What to Know

  • Attackers have drained nearly $114 million in bitcoin from more than 709 addresses.
  • The exploit centered on a Coldcard firmware flaw that generated wallet seeds with only a fraction of the randomness users expected.
  • The first sweep emptied roughly 500 wallets in 25 minutes.
  • The flawed code entered the codebase in March 2021 and remained publicly visible for more than five years.
  • Coldcard’s code had been available for inspection, but the failure went undetected for years.
  • In 2020, Coldcard moved from a GPL open-source license to a Commons Clause license, whose own FAQ says the resulting software is no longer open source.
  • The March 2021 commit that removed the last GPL code is the same commit that broke seed generation.
  • Security researchers had previously faced harsh public pushback after reporting Coldcard-related issues.
  • Updating firmware cannot repair a seed generated on vulnerable versions, making migration guidance central for affected users.

A Major Bitcoin Theft Hits the Self-Custody Debate

A bitcoin security crisis tied to Coldcard has exposed one of the hardest truths in self-custody: a product’s reputation is not the same thing as verification. Attackers have now drained nearly $114 million in bitcoin from more than 709 addresses after exploiting a firmware flaw that generated wallet seeds with far less randomness than users were promised. The first sweep alone emptied roughly 500 wallets in 25 minutes, turning a long-dormant software weakness into a fast-moving loss event for affected holders.

The issue is especially damaging because hardware wallets are marketed around a simple premise: users can remove trusted intermediaries from the custody equation by taking direct control of their private keys. But that model does not eliminate trust unless the underlying code, build process, disclosures, and security culture are examined continuously by people capable of finding subtle failures. In this case, the flawed code entered the Coldcard codebase in March 2021 and remained in public view for more than five years. The code could be inspected, yet the fatal weakness remained effectively invisible until the damage was done.

For Bitcoin users, the incident is more than another wallet exploit. It is a referendum on whether the industry’s best-known slogan, do not trust, verify, is being practiced with the same discipline with which it is repeated. Verification is not a vibe, a brand identity, or a badge of ideological purity. It is labor. It requires qualified review, reproducible builds, adversarial testing, and a culture in which independent researchers are rewarded for being difficult rather than punished for being inconvenient.

The Open-Code Assumption Broke Down

Coldcard’s source code was available for inspection, and that fact gave many users a sense that the product had been subject to meaningful public scrutiny. But code availability is only the first condition for review, not proof that review happened. Open visibility does not automatically translate into expert examination, and it does not guarantee that high-risk cryptographic changes will receive sustained attention from the broader community.

The timeline around the bug has intensified scrutiny. In 2020, Coldcard’s firmware carried a GPL open-source license. Two days after a competitor announced a device building on that GPL code, Coinkite CEO Rodolfo Novak, widely known as NVK, publicly said in a since-deleted post that he regretted choosing GPL. That November, Coldcard adopted a new license with the Commons Clause. The Commons Clause FAQ states plainly that the resulting software is no longer open source.

A sweeping rewrite followed. The March 2021 commit that stripped out the last GPL code is also the commit that broke seed generation. Nobody can determine with certainty how much licensing pressure influenced the pace, scope, or risk tolerance of that rewrite, and the overhaul may also have pursued legitimate technical objectives. Still, the documented sequence is troubling: a license change designed to limit competitors came before the replacement of battle-tested cryptographic code, and the replacement introduced the flaw now tied to massive bitcoin losses.

That sequence matters because free and open-source software principles were designed to reduce dependence on any single vendor’s judgment. In security-sensitive systems, competition, reproducibility, and unfriendly review are protective forces. When commercial strategy narrows the space for outside participation, the system may become more dependent on insiders making perfect decisions. Bitcoin’s security culture was built on the opposite assumption: insiders, institutions, and experts can fail, so users need mechanisms to verify independently.

Researcher Pushback May Have Raised the Cost of Scrutiny

The Coldcard incident has also revived criticism of how independent researchers were treated when they raised earlier concerns. In August 2020, researchers from Shift Crypto and Nunchuk disclosed a multisig verification flaw in Coldcard. Coinkite acknowledged the bug and shipped a fix. At the same time, public commentary around the disclosure became hostile, with NVK describing the disclosure on the Citadel Dispatch podcast as PR terrorism and questioning whether a researcher without a CVE should be considered a professional.

In 2023, the WalletScrutiny project reported problems reproducing older Coldcard builds. The response characterized the project as incompetent or malicious and raised the possibility of litigation. Independent follow-up later found genuine reproduction problems in older releases and concluded that nobody had acted in bad faith. That distinction is important. A mistaken or incomplete report can be corrected through technical process. A public environment that brands good-faith review as hostile can discourage the next researcher from spending months on unpaid, difficult work.

No one can prove that this culture directly caused the seed-generation flaw to remain unnoticed. The better point is more general and more important: security depends on people being willing to look. Independent researchers have limited time, limited funding, and many possible targets. If reviewing a prominent product may bring ridicule, social exclusion, or legal pressure, some researchers will simply move on. In that way, a community can preserve the appearance of scrutiny while quietly reducing the number of people prepared to conduct it.

Reputation Became a Substitute for Evidence

The broader Bitcoin community now faces an uncomfortable question. How did a culture built around verification end up outsourcing so much judgment to reputation? Part of the answer lies in familiar social dynamics. Repeated claims can start to feel independently confirmed when they are echoed through the same podcasts, feeds, and product discussions. Confidence can be mistaken for competence. A strong brand can create a halo around technical choices that still require verification.

Over time, market participants and self-custody advocates heard recurring narratives: critics were shills, researchers were troublemakers, and competitors were copycats. Repetition did some of the work that evidence should have done. When a respected product and a forceful public voice dominate a niche, users may begin to treat reputation itself as evidence. That is especially dangerous in Bitcoin, where the entire point of self-custody is to avoid replacing institutional trust with personality-based trust.

The resulting failure can be understood as a kind of judgment outsourcing. Instead of verifying claims about security, many people accepted the social proof surrounding the product. That does not mean every user acted irrationally. Hardware wallet security is complex, and most holders cannot audit firmware personally. But the community as a whole is supposed to create layers of review, skepticism, and accountability. When those layers weaken, even sophisticated users can end up relying on brand confidence rather than demonstrated resilience.

User Safety Comes First

The immediate priority is not assigning reputational blame. It is protecting users. The most important operational point is that updating firmware cannot repair a seed generated on vulnerable versions. If a seed was created with insufficient randomness, the weakness is embedded in the secret itself. A firmware update may prevent future vulnerable seed generation, but it cannot make an already weak seed strong.

That makes migration guidance critical. Affected users need clear instructions for moving funds to wallets generated outside the vulnerable path. Product pages, old recommendation lists, podcast notes, and wallet guides also need careful review. Claims that were repeated for years without enough verification should be corrected with primary technical evidence attached. This is not merely a public relations cleanup. It is a risk-reduction exercise for users who may still be relying on outdated assumptions.

Media, educators, and builders also have a role. Bitcoin coverage should be adversarial toward friends, sponsors, advertisers, and favored products in the same way it is adversarial toward unknown projects. Friendly scrutiny is still scrutiny. A community that only investigates outsiders is not practicing verification; it is practicing tribal confidence. The Coldcard exploit shows how expensive that difference can become.

The Industry Needs Verification Without Favorites

The lesson for hardware wallet users is not that every vendor is unsafe or that self-custody has failed. The lesson is that self-custody requires a deeper ecosystem than a device purchase. Users need maintainers, reproducible builds, open review, respectful disclosure pathways, and media willing to challenge dominant narratives. Vendors need to treat criticism as part of the security perimeter rather than as an attack on the brand.

Technical traders often describe Bitcoin as an asset whose value depends partly on credible self-custody. If holders lose confidence that they can secure their coins independently, the damage extends beyond a single product. It can weaken one of Bitcoin’s most important value propositions: the ability to hold value without relying on banks, brokers, or custodians. That proposition remains powerful, but it is only as strong as the verification culture surrounding the tools people use.

The industry’s path forward is both simple and difficult. Do not trust vendors merely because they are popular. Do not trust critics merely because they are loud. Do not assume open code has been meaningfully reviewed just because it is visible. Do not punish researchers for finding uncomfortable problems. Verification must apply equally to friends, competitors, sponsors, and critics. Anything less turns security into reputation management, and reputation has now proven to be a weak security model.

Frequently Asked Questions (FAQs)

What happened in the Coldcard bitcoin exploit?

Attackers drained nearly $114 million in bitcoin from more than 709 addresses by exploiting a Coldcard firmware flaw that generated wallet seeds with far less randomness than users expected.

How fast did the initial theft unfold?

The first sweep emptied roughly 500 wallets in 25 minutes, showing how quickly a seed-generation weakness can be exploited once attackers are able to identify vulnerable wallets.

When did the flawed code enter Coldcard?

The flawed code entered the Coldcard codebase in March 2021. It remained publicly visible for more than five years before the exploit became a major loss event.

Why is seed randomness so important?

A wallet seed must be unpredictable because it controls access to funds. If a seed is generated with too little randomness, attackers may have a far easier path to discovering or reconstructing it.

Can a firmware update fix a vulnerable seed?

No. Updating firmware cannot repair a seed that was already generated on vulnerable versions. Users with affected seeds need migration guidance because the weakness is part of the seed itself.

Was Coldcard’s code available for inspection?

Yes. Coldcard’s source code was available for inspection, but availability alone did not ensure that qualified reviewers identified the seed-generation flaw before attackers exploited it.

Why does the licensing history matter?

Coldcard moved from a GPL open-source license to a Commons Clause license in 2020, and a later rewrite removed the last GPL code. The March 2021 commit tied to that removal is also the commit that broke seed generation.

What role did independent researchers play?

Researchers had previously disclosed Coldcard-related issues and reproducibility concerns. Public pushback against some disclosures raised broader concerns about whether the environment encouraged or discouraged independent review.

What is the main lesson for Bitcoin users?

The main lesson is that reputation cannot replace verification. Users, media, researchers, and vendors all need to support adversarial review, clear disclosures, and evidence-based security claims.

Photo by Alesia Kozik on Pexels