The Coldcard Hack: What Happened, Who It Hurt, And Why Sovereignty Still Wins.

The Coldcard Hack: What Happened, Who It Hurt, And Why Sovereignty Still Wins.

 

594 BTC. Gone in 25 minutes.


Not to a scam. Not to a phishing link. Not to a careless click.


To a bug. A firmware bug sitting quietly inside a hardware wallet since March 2021, waiting five years to be found.

On July 30, an attacker drained roughly 594 BTC, around $38 million, out of nearly 500 Coldcard wallets. It took 25 minutes. Researchers who studied the attack noticed something telling: the biggest wallets got hit first. That's not luck. That's someone who did their homework before pulling the trigger. Around 562 BTC of what was stolen has since been moved into one wallet, where it's sitting for now.

Here's the plain-English version of what went wrong. Every Bitcoin wallet needs a truly random secret to generate its keys. That randomness is supposed to come from a dedicated chip built for exactly that job, so it can't be predicted or reverse-engineered. A bug in Coldcard's firmware quietly turned that chip off and used something predictable instead, tied to details like the device's serial number. So instead of a secret nobody could guess, some devices were handing out secrets that could be worked out with enough knowledge of the bug. That flaw has reportedly been sitting in the firmware since 2021. Five years, unnoticed, until now.

Coinkite, the company behind Coldcard, has confirmed the issue. Mk3 devices from that era are hit hardest. Mk4, Q, and Mk5 users on older firmware have a smaller but still real version of the same problem. Bottom line: if your seed was made during that window, treat it as burned. Not "probably fine." Burned.

 

Condolences To Those Affected


If you lost sats in this, we're sorry. Genuinely.

You didn't do anything reckless. You did the responsible thing. You bought a hardware wallet. You held your own keys. You opted out of the system that was never built for you. And the tool you trusted to protect that decision let you down.

That's a hard thing to sit with. No one in this space is above feeling it. Take the time you need.

 

Self Custody Isn't The Problem. Blind Trust Is.


Some people will look at this and say self-custody failed. It didn't.

A product failed. A company's process, from checking the firmware to designing the hardware, let something slip through. That's not the same thing. Holding your own keys was never a promise that nothing can ever go wrong. It's a promise that if something does go wrong, you're the one who finds out first, and you're the one who gets to act on it right away.


Compare that to leaving your Bitcoin on an exchange. When an exchange gets hacked or goes under, you find out from the news, then you wait in line, then you wait for lawyers, hoping to get some of it back. When it's your own setup, you find out through your own tools, on your own time, and you can move your coins before most people even know there's a problem.


This isn't a reason to give up on self-custody. It's a reminder of what self-custody actually asks of you: double-check your tools, don't put all your coins in one basket, and never fully trust any single piece of hardware, even the one in your hand right now.

To be sovereign is to take full responsibility for yourself. You put your trust in yourself to test your setup, verify it, and keep checking it. When you hold your own keys, you're not just storing wealth, you're acting as the sole custodian of your own property. That's a huge privilege, and it comes with real weight. Take it seriously.

Don't just trust a wallet because it's popular. Check it for yourself.

 

What To Do Right Now


If you own a Coldcard, or any hardware wallet, treat this as your prompt to review your setup. Specifically:

Check your device and firmware version.
Coinkite has published which models and firmware versions are affected. Find out exactly where your device stands before you touch anything else.

Never trust a patch alone.
An update fixes the bug going forward. It does not undo the damage to a seed that was already created under the broken randomness. If your seed was made in the vulnerable window, it stays compromised, forever, no matter where you move it.

Set up a fresh wallet on hardware you trust, fully updated and verified.
Whether that's a patched Coldcard or a different device entirely is your call. This gives you a brand-new set of secret recovery words, generated safely instead of using the flawed process. Then move your coins to that new wallet. Don't just import the old seed somewhere else and carry on. Retire it for good.

Add a passphrase.
Think of it as an extra secret word on top of your normal 24-word seed, one that only you know and that never touches the device's own randomness. Early data on this attack shows wallets with a passphrase held up far better than those without one.

Consider spreading the risk.
Don't keep everything on one seed phrase or one device. Splitting your Bitcoin across multiple wallets means one bad firmware update, lost device, or mistake can't wipe out everything you own in one go.

Look into multisig.
This is a setup where more than one device has to approve a transaction before your coins can move. Even if one device is compromised, your coins stay safe, because the attacker would need to compromise several devices at once, not just one.

Don't rush, and don't panic-move funds through channels you don't fully trust.
Scammers watch moments like this closely, hoping people panic. But rushing isn't just risky because of scammers, it's how honest mistakes happen too: sending to the wrong address, skipping a verification step, or moving funds before you've actually confirmed your new setup is safe. Slow down. Double-check every address, every step. A rushed transaction is how a bad week turns into a worse one.

Verify things yourself where you can.
This is exactly why people run their own Bitcoin node instead of trusting someone else's word for it. Checking things independently is what catches problems a closed review process misses.

A personal note.
Coinkite has patched the bug and put out the fixes. Credit where it's due. But a patch doesn't undo five years of trust sitting on top of a flaw nobody caught. Personally, this has shaken my confidence in Coldcard. That's not a call to panic-sell your device tonight. It's a reminder that loyalty to a brand should never outweigh loyalty to your own coins. If a product loses your trust, you're free to walk. That's the whole point of sovereignty.

 

The Standard Doesn't Change


Bitcoin didn't fail this week. A piece of hardware did. That distinction matters. It's the whole reason self-custody exists in the first place, so that one company's mistake is recoverable, not catastrophic.

Hold your keys. Test your setup. Never trust blindly, always verify. Every single time.


The system isn't perfect. Bitcoin is still early, and early means there's still a lot to learn. Sometimes that learning comes the hard way, through moments exactly like this one. As bad as this event is, and again, huge condolences to anyone affected, it's the kind of hard lesson that makes the whole space stronger in the long run. Every flaw found and fixed in public is one less flaw waiting quietly for the next five years.


Bitcoin Sovryn is a network of sovereign individuals, aligned with truth, with Bitcoin, with each other. Nobody has to go through a moment like this alone. If you've been affected, or you just need a hand reviewing your setup, reach out. We're here.


Be early. Be free. Be Sovryn.

0 comments

Leave a comment