Now that the dust has settled on the ColdCard security incident, two of our advisers - Andrew Finnie and Bayani Mills - sat down with Matthew Fraser from the Crypto Collective YouTube channel to discuss what went wrong, who was affected, what to do about it and how to minimise the chances of it happening to you in the future.
ColdCard hardware wallets, long regarded as the gold standard for Bitcoin self-custody, suffered a critical vulnerability that enabled attackers to drain >1,600Bitcoin - valued at roughly $130 million or more - from thousands of addresses. The incident, which unfolded in late July and early August 2026, struck users who had followed best practices: offline key generation, air-gapped devices, and careful storage of seed phrases. It has forced a hard reassessment of hardware wallet trust assumptions and single-signature setups.
What Happened
At its core, Bitcoin security depends on true randomness when generating private keys or seed phrases. ColdCard devices from Coinkite include a hardware true random number generator (TRNG) designed to supply high-entropy randomness for this purpose. A firmware change introduced around March 2021 (starting with version 4.0.1 and affecting subsequent releases on Mk2/Mk3, Mk4, Mk5, and Q models) caused a silent failure. The software checked for the existence of the hardware RNG but did not properly use it. Instead, it fell back to a weak software-based pseudorandom number generator.
The result was drastically reduced entropy. On older Mk2 and Mk3 units, effective entropy dropped to approximately 40 bits - equivalent to a search space small enough for determined attackers with modern computing resources to brute-force. Newer Mk4, Mk5, and Q models retained somewhat higher but still inadequate entropy (around 72 bits in estimates), far below the intended 128 bits or more for a standard BIP-39 seed. Attackers did not need physical access to devices, internet connectivity from the wallets, or social engineering. They reconstructed likely weak seeds offline and swept funds from corresponding on-chain addresses.
The first major wave hit on or around July 30, 2026, draining over 1,000 BTC from more than 1,000 addresses in under an hour. Subsequent waves followed at intervals, targeting additional addresses. Independent on-chain analysis confirmed losses in the range of 1,600–1,800+ BTC across thousands of addresses, with upper estimates approaching or exceeding $130–150 million depending on Bitcoin’s price and inclusion of suspected additional activity. Many affected wallets had been dormant for years; victims had done nothing “wrong” by conventional self-custody standards.
Passphrases (the so-called 25th word) provided a buffer for some users by expanding the search space, buying time to migrate funds. Pure single-signature setups without additional entropy sources such as verified dice rolls were most exposed. The bug went undetected for years despite security reviews, underscoring how subtle configuration or fallback errors can evade detection.
Coinkite released emergency firmware updates that restore proper hardware RNG usage for new seed generation. Critically, these patches do not repair seeds already created under the vulnerable firmware. Existing compromised seeds remain at risk indefinitely as computational power and attacker sophistication increase.
What to Do About It
If you generated a seed on an affected ColdCard model and firmware version (generally post-March 2021 releases prior to the July/August 2026 patches), treat those funds as potentially compromised and prioritize migration. Updating firmware alone is insufficient for existing wallets.
Immediate steps include generating an entirely new seed on patched firmware, a different hardware wallet, or via verified high-entropy methods (such as sufficient private dice rolls), then transferring funds to the new addresses. Do this carefully: verify addresses, send test transactions where appropriate, and avoid combining unrelated UTXOs unnecessarily if privacy or labeling matters. Temporary holding in a reputable exchange or a carefully set-up hot wallet can serve as a bridge for those lacking immediate alternatives, but these introduce their own risks and should not become permanent for significant holdings.
(Until the end of August 2026, The Bitcoin Adviser are offering 3 months of free service in multi-sig vaults, to allow affected individuals to evaluate both our service and alternative options, rather than make a poor decision in a hurry)
Longer-term, reassess your overall custody model against personal risk tolerance, technical competence, and family recoverability. Single-signature hardware wallets remain viable when implemented correctly with strong entropy and optional passphrases, but they concentrate risk on one device, one seed, and one individual’s knowledge. Multi-signature setups distribute that risk: typically requiring 2-of-3 keys held by different parties or devices. This removes single points of failure while preserving user control over spending decisions.
Collaborative or guided multi-signature services can help. Providers may act as a co-signer or hold one key under defined protocols, enabling estate planning, recovery if a key is lost or a holder becomes incapacitated, and structured setups for self-managed superannuation funds or family trusts. Users retain directive control, yet gain recovery paths that pure self-custody often lacks. Diversifying across different security approaches - some multi-sig, some carefully managed single-sig, limited operational amounts elsewhere - reduces concentration risk.
Education and community matter. Attend local Bitcoin meetups to discuss practical setups with others who have navigated similar issues. Avoid rushing into complex arrangements without understanding them; “slow is smooth and smooth is fast.” Evaluate whether complete sovereign self-custody is the right end state for every portion of your stack, or whether a maturity-matched approach (guided multi-sig for larger or long-term holdings, simpler options for smaller operational amounts) better fits your circumstances and those of your heirs.
Finally, remain vigilant against secondary scams. Phishing sites mimicking manufacturers, fake support channels, and social-engineering attempts spike after such events. Use only verified official channels and links provided by sources you trust.
Broader Lessons
The ColdCard incident does not kill self-custody. Hardware wallets and air-gapped signing remain powerful tools when entropy and implementation are sound. It does, however, illustrate that “your keys, your coins” transfers rather than eliminates risk: the risk now sits in firmware, random number generation, code review, and personal operational security. Trust minimization requires ongoing verification, diversification of methods, and realistic assessment of knowledge gaps - including those of family members who may one day need to recover funds.
Users who move promptly to new, high-entropy seeds or robust multi-signature arrangements can restore strong security. Those who treat the event as a catalyst for deeper education and tailored custody design will emerge better prepared. Bitcoin’s security model is only as strong as its weakest practical link; this episode exposed one and demands that holders close it.
We must not place all our trust in one device, business or individual. That creates a single point of failure. The uncomfortable truth we all must face is that single point of failure can also be ourselves.
Schedule a FREE security review with one of our advisers today, to identify any weaknesses in your setup, with practical suggestions of how to address them.