Praveen Perera’s forensic work on the first Coldcard theft wave is both impressive and unsettling. He traced 1,195 drained addresses, reconstructed 328 seeds covering 949.7 bitcoin, and reproduced the vulnerable path through the wallet’s broken random-number generation. Yet 153 addresses holding 132.95 bitcoin remain unexplained. Those addresses were swept with the same transaction builder as the reconstructed set, but neither Praveen nor any independent researcher he has spoken with has been able to reproduce even one of their seeds. Praveen tested 104 billion candidate seeds and 5.6 trillion derived addresses. His conclusion is appropriately careful: the public reconstruction may be missing an input, a device-state assumption, or an entirely different candidate-generation method.

The honest answer is that the attacker’s information advantage remains unresolved. Across the broader incident, Galaxy Research has identified 1,596 bitcoin stolen across three high-confidence waves, worth roughly $100 million around today’s price. Including a suspected fourth wave would bring the estimate to 2,055 bitcoin, or roughly $130 million. It is hard to imagine how awful it must feel to follow the accepted security advice, keep your keys offline, and still watch your life savings disappear because the device generated a key somebody else could reproduce.

As if that were not enough, Trezor disclosed that ShipMonk, one of its fulfillment partners, exposed order data for 13,689 customers. Trezor says its wallets and private keys remained safe, while names, emails, phone numbers, and home addresses were exposed. Buying specialized bitcoin hardware usually means creating a record that connects your identity and physical location to a device used for storing bitcoin. If the vendor or one of its partners mishandles that record, a criminal may learn exactly where to look. Out of the frying pan and into the fire.

I am more cautious today about giving absolute self-custody advice, and I suspect many bitcoiners are having the same rethink. Self-custody remains a fundamental part of bitcoin because the ability to hold and move your own money without permission is the entire point. Bitkey and SeedSigner are both strong options for different users. SeedSigner has a particular privacy advantage because it can be assembled from ordinary off-the-shelf electronics, so an order history does not announce that you bought a bitcoin signing device. The principle survives. Our advice needs more humility.

Read the original article →