A firmware vulnerability in ColdCard, a hardware wallet made by Canadian manufacturer Coinkite, has been exploited to drain roughly 1,367 bitcoin — worth close to $89 million at current prices — from thousands of addresses since July 30, 2026, according to blockchain researchers at Galaxy. The scale of the theft has climbed steadily as more affected wallets were identified, with early estimates of $38 million growing to $89 million and beyond within days as researchers traced additional drained addresses back to the same underlying flaw.
The vulnerability itself traces back to a firmware integration mistake dating to March 2021: under certain conditions, the device bypassed its dedicated hardware random number generator — the component specifically designed to produce genuinely unpredictable values for generating a wallet’s secret seed phrase — and fell back to a software-based method instead, using inputs like device identifiers and timing data that were not sufficiently random or secret. The practical result was that some wallets’ seed phrases carried far less real entropy (randomness) than users believed, making them vulnerable to being reconstructed through brute-force computation, without an attacker ever needing physical access to the device itself.
Updating the Firmware Doesn’t Fix an Already-Compromised Wallet
Coinkite released emergency firmware updates on July 31, 2026, but the company’s own CEO, who goes by NVK, issued a blunt, urgent directive to users: “If you generated a seed using a ColdCard wallet, move your funds now.” That instruction reflects a critical, easy-to-misunderstand detail about the fix: exposure depends on which firmware version was running at the moment a wallet’s seed was originally generated, not which version is currently installed. Simply updating a device’s firmware prevents new, vulnerable seeds from being generated going forward — it does nothing to secure a wallet whose seed was already created under an affected version. Users with potentially exposed wallets must generate an entirely new seed on updated firmware and transfer their funds to it, rather than assuming an update alone resolves the risk.
A Real Blow to Self-Custody’s Core Pitch
The incident has drawn unusually pointed reactions from within the Bitcoin community itself, precisely because ColdCard has long been marketed toward technically sophisticated users who explicitly chose hardware self-custody specifically to avoid the counterparty risk of exchanges or custodians. Bitcoin commentator Guy Swann called it “the worst hit in bitcoin history to the most knowledgeable and ‘properly secured’ bitcoiners,” distinguishing this incident from a typical exchange hack precisely because the affected users had done everything conventionally recommended to secure their own funds. ARK Invest’s Lorenzo Valente argued the episode shows self-custody users have effectively “traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk” — suggesting regulated custodians and spot Bitcoin ETFs may offer better real-world protection for average investors than hardware self-custody, despite self-custody’s philosophical appeal. Casa CEO Nick Neuman was separately critical of one proposed workaround (manually rolling physical dice to generate additional randomness), calling it impractical for mainstream users regardless of its technical soundness.
A Rare Failure for a Device Built Specifically to Prevent This
ColdCard has marketed itself for years as one of the more security-focused hardware wallets available, specifically appealing to technically sophisticated Bitcoin holders willing to pay a premium and accept a steeper learning curve in exchange for stronger security guarantees than a typical consumer-grade wallet. That positioning is precisely what makes this incident land differently than a routine exchange hack: the affected users were, by design, the segment of the crypto market that had already taken the most deliberate, informed steps to secure their own funds, using a device built by a company whose entire reputation rested on getting exactly this kind of cryptographic detail right. A five-year-old firmware integration mistake going undiscovered until actively exploited is a sobering reminder that even security-focused hardware products can carry latent flaws that neither the manufacturer nor its most careful users ever caught through years of ordinary use.
What This Means for Philippine Founders
This incident is a direct, current case study for any Philippine fintech or crypto startup building or recommending hardware wallets, custody solutions, or key-management systems: a single firmware integration mistake, dormant for more than five years before being discovered and exploited, is a sobering reminder that a security architecture’s real strength depends entirely on the correctness of code most users will never audit themselves, no matter how sound the underlying cryptographic design is in theory. For Philippine crypto exchanges and remittance platforms specifically, the incident is also a useful, concrete talking point when explaining to retail users why a regulated custodial platform — with dedicated security teams monitoring for exactly this class of vulnerability — may in practice offer better protection for the average user than self-custody hardware most people lack the technical background to properly audit or even understand the risks of.
Share this article