Bitcoin self-custody at risk after Coldcard exploit drains over $83 million

Via bitrawr.com

Bitcoin self-custody at risk after Coldcard exploit drains over $83 million

A firmware bug dating back to 2021 left Coldcard wallets generating weak seeds, enabling remote brute-force attacks that have stolen more than 1,300 BTC.

A firmware vulnerability in Coldcard hardware wallets has resulted in the theft of over 1,300 BTC, worth roughly $83 million at the time of the attacks, making it one of the largest self-custody security failures in Bitcoin’s history. The flaw, which affected firmware versions 4.0.1 through 4.1.9, caused the wallets to generate recovery seeds with approximately 40 bits of entropy instead of the intended 128 bits.

In English: the wallets were supposed to create passwords so complex that guessing them would take longer than the age of the universe. Instead, they created passwords weak enough to crack remotely. No physical access to the device required.

How a 2021 code regression became a 2026 disaster

The vulnerability traces back to a code regression introduced in March 2021 within Coldcard MK3 devices manufactured by Coinkite. Reports of the exploit began surfacing publicly in late July 2026. The thefts rolled out in multiple waves across thousands of addresses, suggesting a systematic operation rather than opportunistic attacks.

Advertisement

Total reported losses have climbed as high as $89 million as additional victims have come forward.

Coinkite responded with a firmware update, versions 4.2.0 and above, and urged all users on affected firmware to regenerate their seeds immediately. The company also recommended using strong BIP-39 passphrases as an additional layer of protection. Coinkite has begun destroying remaining vulnerable inventory.

The “don’t trust, verify” problem

Jameson Lopp, CTO of Casa, weighed in on the incident with a perspective that cuts to the heart of Bitcoin’s self-custody philosophy. Lopp’s argument is that verification of complex software and hardware systems simply isn’t feasible for 99.9% of users.

Lopp noted that Bitcoin users can choose their preferred security or convenience models in light of the exploit. He also emphasized that prior incidents involving hardware wallets have not ended self-custody as a practice, and that each vulnerability has ultimately raised industry standards.

What this means for Bitcoin holders

The immediate practical concern is straightforward. Anyone running Coldcard MK3 firmware between versions 4.0.1 and 4.1.9 needs to update their firmware and regenerate their seed phrase.

This incident will almost certainly accelerate interest in multi-signature wallet setups, where multiple keys held across different devices and locations are required to authorize a transaction. A multi-sig arrangement would have mitigated this attack entirely, since compromising one key wouldn’t be sufficient to move funds.

Casa, where Lopp serves as CTO, happens to offer exactly that kind of multi-signature solution. The conflict of interest is worth noting, but it doesn’t make the underlying point wrong. Distributing risk across multiple signing devices means a single point of failure, whether it’s a firmware bug, a supply chain attack, or a compromised random number generator, can’t drain your entire stack.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Bitcoin self-custody at risk after Coldcard exploit drains over $83 million

Bitcoin self-custody at risk after Coldcard exploit drains over $83 million

A firmware bug dating back to 2021 left Coldcard wallets generating weak seeds, enabling remote brute-force attacks that have stolen more than 1,300 BTC.

Via bitrawr.com

A firmware vulnerability in Coldcard hardware wallets has resulted in the theft of over 1,300 BTC, worth roughly $83 million at the time of the attacks, making it one of the largest self-custody security failures in Bitcoin’s history. The flaw, which affected firmware versions 4.0.1 through 4.1.9, caused the wallets to generate recovery seeds with approximately 40 bits of entropy instead of the intended 128 bits.

In English: the wallets were supposed to create passwords so complex that guessing them would take longer than the age of the universe. Instead, they created passwords weak enough to crack remotely. No physical access to the device required.

How a 2021 code regression became a 2026 disaster

The vulnerability traces back to a code regression introduced in March 2021 within Coldcard MK3 devices manufactured by Coinkite. Reports of the exploit began surfacing publicly in late July 2026. The thefts rolled out in multiple waves across thousands of addresses, suggesting a systematic operation rather than opportunistic attacks.

Advertisement

Total reported losses have climbed as high as $89 million as additional victims have come forward.

Coinkite responded with a firmware update, versions 4.2.0 and above, and urged all users on affected firmware to regenerate their seeds immediately. The company also recommended using strong BIP-39 passphrases as an additional layer of protection. Coinkite has begun destroying remaining vulnerable inventory.

The “don’t trust, verify” problem

Jameson Lopp, CTO of Casa, weighed in on the incident with a perspective that cuts to the heart of Bitcoin’s self-custody philosophy. Lopp’s argument is that verification of complex software and hardware systems simply isn’t feasible for 99.9% of users.

Lopp noted that Bitcoin users can choose their preferred security or convenience models in light of the exploit. He also emphasized that prior incidents involving hardware wallets have not ended self-custody as a practice, and that each vulnerability has ultimately raised industry standards.

What this means for Bitcoin holders

The immediate practical concern is straightforward. Anyone running Coldcard MK3 firmware between versions 4.0.1 and 4.1.9 needs to update their firmware and regenerate their seed phrase.

This incident will almost certainly accelerate interest in multi-signature wallet setups, where multiple keys held across different devices and locations are required to authorize a transaction. A multi-sig arrangement would have mitigated this attack entirely, since compromising one key wouldn’t be sufficient to move funds.

Casa, where Lopp serves as CTO, happens to offer exactly that kind of multi-signature solution. The conflict of interest is worth noting, but it doesn’t make the underlying point wrong. Distributing risk across multiple signing devices means a single point of failure, whether it’s a firmware bug, a supply chain attack, or a compromised random number generator, can’t drain your entire stack.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.