Coldcard Bug Drains $38M in Bitcoin

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Coinkite's Coldcard hardware wallet suffered a software bug that let attackers recreate wallet recovery phrases and drain ~600 BTC (~$38M) from users' self-custodied wallets, with the flaw since patched but funds still at risk on previously generated seeds.
- Coinkite CEO NVK told affected users in an open letter to move funds immediately using updated best practices, warning that firmware updates alone do not eliminate the risk for seeds already created on vulnerable firmware.
- The underlying flaw was that certain firmware versions generated wallet seeds using far less randomness than intended, making them susceptible to brute-force attacks.
- ARK Invest's Lorenzo Valente said consumers have "traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk," and argued users are "better off today holding funds across several publicly-traded exchanges or ETFs."
- Casa CEO Nick Neuman called the recommended workaround—rolling physical dice to supplement wallet randomness—a "non-starter for 99% of people."
- Blockaid CEO Ido Ben-Natan noted that most H1 2026 crypto losses came from compromised keys and operational security failures rather than smart contract hacks, and said the Coldcard incident fits that pattern, with exposure originating at the key-generation stage.
- Bitcoin commentator Guy Swann called the incident "the worst hit in bitcoin history to the most knowledgeable and 'properly secured' bitcoiners," noting it isn't an exchange hack but "thousands of individuals having their personal private keys recreated out from underneath them."
Why it matters: When a respected, open-source hardware wallet fails at the key-generation stage and even ARK Invest starts recommending ETFs over self-custody, the "not your keys, not your coins" argument loses a major data point—$38 million worth of it. For everyday investors, the incident reframes regulated products from a compromise into the safer default.




