Coldcard Hack Exposes Resilience of Self-Custody in Bitcoin
A massive breach of Coldcard hardware wallets has led to approximately $130 million in stolen Bitcoin. The hack, which started on July 30, was made possible by a firmware bug introduced in March 2021 that routed key generation through a weak software random number generator instead of the device's dedicated hardware chip.
The attackers drained around 2,100 BTC from vulnerable Coldcard wallets, but what's even more significant is that over 233,000 BTC left long-term holder wallets in the days surrounding the breach. Casa CEO Nick Neuman pointed out that some of this movement came from Ledger and Trezor users who upgraded to multisig wallets after watching the hack unfold.
This mass migration into safety highlights the resilience of Bitcoin as an asset class, particularly when it comes to self-custody. According to onchain data, more than 100 times the amount stolen was moved out of long-term holder wallets in search of safety. Neuman noted that if this were a centralized exchange breach, everything would have been compromised at once.
Coinkite has urged anyone who generated a seed on firmware versions 4.0.1 through 4.1.9 to treat their wallets as compromised and migrate to a new seed immediately. The incident underscores the importance of self-custody in securing Bitcoin holdings.