frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

https://medium.com/mountain-movers/the-coldcard-disaster-gets-worse-the-hack-may-have-reached-88-6-af507b028594
24•paulpauper•54m ago

Comments

chistev•9m ago
Will crypto ever gain widespread adoption with constant news like this?

Or, given that previous hacks and losses didn't affect the price from shooting up to new highs, is this the perfect time to buy?

Aurornis•8m ago
The Bitcoin communities seem to really be struggling with this hack. The people losing their coins in this case were following best practices. Typically when someone loses their coins there’s a big pile-on to victim blame them for making some mistake. I think it’s comforting to others to be able to identify a mistake someone else made and then convince yourself that you’re too smart to make the same mistake.

In this case, there isn’t much of a mistake to point out. I’ve seen a couple attempts from people trying the told-you-so routine using some arguments about multisig wallets as the only option, but mostly it looks like people are panicking and wondering if their choice of wallet has some undiscovered vulnerability waiting to be exploited. I mostly try to stay away from Bitcoin communities but in events like this it spills over everywhere. I feel sorry for anyone who lost coins, of course, but it’s also interesting to watch the communities grapple with reconciling their appreciation for irreversible key-based transactions with the realities of how this works when their money is on the line. The old ideas about having perfect OPSEC and being smarter than the other coiners are starting to get weakened with examples like this.

My guess is that the next phase is to revise history and form a consensus that Coldcard was never a recommended wallet and that it was obvious to everyone with good OPSEC at the time.

nullc•5m ago
> Perhaps the most compelling forensic observation is that the first vulnerable firmware was released on March 17th, 2021. From that date onward, we see stolen coins beginning to pour into the few shared addresses used by the attacker.

this is an inexcusable slop-y error that made me press close on the tab.

While no one knows if there might have have been earlier exploitation, the new exploitation just started and did not extend back to the vulnerable firmware release.

mirashii•5m ago
The root cause seems to be known, unlike what this article implies. A bunch of other articles discuss the entropy issue, https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt for one I found quickly.
soared•5m ago
Interesting topic, but I don’t like this writing style. It’s a lot of words to say very little and repeats sentence structure often. The author assumes the reader knows about this hack already, and doesn’t not provide context on what it is, or details like why the attacker is storing coins in 4,000+ wallets.
stblack•5m ago
This is the best technical analysis I have seen, so far.

https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt

It doesn't appear that Coinkite, the company behind ColdCard products, had mature senior engineers in the loop. At least, no engineers who could flag such sloppy (and ongoing to this day) code commit practices.

AI and the iPod Test

https://www.psychologytoday.com/us/blog/the-digital-self/202607/ai-and-the-ipod-test
1•speckx•1m ago•0 comments

Show HN: Mapping Jensen Huang's five-layer AI stack to engineering degrees

https://ai-five-layer-map.pages.dev/
1•ithkai92•1m ago•0 comments

Show HN: Mousecrack – Bypass captchas with deep learning

https://github.com/puffinsoft/mousecrack
1•ReactRocks•3m ago•0 comments

I pointed my agent security tool at myself and four of the bugs were mine

https://agentmetry.ai/blog/dogfooding-found-five-bugs
1•blitzcrieg1•4m ago•0 comments

I built a real self-evolving operating system: Fable-OS

https://github.com/robiot/fable-os
1•robiot•6m ago•1 comments

Microsoft Paint used as a monitor to run Doom at up to 35 FPS

https://www.tomshardware.com/video-games/retro-gaming/microsoft-paint-used-as-a-monitor-to-run-do...
2•sbulaev•7m ago•0 comments

An OPML list of (most) blogs participating in Blaugust

https://82mhz.net/posts/2026/08/an-opml-list-of-most-blogs-participating-in-blaugust/
1•speckx•7m ago•0 comments

Show HN: EvoChess – start with 8 pawns, evolve your army

https://penkovsky.github.io/evochess/
2•penkovsky•8m ago•0 comments

Claude for ADHD: The Coding Workflow I Built for My Brain

https://chudi.dev/blog/claude-code-adhd-workflows
1•thenobsta•11m ago•0 comments

Steeping through data and brewing a database

https://pv.wtf/posts/steeping-through-data
2•dracyr•12m ago•0 comments

Fuse.js

https://github.com/krisk/fuse
1•handfuloflight•12m ago•0 comments

Falco: Tiny browser engine written from scratch in Rust

https://github.com/poxk/Falco
2•adamnemecek•13m ago•0 comments

YouTuber Hank Green says his AI usage is 'not healthy'

https://old.reddit.com/r/nerdfighters/comments/1vbmoj5/on_hank_admitting_he_used_chatgpt_for_his_...
1•embedding-shape•14m ago•0 comments

GenRec: Towards LLM-Native Recommendation at Netflix

https://netflixtechblog.com/genrec-towards-llm-native-recommendation-at-netflix-f20be6f643e3
2•Uriopass•14m ago•1 comments

2012 Boeing 727 crash experiment

https://en.wikipedia.org/wiki/2012_Boeing_727_crash_experiment
1•handfuloflight•16m ago•0 comments

When You Reject Cookies, You Might Be Agreeing to Arbitration

https://blog.ericgoldman.org/archives/2026/07/when-you-reject-cookies-you-might-be-agreeing-to-ar...
1•HotGarbage•17m ago•0 comments

Metropolis 1998

https://yesbox.itch.io/metropolis1998
1•doener•18m ago•0 comments

Dogfooding at scale: migrating cdnjs to Cloudflare's Developer Platform

https://blog.cloudflare.com/cdnjs-dev-platform-migration/
1•CharlesW•18m ago•0 comments

How China Keeps Tabs on Foreigners

https://www.nytimes.com/2026/08/02/world/asia/china-surveillance-foreigners-database.html
4•adriand•19m ago•1 comments

Show HN: Growth-Ratio Energy Function as Leading Indicator of Agent Task Failure

https://vishalvermalabs.com/papers/empirical-lyapunov-stability-agent-failure/
1•visha1v•20m ago•0 comments

Show HN: Offline and Private AI Anime Girlfriend

https://play.google.com/store/apps/details?id=com.clarai&hl=en_US
1•clarai-waifu•20m ago•0 comments

Adopt AI or Die? "The God Test" proposes AI is an opportunity and epochal threat

https://newrepublic.com/article/213738/artificial-intelligence-god-test-adopt-ai-die
2•CharlesW•20m ago•1 comments

Get Claude Code for Free

https://www.bestmillionstartups.com/best/how-to-use-claude-code-for-free-2026
1•thebrevn•20m ago•0 comments

Self-healing agents are just a loop you forgot to build

https://www.lorekit.io/blog/self-healing-agents
1•mthines•24m ago•0 comments

The Wild Wild West of Lego Datacenters

https://newsletter.semianalysis.com/p/the-wild-wild-west-of-lego-datacenters
1•speckx•25m ago•0 comments

Why I Watch Soccer

https://unpredictabletokens.substack.com/p/why-i-watch-soccer
1•jac08h•25m ago•1 comments

Ask HN: Would you buy a Bambu Lab for microchips?

1•dylansuttonc•27m ago•1 comments

Show HN: YouTube Videos Matched to Duolingo Units

https://lingolingo.app/french-course-companion/section/1/unit/1
1•yunusabd•27m ago•1 comments

Harvesting SSH Credentials: Insights from My Honeypot Network

https://uphillsecurity.com/articles/harvesting-ssh-credentials-insights-from-my-honeypot-network/
3•whatbackup•28m ago•0 comments

DroidCap: OS Support for Capability-Based Permissions in Android (2019)

https://publications.cispa.de/articles/conference_contribution/DroidCap_OS_Support_for_Capability...
2•chme•30m ago•0 comments