A flaw in how Coldcard hardware wallets generated seed phrases allowed attackers to drain thousands of devices without ever touching them, undermining the core promise that air-gapped storage keeps bitcoin safe from remote theft. Galaxy Research estimates 1,596 bitcoin, over $100 million at current prices, moved from roughly 7,300 addresses in a campaign that began in late July. The vulnerability lay not in the device’s isolation but in the randomness used to create the private keys themselves.
The flaw in the seed
Coldcard’s appeal was simple: the wallet never connects to the internet, so the secrets inside the chip should never leave it. Toronto entrepreneur Jonathan Goodman followed every recommended practice. His device sat in a safe deposit box. His seed phrase sat in a second one. On July 29, he reported that 18.25 bitcoin, worth about $1.17 million at the time, had vanished. “Perhaps the hardest part about this is that I did everything right,” he wrote on X days later. The breach did not require physical access, malware, or a phishing link. It required only that the seed had been generated by flawed code.
Scale of the losses
Galaxy Research head Alex Thorn said on August 4 that at least 15 distinct actors were exploiting the weakness. The firm expressed high confidence in its address clustering and volume estimate. The stolen coins represent a fraction of the total bitcoin supply, but for a product marketed on the premise that its keys are unguessable, the number is large enough to matter. Bobby Gray, founder of TEXITcoin, told CoinDesk that air-gapped systems help but are not a perfect fix, and that security has to start with how keys are created and extend through every stage of custody.
How the bug survived
Coinkite, the Toronto company behind Coldcard, announced in March 2016 that it was shutting down its hosted hot wallet. Persistent denial-of-service traffic, rising legal costs, and regulatory friction had made the service unsustainable. The pivot produced Opendime, a USB stick that generates and hides a private key until its seal is broken, and then the Coldcard line. Bitcoin traded around $400 at the time. The seed-generation flaw introduced in that era went undetected for years, surviving firmware updates and security audits that focused on the device’s communication layers rather than the entropy source itself.
What to watch
Coinkite has not published a full technical post-mortem. Until it does, the exact conditions that made seeds predictable, and whether any devices produced after a certain firmware version are affected, remain unverified. Users who generated seeds on Coldcard hardware before a fix is confirmed should assume those keys are compromised. The episode is a reminder that in custody, the only thing harder than keeping a secret is proving the secret was ever secret to begin with.
