Coldcard firmware flaw steals $38 million in bitcoin, rattling self-custody model
Key points
- A firmware flaw in Coinkite's Coldcard hardware wallet generated seeds with insufficient randomness, enabling attackers to brute-force private keys and steal at least 600 bitcoin worth roughly $38 million.
- Coinkite CEO NVK confirmed in an open letter that the firmware patch protects new seeds only; users with seeds generated on vulnerable firmware must migrate funds to entirely new wallets.
- ARK Invest's Lorenzo Valente stated that self-custodial hardware has exchanged counterparty risk for a broader set of software, hardware, supply-chain, phishing, and backup risks, and that publicly traded exchanges or ETFs are preferable for most consumers today.
- Casa CEO Nick Neuman described the recommended mitigation of using physical dice rolls to supplement randomness as a non-starter for 99 percent of users, raising questions about the practicality of hardware wallet security guidance.
- The exploit is being cited as a catalyst that may accelerate institutional and retail adoption of regulated custodians and spot bitcoin ETFs over self-custody solutions.
A firmware vulnerability in Coinkite’s Coldcard hardware wallet has resulted in the theft of at least 600 bitcoin, worth roughly $38 million, after attackers exploited a flaw that caused affected firmware versions to generate wallet seeds with insufficient randomness, making them susceptible to brute-force reconstruction. Coinkite chief executive NVK issued an open letter urging all users who generated a seed on a vulnerable device to move funds immediately and create entirely new wallets, stressing that applying the firmware patch alone does not protect seeds already generated under the flawed versions.
The incident is drawing comparisons to exchange failures such as FTX, but with a sharper edge: rather than a centralised intermediary being breached, individual users had their personal private keys recreated without their knowledge. Bitcoin commentator Guy Swann described it as the most damaging self-custody failure in bitcoin’s history precisely because it struck users who believed they had taken the right precautions. Casa chief executive Nick Neuman questioned whether the remediation guidance itself, which advised supplementing wallet randomness with physical dice rolls, was realistic for the vast majority of holders.
Industry observers are reading the episode as a structural argument for regulated alternatives. Lorenzo Valente, director of digital asset research at ARK Invest, argued that self-custodial hardware has in practice substituted counterparty risk with a compounded set of software, hardware, supply-chain, phishing, and backup risks, and stated that holding funds across publicly traded exchanges or exchange-traded funds (ETFs) now presents a more defensible position for most consumers. The likelier read is that the incident accelerates flows toward spot bitcoin ETFs and regulated custodians among retail and institutional allocators who had been weighing self-custody as a viable option.
More on the wire
- Citi Plans Bitcoin Custody Service for Institutional Clients Later This Year
- Citi Plans Crypto Custody Launch This Year, Starting With Bitcoin
- U.S. Accounting Standards Group Proposes Stablecoins as Cash Equivalents
- US Treasury Proposes GENIUS Act Rules Defining Payment Stablecoin Issuance Jurisdiction