[ Story · STORY ]

Coldcard bug drains $38M, dents self-custody

A Coldcard firmware flaw let attackers rebuild seed phrases, draining roughly 600 BTC ($38M) from self-custodied wallets.

STORY·July 31, 2026·3 min read·By Gintautas Nekrosius
A single open padlock next to a stack of closed padlocks on a cream background, one red accent thread running through the open lock
One weak lock in a row of identical ones is all it takes.

A firmware bug in Coinkite's Coldcard hardware wallet let attackers reconstruct wallet recovery phrases, draining close to 600 bitcoin, roughly $38 million, from what owners believed were secure, offline holdings. The flaw is patched, but anyone who generated a seed on vulnerable firmware has to move funds to a brand-new wallet since the fix doesn't retroactively protect old keys.

What the numbers show

The theft sits near 600 BTC, worth about $38 million at current prices, and Coinkite CEO NVK has told affected users to move funds immediately using new seed-generation practices. Researchers traced the root cause to weak randomness in certain firmware versions, which made recovery phrases brute-forceable rather than mathematically secure. Blockaid, a blockchain security firm, says most crypto losses in the first half of 2026 came from compromised keys and operational failures rather than smart contract exploits, and this incident fits that pattern exactly: the exposure sits at the key-generation stage, not the transaction stage. Recommended mitigations, like supplementing wallet randomness with physical dice rolls, drew immediate pushback. Casa CEO Nick Neuman called it "a non-starter for 99% of people." Full detail from CoinDesk.

What it means

Self-custody's pitch has always been that removing banks and exchanges from the equation removes counterparty risk. This exploit shows that promise was incomplete: it swaps counterparty risk for supply-chain and firmware risk that users can't audit themselves. ARK Invest's Lorenzo Valente put it plainly, arguing that consumers holding their own keys have traded one danger for software risk, hardware risk, phishing risk, backup risk, and the chance of losing everything through a single mistake. Bitcoin commentator Guy Swann called it the worst hit in Bitcoin history to the most careful, "properly secured" holders, precisely the group self-custody was supposed to protect.

That framing matters for where capital goes next. If the most disciplined users in the ecosystem can lose funds to a firmware bug they never saw, the argument for regulated custodians and spot ETFs gets stronger, not weaker, even among people who spent years advocating for self-custody. Udi Wertheimer's line captures the shift: security isn't something you set up once and forget anymore, it's a job, and if you don't want to do that job yourself, you pay someone else to do it. That's the ETF pitch in one sentence, and this exploit hands it credibility it didn't have a week ago.

What to watch

Watch whether Coinkite discloses how many wallets were generated on vulnerable firmware and how much of that bitcoin remains unmoved. A large pool of exposed-but-unmigrated funds would confirm the damage is still unfolding rather than contained, and would give the ETF argument more weight with every week that passes.

Gintautas Nekrosius is the founder and editor of Stack and Story. He spent more than a decade in technology and crypto, including senior marketing roles at companies in the Animoca Brands and NordVPN groups, and worked on token launches and go-to-market from the inside. He started Stack and Story to write the independent read he could not find: crypto and markets explained plainly, by someone who has seen how the machine works. The publication holds no tokens and takes no trades.

DisclosureStack and Story holds no position in the assets discussed and earns nothing from their movement. This is analysis, not financial advice. Do your own research.

Understand crypto. Decide for yourself.

The numbers that moved, and the reason they did, every Sunday, free.

Free · Independent · Unsubscribe anytime · Privacy