Community Trust ScoreVerified
A massive theft. Coldcard, a well-known manufacturer of hardware wallets in the Bitcoin ecosystem, has confirmed the loss of 2,000 bitcoins — over $100 million — directly linked to a security flaw in its own firmware. The incident was made public on July 31.
The flaw dates back to March 2021. For years, no one noticed — or at least, nothing was said. The issue affects the generation of 24-word recovery phrases, the fundamental mechanism that allows a user to regain access to their funds if their device is lost or broken. However, Coldcard’s method of generating these phrases made the associated private keys easier to guess for someone who knew where to look. Malicious actors evidently knew where to look. The result: 2,000 bitcoins gone.
No recovery in sight.
Jonathan Goodman and $1.6 Million Vanished
Jonathan Goodman, an entrepreneur, is among the identified victims. He lost $1.6 million in bitcoins. His case is likely not isolated — the flaw has affected an undetermined number of users, and the total amount stolen suggests that several wallets have been emptied. Coldcard has asked its customers to create new strengthened private keys and transfer their funds to new addresses. Quickly.
It’s the kind of recommendation that always comes too late for some.
The situation reignites an old debate in the crypto community: are we really safer with a cold wallet than with a centralized platform? The honest answer is that it depends — and both options have their share of disasters.
Self-Custody vs. Centralized Platforms: The Real Score
A 2025 report provides thought-provoking figures. Since 2010, 1.57 million bitcoins have been lost via self-custody wallets. On centralized exchange platforms, it’s 1.51 million. The numbers are close. Too close for one to be clearly “safer” than the other in the long run.
Centralized platforms are convenient. Simple interface, customer support, account recovery if you lose your password. But they also have their own disasters: massive hacks, sudden bankruptcies, forced closures. In Europe, recent MiCA regulations have pushed several crypto exchanges to shut down, leaving users without access to their funds for weeks.
Cold wallets, on the other hand, embody pure Bitcoin ideology: “Not your keys, not your coins.” You control everything. No one else can block your funds. But you also bear all the responsibility — and if your device’s firmware has had a flaw since 2021, you won’t know until the day your balance is zero.
Coldcard is not the first manufacturer to face this kind of problem. In 2020, Ledger — the French company — suffered a hack that exposed the personal data of over 273,000 clients. Physical addresses, balances, contact information. This led to a series of attacks against wallet holders, notably in France. Technically different — it was a data leak, not a key generation flaw — but the real-world impact for victims was just as harsh.
This sector changes quickly, and not always for the better.
The problem with hardware wallets is that users trust them precisely because they are supposed to be the ultimate solution. Offline, physical, impossible to hack remotely. Except “offline” doesn’t mean “flawless.” The firmware is indeed code. And code has bugs. Here, this bug lasted over four years without being detected — or without being made public, which is an important distinction.
It’s not yet clear if Coldcard knew before July 31.
Users who bought a Coldcard device between March 2021 and the firmware fix are potentially exposed. The company has not specified how many devices are affected or how many wallets have been compromised in total. The figure of 2,000 bitcoins stolen is circulating, but the source does not provide details on the number of individual victims beyond Goodman’s case.
What we know: the 24-word recovery phrase is the heart of any HD wallet system. If the way these words are generated is predictable — even slightly — an attacker with enough computing power can test combinations until they find the right one. That’s exactly what seems to have happened here. The flaw did not allow direct access. It made guessing feasible. Technical nuance, identical consequence.
Coldcard has asked its users to migrate their funds. Jonathan Goodman, however, lost $1.6 million.
Frequently Asked Questions
What flaw allowed the bitcoin theft at Coldcard?
A flaw in Coldcard’s firmware, present since March 2021, affected the generation of 24-word recovery phrases, making private keys easier to guess for malicious actors.
What should Coldcard users do after this incident?
Coldcard has asked its customers to create new strengthened private keys and transfer their bitcoins to new addresses to secure their funds.
How many bitcoins were stolen and what is their value?
Approximately 2,000 bitcoins were stolen, valued at over $100 million at the time the incident was revealed on July 31.




