A firmware vulnerability that remained undetected in certain Coldcard hardware wallets for more than five years has triggered one of the largest known compromises of Bitcoin self-custody devices, prompting widespread fund migrations and reigniting debate over the safest way to store digital assets. Researchers say the flaw originated in firmware released in March 2021, when a coding error caused affected devices to generate wallet recovery seeds using a weakened software-based random number generator rather than secure hardware entropy. The reduced randomness made some seed phrases sufficiently predictable that attackers could reconstruct private keys offline without ever gaining physical access to the device.
Blockchain investigators estimate that attackers have stolen approximately 1,367 BTC, worth about $88.6 million, from more than 4,500 addresses. Galaxy Research identified an initial attack that drained roughly 1,000 BTC from more than 1,100 wallets in just 41 minutes on July 30, followed by three additional suspected attack waves, although investigators caution that not every affected wallet has been definitively linked to the vulnerability. Coinkite, the Canadian manufacturer of Coldcard, has released emergency firmware updates and instructed affected users to generate entirely new recovery seeds and migrate their Bitcoin immediately. The company emphasized that simply updating firmware is insufficient, because wallets created with vulnerable seeds remain compromised.
Firmware Bug Sparks Largest Custody Migration Since FTX
The incident triggered an immediate on-chain response. Blockchain analytics showed a sharp increase in small Bitcoin transfers as users rushed to move funds from potentially vulnerable wallets into newly generated wallets or regulated custodial platforms. Researchers described the migration as the largest wave of sub-1 BTC transfers since the collapse of FTX in November 2022, underscoring the urgency with which holders reacted once the vulnerability became public.
Coinkite Chief Executive Rodolfo Novak publicly apologized for the incident, saying the company was “heartbroken” and urging customers to act immediately. He said Coinkite is cooperating with blockchain investigators and law enforcement while continuing to determine the full scope of the compromise. The company also noted that wallets created using sufficient external entropy—such as at least 50 private dice rolls—are not affected by this specific vulnerability. Security researchers believe the attack demonstrates how even highly respected hardware wallets remain dependent on software quality. While the physical devices were never breached, a flaw in seed generation proved enough to undermine the security guarantees on which self-custody relies.
Self-Custody Debate Intensifies
The incident has reopened one of Bitcoin’s longest-running debates: whether self-custody remains the safest option for long-term holders. Advocates argue that self-custody still eliminates counterparty risk associated with exchanges, custodians and financial institutions. They contend the Coldcard incident represents an implementation failure rather than a failure of the self-custody model itself, noting that users retained full control over their assets and could migrate funds once the vulnerability became known.
Critics counter that the compromise illustrates how hardware wallets introduce their own risks through firmware, supply chains and operational complexity. Unlike exchange failures, vulnerabilities in seed generation can remain undiscovered for years before attackers exploit them. The broader lesson may be that custody risk cannot be eliminated—only shifted. Exchange custody introduces counterparty exposure, while self-custody places greater responsibility on device security, software integrity and operational practices. Increasingly, security professionals advocate layered approaches such as multisignature wallets, diversified hardware vendors and independently generated entropy to reduce single points of failure.
As investigations continue into the Coldcard exploit, the incident is likely to influence both hardware wallet design and institutional custody practices. More broadly, it serves as a reminder that Bitcoin’s cryptography remains robust, but the systems surrounding key generation and storage must evolve continuously to keep pace with increasingly sophisticated attackers.







