Coldcard Exploit Drains $70M, Tests Bitcoin Self-Custody Model
A firmware flaw in Coldcard hardware wallets allowed an attacker to steal $70 million in bitcoin without physical access, undermining a core premise of crypto self-custody.
A critical firmware flaw in Coldcard hardware wallets allowed an attacker to steal $70 million worth of bitcoin on July 30 without ever touching the physical devices. The exploit targeted a vulnerability dating back to March 2021 that weakened the randomness used to generate recovery seeds on certain models. By reconstructing private keys entirely offline, the attacker bypassed the primary security advantage of cold storage.
Initial on-chain reports estimated the damage at 594 bitcoin taken from roughly 500 wallets in 25 minutes. However, subsequent analysis by Galaxy Research significantly revised the scale of the breach. The firm found that 1,082.65 bitcoin were actually drained from 1,196 addresses over a 41-minute window. Many of the compromised wallets had sat dormant for years before the sudden sweep.
Coldcard manufacturer Coinkite has acknowledged the bug, issued an apology, and pushed emergency firmware updates. The company warned affected users that simply patching the software will not protect funds generated on the flawed versions. Instead, Coinkite advised creating entirely new recovery seeds on updated devices and carefully migrating assets to those fresh addresses.
The incident has forced a reassessment of self-custody risk in the digital asset sector. Hardware wallets are widely promoted to institutional and retail investors as the most secure method for holding bitcoin offline. The Coldcard breach demonstrates that even established cold storage solutions can harbor undetected, catastrophic vulnerabilities for years.
Responding to the theft on Saturday, Binance founder Changpeng Zhao urged crypto holders to distribute their holdings across multiple devices. “Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!” he said.
While diversifying storage locations limits exposure to a single point of failure, it introduces new operational hazards. Investors must now weigh the remote risk of a dormant firmware exploit against the daily friction and heightened key management complexity of maintaining a multi-wallet architecture.