Price:

Coldcard flaw destroys single-key Bitcoin custody

Aug 8, 2026Summary from 2 podcasts.
  • A five-year-old firmware flaw in Coldcard wallets drained over $130 million in user Bitcoin.
  • Attackers cracked weak keys in seconds and sniped public recovery transfers in the mempool.
  • Private relays and multi-vendor multisig setups are replacing single-hardware wallets across the ecosystem.

The panic selling has turned into a structural reckoning. While early reports focused on the headline $130 million loss from CoinKite’s broken wallet firmware, the deeper damage is now ripping through Bitcoin's broader security layer. Historical privacy sets are collapsing, and emergency rescue operations are forcing holders to rely on private mining relays to bypass predatory bots.

The catastrophe traces back to March 2021, when a preprocessor macro error in Coldcard's custom firmware silently disabled the hardware random number generator. Instead of throwing an error or halting operations, the system fell back to a software default with only 32 to 40 bits of entropy. Cryptographic signatures tied the fatal code commit directly to CTO Peter Gray's personal key, revealing that the change bypassed peer review after CoinKite abandoned open-source libraries.

On The Jack Mallers Show, Jack Mallers detailed how that mathematical shortcut stripped devices of their primary defense. Instead of forcing an attacker to search a space larger than the known universe, the firmware left user funds protected by a sequence easily guessed on a consumer laptop.

"A 40-bit search space requires only a trillion guesses."

- Jack Mallers, The Jack Mallers Show

That trivial math allowed automated scripts to sweep funds across public blockchains within seconds. When panicked users tried to transfer their assets to fresh wallets, mempool snipers watched for outgoing transactions, calculated the underlying seed, and submitted competing Replace-By-Fee transactions with higher gas costs to hijack the funds in transit.

To survive the predatory mempool, distressed holders turned to an unlikely savior. Marathon's Slipstream, a private transaction relay long criticized by purists for centralizing block space, routed over 5,600 Bitcoin directly to miners. By keeping recovery transactions off public nodes, Slipstream prevented automated bots from front-running emergency transfers.

On TFTC: A Bitcoin Podcast, host Marty Bent and Galaxy Research head Alex Thorn emphasized that the victims were not reckless traders or DeFi speculators. They were disciplined, long-term stackers who followed every self-custody rule, bought hardware air-gaps, and held coins dormant for years without leaking seed phrases.

"Single-key cold storage is no longer a safe baseline."

- Marty Bent, TFTC: A Bitcoin Podcast

The collateral fallout extends far beyond stolen balances. Because attackers now hold the master keys to thousands of compromised addresses, they can retroactively map past CoinJoin mixing rounds. Identifying single Coldcard users inside historical pools de-anonymizes every other participant in that transaction, destroying plausible deniability for thousands of untargeted holders.

At the same time, automated AI probes are overwhelming open-source maintainers. Swapping protocols like Boltz and Zeus Lightning were forced to suspend operations after machine-driven vulnerability scans flooded their infrastructure with exploit attempts. Small developer teams can no longer patch code at the speed black-hat AI agents identify flaws.

The era of trusting a single hardware manufacturer for sovereign security is over. Sovereign custody now requires multi-vendor multisig setups where no single firm's firmware error can reach a signing threshold. The lock didn't fail because Bitcoin broke; it failed because the community trusted a black box.

Source Intelligence

- Deep dive into what was said in the episodes

CATASTROPHIC COLDCARD BUGAug 3

  • The bug, which existed for five years, appears to have been recently identified with assistance from AI, possibly through OpenAI's Cypher program utilized by Rob Hamilton's team for auditing Bitcoin projects.
Also discussed on this episode: (12)

Custody (6)

  • A critical vulnerability in Coldcard hardware wallets (versions 4.0.1 and later, or any model after 4.0.0) compromises private keys due to a faulty random number generator.
  • The catastrophic Coldcard bug, introduced in March 2021, compromises seeds generated on any device after that date unless sufficient dice roll entropy (over 100 rolls) or a passphrase was used.
  • Hosts advise all Coldcard users to immediately move their funds off the devices and to cease using the product entirely, regardless of previous protective measures like passphrases or multisig.
  • The hosts had previously conducted Coldcard workshops since December 2019 at Chaincode Labs with figures like Evan Kaludis and James O'Byrne, demonstrating features like dice rolls and passphrases.
  • Hosts concede to complacency, having placed too much trust in CoinKite's NVK and Peter; they now believe the concept of a "magic bullet" beginner-friendly solution for high-value self-custody is dead.
  • The hosts will now refrain from directly recommending specific custody solutions, instead laying out options and emphasizing multi-vendor multisig and robust passphrases as critical for long-term secure Bitcoin storage.

Media (2)

  • The hosts express deep regret and take accountability for recommending Coldcard for seven years, admitting their past confidence was misplaced despite consistently advocating "don't trust, verify."
  • The Coldcard vulnerability was publicly disclosed on August 3, 2023, at Bitcoin block height 960885, prompting hosts to release this podcast immediately to maximize user notification efforts.

Safety (4)

  • The Bitcoin community has rallied to assist affected users, with Rob Hamilton (@Roboneham on X) publishing an extensive guide detailing Coldcard vulnerabilities, migration options, and recovery steps.
  • Attackers are actively brute-forcing compromised Coldcard seeds using GPUs, while authorities are investigating an attacker who reportedly pinged a centralized API provider to look up vulnerable addresses.
  • The hosts clarify the vulnerability is entirely CoinKite's responsibility, stating their firm 1031 is a minority investor (under 10%) with NVK and Peter maintaining majority ownership and control.
  • Users are strongly advised not to update Coldcard firmware, as new releases may brick devices; instead, the immediate priority should be transferring all funds off the compromised hardware.

Unpacking the Coldcard Exploit | FREEDOM TECH FRIDAY 50Aug 1

  • If a user generated their seed with 50-98 independent dice rolls, they achieved 128 bits of entropy, bypassing the software bug. 99 or more rolls provided 256 bits of entropy.
  • Multi-vendor multisig users, such as a 2-of-3 setup, are safe from direct fund loss because one compromised Coldcard key is insufficient to move funds, but they should rotate the key.
  • Zach explains that Foundation's Passport devices are not affected, as they combine multiple entropy sources including an open-source avalanche noise source, avoiding reliance on black-box silicon.
  • Zach attributes the bug to Coldcard's move away from free and open-source software (FOSS) in early 2021, replacing GPL code with a proprietary 'source available' library, LibNGU, which lacked community scrutiny.
Also discussed on this episode: (9)

Custody (4)

  • A Coldcard hardware wallet exploit led to approximately 600 Bitcoin, valued at about $38 million, being emptied from around 500 single-signature wallets within 30 minutes.
  • Q reports that updated estimates suggest over 1,000 Bitcoin have been stolen, emphasizing that the situation is still evolving and users who lost funds did nothing inherently wrong.
  • Q states that the crucial factor for determining risk is the firmware version on the Coldcard when the seed was *generated*, not the current firmware version.
  • Seth advises all users to move funds from any seed generated on a Coldcard due to this issue, even if they used dice rolls or a passphrase, as the vulnerability window varies.

Coding (2)

  • The exploit affects Coldcard Mark 3 devices on firmware version 4.0.1 and later, Mark 4 and 5 devices before version 5.6, and Q devices on firmware 1.5 or earlier.
  • The vulnerability stems from a core code rewrite in March 2021 that stopped using the device's hardware randomness for seed generation, instead relying on predictable software randomness.

Privacy (2)

  • Seth warns that privacy for non-Coldcard users could be damaged if they participated in coinjoins or payjoins with vulnerable Coldcard users, as transaction histories are now traceable.
  • For migration, Seth advises moving individual UTXOs one at a time to unique addresses and randomizing timing to preserve privacy, though sweeping all funds is simpler for security-first users.

Education (1)

  • Q cautions against scammers and impersonators who will exploit the panic, reminding users to never give out seed words and to only use official channels for support.