Loading prices…
🩸BEARISH

Coldcard bug drains $38M in BTC from self-custody wallets

Nearly 600 BTC were stolen from a flaw in Coldcard's firmware that let attackers reconstruct wallet seeds, reopening the case that institutional products like BlackRock's IBIT now make more sense for…

Coldcard bug drains $38M in BTC from self-custody wallets
Coldcard bug drains $38M in BTC from self-custody wallets
Coldcard bug drains $38M in BTC from self-custody wallets
Coldcard bug drains $38M in BTC from self-custody wallets

A software flaw in Coinkite's Coldcard hardware wallet has led to the theft of nearly 600 BTC worth roughly $38 million, exploiting a bug in certain firmware versions that generated wallet seeds with far less randomness than intended and left them vulnerable to brute-force attacks. The vulnerability has since been patched, but Coinkite CEO NVK warned in an open letter that existing users must generate entirely new wallets and move their funds, because the fix does not retroactively secure seeds already created on vulnerable firmware.

Why it matters

The incident strikes at one of Bitcoin's foundational promises: the ability to hold assets without trusting a bank or exchange. Bitcoin commentator Guy Swann called it "the worst hit in bitcoin history to the most knowledgeable and 'properly secured' bitcoiners," noting that the theft targeted individual private keys rather than a centralized custodian's hot wallet. ARK Invest's Lorenzo Valente went further, arguing that "the self-custodial hardware space is a disaster at this point" and that users have effectively traded counterparty risk for software, hardware, supply-chain, and operational risks. Casa CEO Nick Neuman added that asking ordinary users to supplement wallet randomness with physical dice rolls is "a non-starter for 99% of people."

Market impact

The exploit fits a broader pattern flagged by blockchain security firm Blockaid: most crypto losses in the first half of 2026 came not from smart contract hacks but from compromised keys and operational security failures. Taproot developer Udi Wertheimer argued the incident exposes how unrealistic passive custody has become, with holders now needing either to monitor threats constantly or pay a professional custodian to do it. That calculus is likely to channel more mainstream capital into regulated vehicles like BlackRock's IBIT. Amicus co-founder David Lawrence said new investors looking at the fallout may simply conclude, "I'm safer to just buy IBIT," adding that the dream of eight billion people holding their own bitcoin in cold storage is "done."

Related tokens
$BTC

Frequently asked questions

  1. What happened in the Coldcard exploit?

    A bug in certain Coldcard firmware versions generated wallet seeds with far less randomness than intended, making them vulnerable to brute-force attacks. Attackers used the flaw to reconstruct recovery phrases and steal nearly 600 BTC worth roughly $38 million from users who believed their wallets were secure.

  2. Has Coldcard fixed the vulnerability?

    Coldcard has patched the firmware, but Coinkite CEO NVK warned that affected users must generate entirely new wallets and move their funds. Updating the firmware does not retroactively secure seeds already created on vulnerable versions.

  3. Why are bitcoin advocates calling this the worst self-custody failure?

    Bitcoin commentator Guy Swann and others note that the attack did not target a centralized custodian's hot wallet, but rather the private keys of individual users running what was considered the most secure self-custody setup. The victims were the most technically careful holders, not careless ones.

  4. How does this affect spot bitcoin ETFs like IBIT?

    Analysts including Amicus co-founder David Lawrence argue the incident will push new investors toward regulated products like BlackRock's IBIT rather than self-custody. The reasoning is that institutional custodians carry dedicated security teams, removing the technical burden from individual holders.

  5. What does Coldcard recommend affected users do?

    Coinkite CEO NVK urged users to move their funds immediately using updated best practices before reading further guidance. The recommended fix is to generate entirely new wallets on patched firmware rather than relying on firmware updates alone, since old seeds remain vulnerable.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 1h ago
Open original →