract. É uma falha de entropia a nível de hardware que atinge armazenamento puramente offline.
A resposta do mercado é a verdadeira história. $BTC continua a defender a zona dos $63,000. Esse tipo de absorção perante más notícias genuínas mostra que a venda forçada já passou em grande parte e a liquidez restante é seletiva em vez de panificada. As instituições parecem contentes em observar em vez de vender, enquanto os fluxos de ETF permanecem mistos e o tom hawkish do Fed mantém as esperanças de cortes nas taxas adiadas.
$ETH mantém o seu intervalo recente. $SOL e $XRP mostram ofertas relativas melhores, e $ADA continua a liderar a valorização das grandes capitalizações. $BNB, $DOGE, $TRX, $HYPE, $AVAX, $LINK, $DOT, $UNI, $ATOM e $NEAR estão maioritariamente a acompanhar o mesmo tom cauteloso de risco sem catalisadores separados.
A minha opinião: episódios como este aceleram a mudança para soluções de custódia institucionais e wrappers de ETF. Ao mesmo tempo, qualquer alavancagem remanescente em nomes de maior beta permanecerá apertada até ao próximo dado macroeconómico claro. Agosto já se mostra volátil; o volume fino do fim de semana e o timing regulatório por resolver só agravam isso.
Mantenha-se atento à fita, respeite os intervalos e deixe a ação do preço confirmar o próximo movimento real.
