1,596 Bitcoin. $100 million. 7,300 addresses swept clean across four days. That is what the Coldcard firmware exploit has cost Bitcoin holders since July 30, 2026. The number keeps rising.
This is not an exchange hack. There is no company that failed to protect customer funds, no custodian to point at, no terms of service that covered this scenario. These were people doing everything the Bitcoin community taught them to do. Cold storage. Air-gapped devices. Seeds written in steel. Coins held offline for years. And on July 30 , some of them in the early hours of the morning , it was gone.
The Coldcard exploit is the worst self-custody failure in Bitcoin history. It deserves an honest accounting: what happened, what it means, what to do right now, and why none of this diminishes the deeper promise that brought people to Bitcoin in the first place.
What Happened: A Bug Hidden Since 2021
The vulnerability traces to Coldcard firmware version 4.0.0, released by Coinkite in March 2021. In that update, a configuration error caused devices to bypass their hardware random number generator. Instead of drawing entropy from the dedicated hardware chip , the source of true randomness that makes a Bitcoin seed unpredictable , the firmware fell back to MicroPython's software-based deterministic fallback, seeded by non-secret chip data.
The result: seeds that should have carried 128 bits of entropy were effectively reduced to 40. That is not a subtle difference. 128-bit entropy means the keyspace is larger than the number of atoms in the observable universe. 40-bit entropy is searchable with modest computing resources if you know where to look.
For five years, the flaw sat dormant. Coinkite ran its own internal security reviews, including AI-assisted code audits. The flaw passed undetected. What found it, according to Coinkite's own incident report, was a different AI model , one used by an unknown attacker, methodically scanning old firmware versions for exploitable patterns.
The first sweep happened at 01:10 UTC on July 30. In 25 minutes, 594 BTC was drained from approximately 500 single-signature wallets. By 01:56 UTC it was over , $38 million gone before most of the world had woken up. Galaxy Research tracked the on-chain movement in near-real time and published its analysis by midday. The pattern was unmistakable: a systematic sweep, address by address, the attacker already holding the private keys before a single transaction was broadcast.
A second wave came hours later. Then a third. By August 4, Galaxy Research confirmed 1,596 BTC stolen from more than 7,300 addresses. Fortune reported 1,816 BTC across 5,200 addresses and a figure of $116 million. Bloomberg put total losses above $100 million. The attack may still be ongoing.
Coinkite CEO Rodolfo Novak has urged all users with seeds generated on affected firmware to act immediately. The critical detail: restoring an old seed to updated firmware does not fix the problem. The seed itself is compromised. Users must generate a new seed on patched firmware and move funds to the new address. The old coins must move first.
Which Devices Are Affected
The vulnerability affected Coldcard Mk2 and Mk3 hardware wallets. Users who set up their devices on firmware 4.0.0 or later versions that carried the flaw forward are at risk. Coinkite has published a checker on their website. The single most important thing you can do right now: verify your firmware version, check whether your seed was generated on affected firmware, and if there is any doubt, move your funds immediately.
One critical finding from Galaxy Research: multisig wallets were not affected by the sweep. The attack was surgical , it targeted single-signature wallets because those can be spent with a single key. A 2-of-3 multisig arrangement requires two keys from different sources, which means a compromised Coldcard key alone cannot drain funds. This is not a minor footnote. It is the most important technical lesson from the entire incident.
Trust But Verify: The Mantra That Broke Down
The Bitcoin community has a saying: not your keys, not your coins. The logic is sound. When you hold Bitcoin on an exchange, you are trusting a third party with custody of your wealth. Exchanges fail. They get hacked. They go bankrupt. Mt. Gox cost 850,000 BTC. FTX cost billions. The case for self-custody , holding your own private keys on a hardware device that never connects to the internet , has been made clearly and compellingly for a decade.
Coldcard was, by many accounts, the gold standard. It is made by Coinkite, a Toronto-based company with a strong reputation in the Bitcoin-only community. The device is air-gapped, designed to sign transactions without ever touching an internet-connected computer. Security researchers respected it. It was the wallet recommended to people who were serious about self-custody. It carried the trust of the most security-conscious segment of the Bitcoin ecosystem.
That trust was not misplaced. Coldcard is a well-engineered product built by people who care deeply about Bitcoin. What the exploit reveals is something more uncomfortable: even the best hardware, built by the most capable team, run by people with the right values, can carry a silent flaw for five years without anyone knowing. Not because of negligence. Because software is hard, entropy is subtle, and the attack surface of a hardware wallet extends to every line of firmware ever written.
"Trust but verify" is the mature version of "not your keys, not your coins." It means: self-custody is right, and also, verify that your self-custody implementation is correct. Verify the firmware. Verify the seed generation process. Verify the entropy source. Verify with multiple devices. Most people who chose Coldcard were acting on trust , in the product, in the company, in the community , and doing so reasonably. The lesson is not that they were wrong to trust. The lesson is that trust in any single point of failure is a risk, no matter how trusted that point is.
Jonathan Goodman followed every rule. He stored his Coldcard in a safety deposit box. His 18.25 BTC was held across multiple safes. He never shared his seed phrase. He kept every device isolated from online exposure. None of it mattered on July 29, 2026, because the flaw was not in his security practices. It was in the entropy generated the day he first set the device up, four years earlier.
The Bitcoin adage needs an update: not your keys, not your coins. But also: not your entropy, not your security.
The Weight of What Was Lost
It is worth pausing here. Before we talk about what to do next , multisig, ETFs, diversification strategies , it is worth sitting with what this actually means for the people who lived it.
Somewhere, there is a person who spent five years accumulating Bitcoin in small amounts. A software engineer who put aside money every month. A nurse who read about Bitcoin in 2021, believed in it, bought a Coldcard because she wanted to do it right, and set up her wallet carefully following a tutorial. A father who bought his first Bitcoin in 2022 and never sold through every correction because he believed he was building something for his kids. Families in Nigeria and Argentina and the Philippines who saw Bitcoin as protection against currencies that had already failed them once. Retirees who had moved a portion of their savings into cold storage because they had lost faith in banks.
These are not abstractions. The Reddit forums are full of them. A user named Weary-Discipline591 posted that more than 3 BTC disappeared , years of disciplined investing, gone in a transaction they never authorized. Moneycontrol documented victims in India: Rs 15 crore worth of Bitcoin drained in 7 minutes, described as lifetime savings. Yahoo Finance ran the story of Jonathan Goodman, who did everything right and still lost $1.6 million.
Bitcoin's promise is profound. It is a system that does not ask permission. It does not freeze accounts. It does not require a government's recognition or a bank's approval. It does not discriminate by passport, by credit score, by geography. For billions of people living under monetary systems that have been weaponized against them , through inflation, through capital controls, through outright confiscation , Bitcoin represents something that almost no other technology has offered: the possibility of holding wealth that no one can take from you.
That promise is not broken by the Coldcard exploit. Bitcoin itself performed exactly as designed. The network is intact. The blockchain is intact. The protocol is intact. What failed was a layer above Bitcoin , the human and software infrastructure around it. And that distinction matters enormously, not as a defense of what happened, but because the promise that drew people to Bitcoin remains true.
But the promise of sovereignty cuts both ways. It means your gains are yours. It also means your losses are yours. There is no customer service number. There is no FDIC insurance. There is no dispute resolution. The coins that left those 7,300 addresses on July 30 are not recoverable. The attacker holds them. That is the irreversible finality of the Bitcoin ledger working as intended , only this time, working against the people who believed in it most.
It is genuinely devastating. There is no softer word for it. These are real people who made a principled choice to hold their own money, who trusted a product and a community, who followed the advice they were given, and who woke up one morning to find that the floor had given way. Some of them will recover. Some will not. For some families, this is a blow that will take years to absorb. For all of them, the community that told them self-custody was the answer owes them honesty, not defensiveness.
This happened. It was real. And the correct response is not to dismiss it, or to say "this is why Bitcoin is risky," or to retreat into ideology. The correct response is to grieve it honestly, learn from it completely, and help the people still holding compromised wallets act before they become the next entry in the tally.
What To Do Right Now
If you hold Bitcoin on a Coldcard device, this section is the most important thing you will read today.
First: determine whether your wallet is affected. Coinkite has published guidance at their website. The affected firmware is 4.0.0 and subsequent versions that did not fix the entropy bug. If you set up your wallet between March 2021 and the date of the patch, treat your seed as compromised.
Second: move your funds immediately. Do not wait. Do not delay to research further. The attack is ongoing. Send your Bitcoin to a new wallet generated on a different, verified device with confirmed secure entropy , a Trezor Safe 5, a Foundation Passport, a BitBox02, or any hardware wallet with a verified clean seed generation process. Move first, investigate later.
Third: do not restore your old seed to the new firmware. This is the critical error many people will make. The seed itself is the problem. Updating the firmware on your Coldcard and importing the old seed does not fix anything. The compromised seed generates the same weak private keys regardless of which firmware processes it. Generate a new seed. Send to the new address. Then verify the old wallet is empty.
Fourth: if you are unsure, ask. The Bitcoin community has rallied around this. Jameson Lopp at Casa and other experts have published step-by-step guides. Do not try to navigate this alone if you are uncertain.
Beyond Coldcard: A Better Architecture for Your Bitcoin
The Coldcard exploit is not an argument against self-custody. It is an argument against single points of failure.
Multisig is the most important structural upgrade available to Bitcoin holders today. A 2-of-3 multisig wallet requires two of three separate private keys to authorize a transaction. Those keys can be held on different hardware devices, from different manufacturers, generated at different times. If any single device is compromised , through a firmware flaw, physical theft, or destruction , the funds cannot be stolen. The attacker needs two keys, not one.
The Coldcard exploit did not touch a single multisig wallet. Not one. That is not a coincidence. It is the architecture working.
Services like Casa, Unchained Capital, and Sparrow Wallet (for self-managed multisig) make this accessible to non-technical users. A 2-of-3 setup with keys distributed across a Coldcard (once patched and freshly seeded), a Trezor, and a Foundation Passport is substantially more secure than any single hardware wallet, regardless of brand or reputation.
For holders who do not want to manage the complexity of multisig, institutional custody has matured significantly. Coinbase Prime, BitGo, Anchorage Digital, and Fidelity Digital Assets offer regulated, insured custody with proof-of-reserves audits. This is not the same as leaving Bitcoin on an exchange. These are dedicated custody institutions with segregated holdings, cold storage, and regulatory oversight. For holdings above a threshold you would not want to risk on a single hardware device, institutional custody is a rational complement to self-custody, not a betrayal of it.
For investors who want Bitcoin exposure without the custody responsibility entirely, the spot ETF market has matured into a legitimate option. BlackRock's $IBIT, Fidelity's $FBTC, and 21Shares' $ARKB hold Bitcoin in institutional custody on behalf of investors. Citi research estimated that ETF flows account for 45% of weekly Bitcoin price movements. These products carry counterparty risk , they are not the same as holding your own keys , but for a portion of a portfolio, or for investors who reasonably assess that custody risk outweighs sovereignty risk in their specific situation, they are a legitimate tool.
The right architecture depends on who you are, how much you hold, and what risks you are most exposed to. No single model is right for everyone. What the Coldcard exploit demonstrates clearly is that the model of relying on any single device, single manufacturer, or single custody approach is a single point of failure. Diversify. Distribute. Verify.
The Lesson the Community Must Learn
The Bitcoin community has a habit of circling the wagons when self-custody fails. The instinct is to say: the technology is sound, the protocol is intact, this was a third-party implementation problem. All of that is true. And it is not enough.
If the community continues to tell people that self-custody with a single hardware wallet is the right and only answer, more people will be hurt. The answer is not to abandon self-custody. The answer is to tell the truth about what self-custody actually requires: redundancy, verification, ongoing attention, and a willingness to build an architecture rather than buy a device.
Not your keys, not your coins. Also not your entropy, not your security. Also: not your redundancy, not your resilience.
Bitcoin offers something extraordinary. The ability to hold wealth that no government can seize, no bank can freeze, no company can confiscate. That promise is worth protecting. Protecting it means being honest about the full stack of risks involved in holding it , and building accordingly.
To the people who lost funds in the Coldcard exploit: this community owes you better than defensiveness. You did what you were taught to do. The infrastructure failed you. That is not your fault. And the best thing any of us can do is make sure it does not happen to the next person.
Move your funds. Verify everything. Build redundancy. The sovereignty Bitcoin offers is real. Protect it accordingly.
Thanks, Lance.