Luke Dashjr, one of the original core BTC developers, says someone stole “basically all” his BTC by compromising his PGP key; a wallet shows ~217 BTC were moved
A Bitcoin OG and core developer Luke Dashjr claims his PGP key was compromised, resulting in virtually all his Bitcoin being stolen from him on Dec. 31.
CointelegraphStephen Katte
Context & Ripple Effects
The reported loss sits alongside prior coverage of custody failures that reached beyond ordinary online-account theft: prosecutors alleged a remote theft of 713 BTC from a seized hardware wallet, while a fault-injection recovery of a Trezor wallet showed that physical wallet protections also have limits.
Dashjr's case adds compromised PGP credentials to that record. The visible movement of roughly 217 BTC makes the incident a concrete reminder that control of the keys and systems around a wallet matters as much as the wallet device itself.
First-order effects
Luke Dashjr says he has lost control of virtually all of his BTC after the alleged PGP-key compromise, with roughly 217 BTC moved from a wallet.
The reported wallet movements give the claimed theft an on-chain trail, even though attribution of the party controlling the destination remains unresolved in the supplied coverage.
Second-order effects
Bitcoin holders relying on a single signing credential face renewed pressure to separate wallet custody from the identity and key-management systems used around it.
Hardware-wallet makers and custody providers must contend with a broader security comparison: the earlier alleged remote theft from a seized hardware wallet and Dashjr's claim both center on compromise paths outside a straightforward blockchain transaction.
Third-order effects
If incidents across PGP credentials, hardware wallets, and physical attacks persist, crypto custody will be judged less by whether assets are self-custodied than by the resilience of the full key-management process.
The pattern favors custody designs that reduce dependence on any one credential or device, though the supplied coverage does not establish which safeguards would have prevented Dashjr's reported loss.
The trend: Bitcoin custody risk is shifting from blockchain-level concerns toward failures in the credentials, devices, and operational systems that control access to wallets.
@LukeDashjr Sorry to see you lose so much. Informed our security team to monitor. If it comes our way, we will freeze it. If there is anything else we can help with, please let us know. We deal with these often, and have Law Enforcement (LE) relationships worldwide.
Sad to see even an OG #Bitcoin Core Developer lost 200+ BTC ($3.5 million). Self custody have a different set of risks. We will try to monitor and see where we can help. 🙏 https://twitter.com/...
> Self custody have a different set of risks Self custody and financial sovereignty are the ENTIRE point of this movement. Ten years from now it will be as easy and as second-natured as having an email address. If you don't get this, you have no business here. You're Fiat 2.0. ht…
If an OG core #Bitcoin dev failing to manage his own private keys doesn't tell you that the private key is the biggest pain point in crypto - I don't know what will. This needs to be solved for mass crypto adoption. And there'll be a big prize waiting for whoever does.
Bad way to start 2023: realize that you had $3.5M in Bitcoin stolen from you yesterday. If a Bitcoin developer can't safely store his own keys, normal people can't either. We are very far from scaling self-custody in crypto. https://twitter.com/...
cryptocurrency has never advanced beyond the wires-on-a-lab-bench prototype stage https://davidgerard.co.uk/... this is why real finance runs on centralised trusted custodians ofc in crypto you can't trust those either https://twitter.com/...
We're not offering a serious alternative to the existing financial system when even extremely technical people cannot keep their crypto secure Priority order 1. Decentralize nodes 2. Improve usability of self custody tools 3. Scalability 4. Everything else https://twitter.com/...
Luke materially shifted human civilization with his open source contributions to Bitcoin. Before dunking on Luke, post your GitHub. https://twitter.com/...
Perhaps implementing the Digital Asset Recovery tool? Seems like a more justified answer than, not your keys, not your Bitcoin eh? https://twitter.com/...
Self custody in its current form is too difficult. Luke is a Bitcoin developer and absolutely obsessed with security. He can still get his bitcoin stolen. Now imagine an average dude. https://twitter.com/...
This is sad to hear but, unfortunately, this kind of thing is not an uncommon story: secure key management is very difficult to do right for people with experience and training; it's nigh impossible for everyone else. This is something the industry as a whole needs to do better. …
Ok my theory: Maybe luke used LastPass, which was hacked the other day. If he stored seeds, PGP private keys etc. there and the hackers managed to brute force the LastPass file, it is clear. Be careful where you store things! (Just my thoughts, nothing is confirmed yet!) https://…