The Coldcard Hack Explained: How a 2021 Bug Drained Over $130 Million in Bitcoin
I spent hours researching and documenting the lessons from this hack. Now, let's look at what actually happened, why it matters to anyone who holds crypto in self-custody, and the real stories from pe
Hello, crypto investors. For days, I have been following the distressing news about the Coldcard wallet hack. Sadly, many families lost their Bitcoin fortunes not because they carelessly shared their keys with strangers online or connected their devices to phishing sites that drained their wallets.
No, that wasn’t the case. Many of them followed the security advice we've been given to protect their BTC holdings. Yet their accounts were still wiped out.
This recent event has reminded me of something that many crypto investors overlook: investing in cryptocurrency is one thing, but keeping your assets secure presents an entirely different challenge.
You can time the market, pick the right coins, and survive every crash the market throws at you. None of that matters if you lose access to the Bitcoin you’ve spent years accumulating.
That’s what makes this incident so important. The story should concern every self-custody user, regardless of which hardware wallet brand they trust.
You may ask…
What Is the Coldcard Hack, and Why Is This Topic Relevant?
Coldcard is a hardware device designed to store Bitcoin. It wasn’t a budget product from an unknown manufacturer. For years, it was the hardware wallet serious Bitcoin holders recommended without hesitation.
Yes, it’s Bitcoin-only, uses dual secure elements, has fully open-source firmware, and has a reputation for paranoid attention to security details. If you’d asked me which cold storage wallet to trust with a life-changing amount of Bitcoin, Coldcard would consistently rank near the top of my list.
But a few days ago, that reputation took a direct hit. Hackers exploited a bug in the device’s firmware and began draining Bitcoin from Coldcard wallets in coordinated waves. The flaw had gone undetected in the firmware since March 2021.
So far, blockchain investigators at TRM Labs have tracked roughly 1,816 BTC, valued at about $116 million, stolen from more than 5,200 addresses in four waves. That makes it the third-largest crypto hack of 2026, a year that had already recorded more than $1.2 billion in losses from 276 incidents.
Once again, this should make us rethink how we approach Bitcoin custody.
If you hold a substantial amount of Bitcoin in self-custody, I strongly believe you should consider spreading your holdings across two or more hardware wallets from different manufacturers. That’s the approach I shared with our paid members during this incident.
The goal isn’t to eliminate every possible risk. It’s to avoid keeping your entire Bitcoin position on a single device.
Remember, as investors, we don’t put all our eggs in one basket. This diversification principle shouldn’t be limited to the coins you own but should also apply to how you store them. Next, let’s discuss…
What Caused the Coldcard Vulnerability…
Here’s the part that should bother anyone who owns a hardware wallet, regardless of brand. Based on the stories I have followed and the articles I have read, the secure elements in the Coldcard were never compromised. Every physical security mechanism performed exactly as designed. The failure occurred in the software process that generates your seed phrase in the first place.
According to a disclosure from Block’s Bitcoin engineering and security team, a single code change made on March 1, 2021 — introduced in Coldcard firmware version 4.0.0 — silently routed seed generation through a software-based pseudorandom number generator instead of the device’s dedicated hardware random number generator.
The practical effect was severe. Entropy that should have measured a full 128 bits fell to as little as 40 bits on Mk2 and Mk3 devices, and roughly 72 bits on later models.
The vulnerable code path affected more than just standard wallet seeds; it affected every function on the device that relied on that same random number generator, including paper wallet private keys, seed backup masks, device cloning keys, and stored password features.
Painfully, paper wallets were hit especially hard because their private keys came straight from the flawed randomness, with no extra processing step standing between the bug and your funds. Now, let me ask, were you affected by the hack?
»»» Before you continue, I am giving away The Crypto Cycle Checklist. Click HERE to claim yours or skip to keep reading.
Here are a few unaffected categories:
Seeds created with at least 50 fair, independent, private dice rolls entered during setup.
Wallets protected by a strong, unique BIP-39 passphrase
Multisig setups where the keys didn’t all come from vulnerable devices.
The original Mk1 device
Coinkite’s TAPSIGNER, OPENDIME, and SATSCARD products, which run on entirely different codebases.
This brings us to an important discussion…
Is Bitcoin Self-Custody Still Safe Following the Coldcard Hack?
Well, this article isn’t an argument against self-custody. It’s an argument for treating self-custody as an ongoing responsibility rather than a one-time purchase you make and then forget about.
I’m a strong believer in crypto self-custody, but I also use centralized exchanges. I’m not saying one approach is right for everyone. Your choice should depend on your experience, risk tolerance, and comfort with managing your own security.
For some investors, keeping a portion of their assets on a reputable centralized exchange may be more practical, especially if they aren’t comfortable managing hardware wallets, seed phrases, firmware updates, and other aspects of self-custody.
Meanwhile, a centralized platform often provides customer support when issues arise, but that support doesn’t eliminate the risks of trusting a third party.
Sure, exchange custody comes with counterparty risk. The exchange could fail, suffer a security breach, freeze withdrawals, or lose access to customer funds. In some cases, there’s little an individual user can do to prevent those events.
On the other hand, self-custody removes that specific counterparty risk, but it introduces a different set of responsibilities. You become responsible for your seed phrase, device security, firmware integrity, backups, and the trustworthiness of the hardware and software supply chain.
You see, neither approach eliminates risk.
The real question is which risks you understand, which you can manage, and how you can structure your custody setup so that a single failure doesn’t wipe out everything you’ve spent years accumulating.
How to Protect Your Bitcoin Wallet Against This Type of Attack
Here are the three habits that address what this exploit exposed, and each applies regardless of which hardware wallet you’re running.
Use a BIP-39 passphrase — the “25th word.” This is a second input you provide alongside your standard seed phrase, and it generates an entirely different wallet from the same set of words.
Notably, wallets protected by a strong, unique passphrase were largely spared in this attack. But it has to be strong: long, randomly generated, and never built from a dictionary word, a memorable pattern, or a birthday. A short passphrase barely slows down an attacker who has already reconstructed your seed.
Track firmware like it actually matters — including when your seed was created, not just the version you’re running today.
This is the detail that trips people up. A firmware update installed today doesn’t tell you anything about the firmware that was running when your seed was originally generated. That earlier moment is the only one that matters for this specific vulnerability.
Many believed Coinkite had been explicit. CZ, Binance's founder, has this to say… “The thing is, with self-custody, devs patching the bug won't fix previously generated wallets. And devs have no way to reach users on air-gapped devices. Your wallet stays open to hackers until you act. I'm a believer in self-custody, but it puts the burden on you.”
Diversify hardware in multisig setups.
A 2-of-3 wallet split across a Coldcard, a Ledger, and a Trezor doesn’t fail just because one manufacturer had a bad five years — the attacker who reconstructs one key still needs a second key from hardware they never touched.
But the thing is, Multisig arrangements built entirely from a single vulnerable device line inherit the full risk, so diversification only works if the keys genuinely come from different manufacturers with different firmware stacks.
If everything we’ve discussed so far seems complicated to you, you’d better focus on storing your assets on centralized exchanges.
Before you continue, claim your Crypto Cycle Checklist HERE.
Real Stories From Coldcard Hack Victims And What They Teach Us
Everything you’ve read so far explains the technical breakdown and the mechanism. It doesn’t describe what it actually felt like. For that, let’s read stories we curated from victims themselves on X (Twitter).
Jonathan Goodman had $1.6 million CAD in Bitcoin on a Coldcard that had never connected to the internet, stored in a safety deposit box. He detected unauthorized outgoing transactions he didn’t make, all within a seven-minute window. He claimed he’d never shared his seed. His device never went online. He did everything the community recommends.
But when the hacker exploited the bug they found in a single line of code, none of the safety measures mattered, because the flaw wasn’t in anything he controlled — it was baked into the wallet before he even opened the box.
The lesson: You can lock a device in a vault forever, but it won’t prevent future losses if the infrastructure it depends on is compromised.
Adam Carson reported losing 6.42 BTC — roughly $400,000 — from a Coldcard that had never connected to the internet and was locked in a safety deposit box.
He wrote on X: No seed in the cloud, no photo on a phone, no password manager backup.
He spent hours afterward reviewing his own history for a mistake, hoping to find one, because at least a mistake would mean he understood what happened. He found nothing.
Tim Lamb was on a family vacation when news of the Coldcard hack broke. He had two Bitcoin set aside for his kids, with the seed backed up on a metal plate at home.
He wrote on X that he heard about the hack on Friday and spent a day deciding whether to cut the trip short. He didn’t think to ask a neighbor to check the wallet until Saturday evening. By Sunday morning, when it was checked, the funds were gone — swept out Saturday afternoon, hours before he’d had the idea.
I felt emotional reading Tim’s story because he was building a future for his lovely kids with Bitcoin, yet the hackers didn’t care.
ACEIN had his retirement savings stored on a Coldcard when he traveled to a conference without the device. Fortunately, he had a backup plan.
He recalled his seed phrase from memory, imported it into a software wallet, sent a small test transaction to Coinbase, and then transferred the rest of his funds. The test confirmed everything worked before he transferred the remaining balance.
Thank goodness he memorized his seeds; without that backup plan, this could have turned out very differently.
Now, just like Ishita, you might be wondering what the safest way to store Bitcoin actually is.
She asked a simple question: what is the safest way to store crypto right now?
I don’t think she expected the blunt answer she received.
Someone replied, “The safest option is never to get into crypto.” If you’re asking the same question, there’s your answer. On a serious note, you can split your holdings across a few hardware wallets or use two or more centralized exchanges. The IBIT (EFT) option is also available.
The Real Takeaway From This Article
Every story I’ve discussed points to the same gap: the distance between buying crypto and keeping it safe.
You see, buying Bitcoin is a one-time decision. Self-custody is different. It requires habits you need to maintain over time. That means checking firmware history, understanding how your passphrase works, reviewing your backup process, and knowing what your setup can and can’t protect against.
After reading the accounts from people affected by this incident, one thing stands out to me. Many of them didn’t ignore basic security steps. They followed the guidance available to them at the time.
Sadly, those instructions were incomplete, not because anyone was careless, but because a flaw introduced five years earlier became visible only the week they were used.
Buying Bitcoin gives you exposure. Keeping it requires maintenance — and that maintenance never really ends.
I hope this incident prompts you to take another look at how you store your Bitcoin. You know more now than you did before, and you are wiser.
If you were affected by the Coldcard wallet hack, I’d like to hear about your experience. If you weren’t, tell me which part of this article changed how you think about Bitcoin custody.
I’ll read and respond to every relevant comment.
Stay safe and stay vigilant.
Before you leave, claim your Crypto Cycle Checklist HERE.
If you want to dive deeper into our cycle thesis and see our accumulation zones for Bitcoin and altcoins on our watchlist, check out the Golden Buy Zone Blueprint.
Thanks for reading.
Jonas (Crypto Big Stories).



