The Unbreakable Vault That Wasn't: Inside the $116 Million Coldcard Hack

Comments · 21 Views

A five-year-old firmware bug in Coldcard hardware wallets quietly weakened seed generation for thousands of Bitcoin users, allowing an anonymous attacker to sweep more than $100 million in a matter of hours and shatter the myth of foolproof self-custody.

The Unbreakable Vault That Wasn't

On a quiet Thursday morning in late July, as most of the world slept, a ghost moved through the Bitcoin blockchain. In less than an hour, it swept through more than a thousand digital addresses, vanishing with roughly $70 million in cryptocurrency. The target was not a flashy exchange or a high-profile fund. It was something far more intimate: the Coldcard, a small, unassuming hardware device that thousands of Bitcoin believers trusted to keep their life savings safe from prying eyes. 

What unfolded over the next few days would become one of the most unsettling episodes in the history of cryptocurrency self-custody. The attacker never breached a server. They never phished a single user. They never laid hands on a Coldcard device. Instead, they exploited a flaw that had been hiding in plain sight for more than five years—a bug so subtle, so buried in the firmware's code, that it turned the very process meant to generate unbreakable security into a predictable, reproducible pattern. 

The Promise of Cold Storage

To understand why this hack cut so deep, you have to understand what Coldcard promised. In the anarchic world of Bitcoin, where centralized exchanges have collapsed in spectacular fashion and regulators loom ever larger, the hardware wallet became the ultimate symbol of sovereignty. Coldcard, made by a Canadian firm called Coinkite, was the gold standard among Bitcoin purists. It was a device designed for one thing and one thing only: keeping Bitcoin offline, far from the reach of hackers, governments, and the general chaos of the internet. 

The Coldcard looked like a pocket calculator, all matte black plastic and a small monochrome screen. It had no Wi-Fi, no Bluetooth, no USB data connection when in use. You generated your recovery seed—those 12 or 24 words that could restore your entire fortune—on the device itself, and the private keys never left it. For Bitcoin maximalists, this was the closest thing to digital gold you could get: a fortress that no one could storm. 

Jonathan Goodman, a prominent Bitcoin educator who lost roughly $1.6 million in the hack, epitomized the Coldcard user. He kept his device in a safety deposit box that had never touched the internet. He followed every best practice, every security recommendation. "I did everything right," he wrote later, in a post that would circulate widely across crypto Twitter. His story, and hundreds like it, would become the human face of a breach that exposed the limits of even the most careful self-custody. 

The Flaw in the Machine

The vulnerability traced back to a single line of code, committed on March 1, 2021. In what would prove to be a fateful firmware update, Coldcard's engineers introduced a change that quietly rerouted how the device generated its recovery seeds. Instead of drawing from the dedicated hardware random number generator—a chip designed to produce truly unpredictable entropy—the firmware fell back to a software-based pseudorandom number generator. 

On the surface, nothing seemed amiss. The seeds still looked random. The 12 or 24 words that users carefully wrote down on paper or stamped into metal plates appeared as unpredictable as ever. But behind the scenes, the process had been compromised. The software generator, known as Yasmarang, was initialized from fixed device data like the chip's unique ID and timer registers, and it gathered no fresh entropy after that initial moment. 

The result was a catastrophic reduction in what cryptographers call entropy—the measure of unpredictability in a system. A standard 12-word seed should have 128 bits of entropy, a number so vast that brute-forcing it would take longer than the age of the universe. On the affected Coldcard Mk3 devices, that number dropped to roughly 40 bits. On newer models like the Mk4 and Mk5, it fell to about 72 bits.

To put that in perspective: 40 bits of entropy is about a trillion possible combinations. That's a number that modern cloud computing can work through in hours. Seventy-two bits is far larger, but still within reach for a well-funded attacker with the right tools. The difference between 128 bits and 40 bits isn't a matter of degree. It's the difference between a lock that cannot be picked and one that can be opened by anyone with enough computing power and patience. 

The Attack Unfolds

The attacker, whoever they were, understood this perfectly. They didn't need to steal a single device. They didn't need to trick a user into revealing their seed. All they needed was to replicate the flawed seed-generation process on their own machines, generate candidate seeds, derive the corresponding Bitcoin addresses, and check those against the public blockchain. When a match appeared, they had the private key. When they had the private key, they had the Bitcoin. 

On July 30, at approximately 1:10 UTC, the first wave began. Over the next 41 minutes, 1,196 addresses were systematically drained of 1,082.65 BTC, worth about $70.2 million at the time. Blockchain intelligence firm Galaxy Research, which first mapped the sweep, noted that the attacker went after the largest balances first, pulling more than $30 million in the opening ten minutes alone. One victim lost around $1.8 million. 

The pattern was unmistakable. Every coin taken in that first wave came from a wallet created after March 17, 2021—the strongest evidence linking the thefts to the firmware release. Coinkite's first public advisory came roughly 30 hours later, by which time the damage was done.

But the story didn't end there. On July 31, a second wave drained another 76.16 BTC from 1,478 addresses. On August 1, a third wave took 207.73 BTC from 1,912 more. By early August, Galaxy Research estimated total losses at 1,367 BTC, worth about $88.6 million. Fortune later reported that the total had climbed to 1,816 BTC, or nearly $116 million, across more than 5,200 addresses. 

The Aftermath

What made this hack particularly chilling was who it affected. Coldcard users were not casual investors who had left their Bitcoin on an exchange. They were the people who had gone out of their way to learn self-custody, to buy dedicated hardware, to follow every security best practice. They were the ones who had taken the ethos of "not your keys, not your coins" to heart. And yet, through no fault of their own, they found themselves exposed to a flaw that had been baked into the device itself. 

Coinkite's CEO, Rodolfo Novak, issued a public apology that was raw and unfiltered. "I'm sorry and I'm devastated," he wrote on X. "Our team is heartbroken about yesterday's news." The company released emergency firmware updates for all affected models, but with a caveat that would prove crucial: updating the firmware would not repair a seed that had already been generated with weak entropy. A seed created with 40 bits of randomness would stay weak forever, no matter what version of the software was running. 

The fix, such as it was, required users to generate an entirely new seed on patched firmware and move their coins to a fresh wallet. For those who had used additional entropy during setup—rolling dice 50 times or more to add randomness, or using a strong BIP-39 passphrase—the risk was lower. But for everyone else, the message was clear: migrate now, or risk becoming the next victim in a sweep that was still ongoing. 

The Broader Implications

The Coldcard hack reignited a long-simmering debate in the Bitcoin community about where to keep your coins. On one side were the self-custody purists, who argued that this incident proved the need for even more rigorous security practices, not less. On the other were those who saw the hack as evidence that self-custody was simply too risky for most people, and that the perceived safety of large, regulated exchanges might be the better option. 

Binance founder Changpeng Zhao, commonly known as CZ, weighed in with a characteristically blunt assessment. "I'm a believer in self-custody, but it puts the burden on you," he wrote. It was a sentiment that would resonate with many in the wake of the hack. If a five-year-old firmware bug could sit undetected in a well-regarded device like Coldcard, what basis was there for treating other hardware wallets as safe simply because they hadn't been caught yet? 

The incident also underscored a broader trend in cryptocurrency security: the gap between a bug shipping and someone finding it is likely to keep shrinking. Coinkite itself acknowledged that AI tools may have helped surface the flaw, a sign that the same technologies that promise to make systems more secure can also make them more vulnerable. Just weeks before the Coldcard hack, security firm Coinspect had published research on a separate weak-PRNG flaw in older software wallets, linking it to more than $5 million in losses across several blockchains. The two disclosures pointed to the same lesson: when randomness is weak, the rest of the cryptography can be perfectly sound and still fail. 

The Unanswered Questions

As of early August, many questions remained. No one had publicly named the attacker. Galaxy Research noted that the stolen Bitcoin—now worth well over $100 million—had not moved since the initial sweeps, an unusual pattern for a theft of this size. The firm offered two possibilities: the operator was waiting for scrutiny to fade, or had no viable way to launder a sum this visible in an era of tightened exchange compliance and real-time blockchain surveillance. 

The identity of the attacker may never be known. State-backed groups in North Korea or Russia have been behind many large crypto thefts in recent years, but investigators had not yet linked this incident to any specific actor. What was clear, however, was the impact: thousands of Bitcoin holders, many of whom had spent years building their positions, had seen their trust in one of the most respected devices in the space shattered in a matter of hours. 

The Human Cost

Behind the technical details and the blockchain analysis were the human stories. There was Jonathan Goodman, who had lost $1.6 million despite doing everything right. There were the countless others who had spent years accumulating Bitcoin, only to wake up one morning and find their wallets empty. There were the Coldcard users who now faced the unenviable task of explaining to their families that the fortress they had built had been breached not by a storm, but by a flaw in the foundation. 

For many, the hack was more than a financial loss. It was a betrayal of trust. Coldcard had been marketed as the ultimate solution for Bitcoin self-custody, a device that could keep your coins safe from everything from hackers to government seizures. And yet, the very thing that was supposed to make it secure—the offline generation of private keys—had been its undoing. 

The Road Ahead

In the weeks following the hack, the Bitcoin community grappled with what it all meant. Some doubled down on self-custody, arguing that the lesson was not to abandon hardware wallets but to use them more carefully, to add additional entropy, to diversify across multiple devices and strategies. Others began to question whether the dream of true self-custody was ever realistic for most people, or whether the future of Bitcoin would inevitably involve some degree of trusted third parties. 

Coinkite, for its part, faced an existential challenge. The company had built its reputation on security, on the promise that its devices were the safest place to keep Bitcoin. Now, it had to rebuild that trust, one user at a time. The firmware updates were a start, but they were not enough. The real test would be whether the company could convince its users that this was a one-time mistake, not a harbinger of deeper problems.

For the broader cryptocurrency industry, the Coldcard hack was a reminder that security is not a destination but a journey. Even the most carefully designed systems can harbor hidden flaws. Even the most trusted devices can fail. And in a world where the stakes are measured in millions of dollars, the cost of a single line of bad code can be catastrophic.

The Unbreakable Myth

In the end, the Coldcard hack was a story about the limits of human engineering. For all the promises of cryptography, for all the assurances of security experts, there is no such thing as an unbreakable vault. There are only systems that have not yet been broken, vulnerabilities that have not yet been found, and flaws that are waiting, quietly, for someone to notice them.

The Bitcoin that was stolen in those 41 minutes on July 30 may never be recovered. The attacker may never be caught. But the lesson of the Coldcard hack will linger long after the stolen coins have been laundered or lost to time: in the world of cryptocurrency, as in life, trust is a fragile thing. And once it's broken, it's almost impossible to put back together. 

Comments