Alles richtig gemacht und trotzdem Bitcoin verloren/ I did everything right and still lost Bitcoin

Published on HivePostify by @der-prophet · Fri Sep 04 2026

Sieben Minuten genügten, um 18,25 BTC aus einer Coldwallet zu stehlen, die nie eine Verbindung zum Internet hatte.

Der Coldcard-Hack betraf vor allem solche Bitcoiner, die dem klassischen Selbstverwahrungsideal der Szene folgen. Unter den Opfern befand sich der kanadische Autor Jonathan Goodman als einer der am schwersten geschädigten Einzelnutzer der Angriffes. Im “Coin Stories”-Podcast von Natalie Brunell erzählt Goodman nun, wie er selbst von seinem tragischen Bitcoin-Verlust erfuhr und was in den Tagen danach geschah.

Goodman erfuhr von dem Angriff über einen Facebook-Beitrag eines befreundeten Bitcoiners, der alle Coldcard-Nutzer aufforderte, ihre Bestände sofort zu verschieben, um diese in Sicherheit zu bringen. Sein erster Gedanke war daraufhin, dass ihn das schon nicht betreffen werde, weil Meldungen über Angriffe mittlerweile zum Alltag eines jeden Krypto-Anlegers gehören.

Er startete seine Wallet-Software zur Kontrolle, wartete auf den Abgleich mit der Blockchain – und fand alle Bestände als Abflüsse verbucht.

Nach Recherchen von The Defiant und Decrypt wurden am Abend des 29. Juli zwischen 21:36 und 21:43 Uhr alle seiner drei Wallets vollständig geleert, insgesamt 18,25 BTC im Gegenwert von rund 1,6 Millionen Kanadischen Dollar. Es waren Bitcoin, die Goodman ab Ende 2020 über anderthalb Jahre gekauft und dauerhaft für seine Kinder zurückgelegt hatte.

Ursprünglich kaufte er im Jahr 2021 insgesamt drei Coldcard-Geräte und verteilte seine Bestände anschließend zwischen ihnen, für den Fall, dass eines davon ausfällt. Die Hardware lag im Bankschließfach, seine Seed-Phrase stanzte er zusätzlich in Metall. Damit war die Wortfolge, aus der sich alle privaten Schlüssel einer Wallet ableiten lassen, scheinbar gegen Diebstahl, Verlust und Feuer abgesichert.

Doch der Angriff erfolgte aus einer Richtung, die in diesem Set-up nicht berücksichtigt wurde. Direkt bei der Einrichtung zieht eine Hardware Wallet eine sehr große Zufallszahl und übersetzt sie in zwölf oder 24 Wörter. Fachleute nennen das “Entropie”, im Kern ist es aber nichts anderes als die Frage, wie oft und wie ehrlich gewürfelt wurde. Ist diese Zahl erratbar, dann ist alles erratbar, denn aus ihr entstehen jeder Schlüssel und jede Adresse.

Die Coldcard-Firmware umging den Zufallsgenerator der Geräte. Sie nutzte stattdessen einen Software-Ersatz, der aus der Seriennummer des Chips startete und danach nichts Neues mehr aufnahm. In der Konsequenz fehlte es an Entropie, also an echter Unvorhersehbarkeit, und die Geräte erzeugten Wortfolgen aus einem viel zu kleinen Vorrat.

Vorgesehen waren 128 Bit Zufall, also so viele mögliche Wortfolgen, dass kein Rechner der Welt sie durchprobieren kann. Nach Angaben von Coinkite blieben davon rund 40 Bit bei den Mk3-Geräten. Statt einer Zahl mit 39 Stellen kommen nur noch rund eine Billion Möglichkeiten in Frage. Und diese lassen sich durchprobieren. Eben das taten die Angreifer auch, berechneten zu jeder möglichen Wortfolge die passenden Adressen und prüften auf der Blockchain, welche davon gefüllt waren.

"Alex Thorn von Galaxy Digital verfolgt die Coins seit dem zweiten Tag des Angriffs und kommt auf 1.789 BTC aus 8.865 Adressen, beim Diebstahl rund 114,7 Millionen US-Dollar wert. 87 Prozent davon haben sich seither nicht bewegt. An der Bilanz der Geschädigten ändert diese Sichtbarkeit auf der öffentlichen Blockchain jedoch nichts.

Ich zitierte aus folgendem Artikel...

https://www.btc-echo.de/news/alles-richtig-gemacht-und-trotzdem-bitcoin-im-millionenwert-verloren-236786/

Mein persönliches Fazit:

Da verlässt man sich auf eine Hardware Wallet und wird dennoch bestohlen. Wir du durch dieses Beispiel siehst, ist nichts zu 100% sicher. Am sichersten scheint es mir sein Vermögen in Kryptowährungen auf verschiedenen Wallets, Geräten und Brokern zu verteilen.

Sei immer wachsam und bilde dich stetig weiter 😉

Und gib auch nicht auf Hive deine private Keys weiter, auch hier gibt es den ein oder anderen Betrüger.

---

English

Seven minutes were all it took to steal 18.25 BTC from a cold wallet that had never been connected to the internet.

The Coldcard hack primarily affected Bitcoiners who adhere to the community's classic self-custody ideal. Among the victims was Canadian author Jonathan Goodman, one of the most severely affected individual users. In Natalie Brunell's "Coin Stories" podcast, Goodman recounts how he learned of his tragic Bitcoin loss and what happened in the days that followed.

Goodman learned of the attack through a Facebook post by a Bitcoiner friend who urged all Coldcard users to immediately move their holdings to a safe location. His first thought was that this wouldn't affect him, since reports of attacks are now part of everyday life for every crypto investor.

He launched his wallet software to check, waited for the blockchain to synchronize—and found all his holdings recorded as outflows.

According to research by The Defiant and Decrypt, on the evening of July 29, between 9:36 p.m. and 9:43 p.m., all three of his wallets were completely emptied, totaling 18.25 BTC, worth approximately 1.6 million Canadian dollars. These were Bitcoins that Goodman had purchased over a year and a half, starting in late 2020, and permanently set aside for his children.

He originally bought three Coldcard devices in 2021 and then distributed his holdings among them in case one failed. The hardware was stored in a bank safe deposit box, and he also had his seed phrase stamped in metal. This meant that the word sequence from which all of a wallet's private keys could be derived was seemingly protected against theft, loss, and fire.

However, the attack came from a direction that this setup hadn't accounted for. During setup, a hardware wallet generates a very large random number and translates it into twelve or twenty-four words. Experts call this "entropy," but at its core, it's nothing more than the question of how often and how fairly the random number was generated. If this number is guessable, then everything is guessable, because every key and every address is derived from it.

The Coldcard firmware bypassed the devices' random number generator. Instead, it used a software substitute that started with the chip's serial number and then didn't accept anything new. Consequently, there was a lack of entropy, i.e., true unpredictability, and the devices generated word sequences from a far too small pool.

The intended system used 128 bits of randomness, meaning so many possible word sequences that no computer in the world could try them all. According to Coinkite, around 40 bits of the original number remained with the Mk3 devices. Instead of a 39-digit number, only about one trillion possibilities remained. And these could be tried out. That's precisely what the attackers did: they calculated the corresponding addresses for each possible word sequence and checked the blockchain to see which ones were populated.

"Alex Thorn of Galaxy Digital has been tracking the coins since the second day of the attack and has identified 1,789 BTC from 8,865 addresses, worth approximately $114.7 million at the time of the theft. 87 percent of these coins have remained untouched since then. However, this visibility on the public blockchain does not change the outcome for the victims."

I quoted from the following article...

https://www.btc-echo.de/news/alles-richtig-gemacht-und-trotzdem-bitcoin-im-millionenwert-verloren-236786/

My personal conclusion:

You rely on a hardware wallet and still get robbed. As this example shows, nothing is 100% secure. The safest approach seems to be to distribute your cryptocurrency assets across different wallets, devices, and brokers.

Always be vigilant and keep learning 😉

Posted Using [INLEO](https://inleo.io/@der-prophet/alles-richtig-gemacht-und-trotzdem-bitcoin-verloren-i-did-everything-right-and-still-lost-bitcoin--929)

Tags: #hive-167922#threadstorm#outreach#pob#cent#deutsch#bitcoin

View full post on HivePostify →

Join HivePostify — Pakistan's First Web3 Platform →