Loading prices…
🩸BEARISH

BTC Hack: Coldcard Flaw Drains $114M From 709 Wallets

The bug sat in open-source code for five years while a community built on 'don't trust, verify' outsourced its judgment to one vendor's reputation, Foundation CEO Zach Herbert argues.

BTC Hack: Coldcard Flaw Drains $114M From 709 Wallets
BTC Hack: Coldcard Flaw Drains $114M From 709 Wallets
BTC Hack: Coldcard Flaw Drains $114M From 709 Wallets
BTC Hack: Coldcard Flaw Drains $114M From 709 Wallets

A flaw in Coldcard's firmware has drained nearly $114 million in bitcoin from more than 709 addresses, with the first sweep emptying roughly 500 wallets in 25 minutes, Foundation CEO Zach Herbert reported in a CoinDesk column. The bug entered Coldcard's codebase in March 2021 and sat in public, open-source view for more than five years before being exploited. Herbert frames the incident as a community-wide failure of verification, not a single-vendor lapse.

Why it matters

The deeper read is structural. Coldcard's source was always open for inspection, but the 'don't trust, verify' ethos only works when qualified reviewers actually look, and for five years, effectively nobody did. The bug entered the codebase shortly after Coinkite CEO Rodolfo Novak publicly regretted Coldcard's GPL license; Coldcard then moved to the Commons Clause, whose own FAQ states the resulting software is no longer open source. A sweeping rewrite followed, and the March 2021 commit that stripped out the last GPL code is the same commit that broke seed generation.

The second failure is what happened to the people who did look. In 2020, Shift Crypto and Nunchuk disclosed a multisig verification flaw in Coldcard; Novak branded the disclosure 'PR terrorism' on the Citadel Dispatch podcast. In 2023, when WalletScrutiny reported reproduction problems in older builds, the response labeled the project incompetent or malicious and floated litigation. Independent follow-up later confirmed genuine reproduction problems and concluded nobody had acted in bad faith.

Market impact

The dollar figure is climbing. Roughly 500 wallets were drained in the first 25 minutes, with the total now at $114 million and rising across 709+ addresses. Coldcard users on vulnerable firmware cannot recover by updating; affected seeds must be migrated to wallets generated on a clean entropy source.

The reputation cost runs deeper. BTC Sessions host Ben Perrin publicly admitted he gave Coldcard's behaviour a pass because he assumed confidence came packaged with security. The episode is reverberating through self-custody recommendations and product reviews that carried the same unverified claims.

Related tokens
$BTC

Frequently asked questions

  1. How long did the Coldcard entropy bug sit in the codebase before being exploited?

    The bug entered the codebase in March 2021 and sat in public, open-source view for more than five years before being exploited.

  2. Why didn't independent researchers catch the Coldcard bug sooner?

    Herbert argues Coldcard's culture punished independent review, with a 2020 Shift Crypto and Nunchuk multisig disclosure branded 'PR terrorism' and a 2023 WalletScrutiny reproduction report dismissed as malicious.

  3. Can updating Coldcard firmware recover bitcoin lost in the exploit?

    No. Updating firmware does not repair seeds generated on vulnerable versions; users must migrate to wallets generated on a clean entropy source.

  4. What role did Coldcard's license change play in the entropy bug?

    The bug entered the codebase shortly after Coldcard moved from GPL to the Commons Clause, whose own FAQ states the resulting software is no longer open source. The March 2021 commit that stripped the last GPL code is the same commit that broke seed generation.

  5. What does Foundation propose after the Coldcard hack?

    Herbert calls for applying Bitcoin's 'don't trust, verify' ethos without favourites: not trusting the vendor, not trusting its critics, and verifying every claim independently.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 1h ago
Open original →