BNB $588.63 +0.26%
XRP $1.07 -0.29%
ETH $1,857.69 +0.25%
BTC $63,621.08 +0.54%
BNB $588.63 +0.26%
XRP $1.07 -0.29%
ETH $1,857.69 +0.25%
BTC $63,621.08 +0.54%
BREAKING
Regulations

Coldcard Firmware Flaw Leads to $100 Million Bitcoin Heist

Coldcard perd 2 000 Bitcoins à cause d'une faille de firmware vieille de quatre ans
Coldcard Firmware Flaw Leads to $100 Million Bitcoin Heist

Community Trust ScoreVerified

84%
Real
Verified25 votes
Updated 2 hours ago

A massive theft. Coldcard, a well-known manufacturer of hardware wallets in the Bitcoin ecosystem, has confirmed the loss of 2,000 bitcoins — over $100 million — directly linked to a security flaw in its own firmware. The incident was made public on July 31.

The flaw dates back to March 2021. For years, no one noticed — or at least, nothing was said. The issue affects the generation of 24-word recovery phrases, the fundamental mechanism that allows a user to regain access to their funds if their device is lost or broken. However, Coldcard’s method of generating these phrases made the associated private keys easier to guess for someone who knew where to look. Malicious actors evidently knew where to look. The result: 2,000 bitcoins gone.

No recovery in sight.

Advertisement

Jonathan Goodman and $1.6 Million Vanished

Jonathan Goodman, an entrepreneur, is among the identified victims. He lost $1.6 million in bitcoins. His case is likely not isolated — the flaw has affected an undetermined number of users, and the total amount stolen suggests that several wallets have been emptied. Coldcard has asked its customers to create new strengthened private keys and transfer their funds to new addresses. Quickly.

It’s the kind of recommendation that always comes too late for some.

The situation reignites an old debate in the crypto community: are we really safer with a cold wallet than with a centralized platform? The honest answer is that it depends — and both options have their share of disasters.

Self-Custody vs. Centralized Platforms: The Real Score

A 2025 report provides thought-provoking figures. Since 2010, 1.57 million bitcoins have been lost via self-custody wallets. On centralized exchange platforms, it’s 1.51 million. The numbers are close. Too close for one to be clearly “safer” than the other in the long run.

Centralized platforms are convenient. Simple interface, customer support, account recovery if you lose your password. But they also have their own disasters: massive hacks, sudden bankruptcies, forced closures. In Europe, recent MiCA regulations have pushed several crypto exchanges to shut down, leaving users without access to their funds for weeks.

Cold wallets, on the other hand, embody pure Bitcoin ideology: “Not your keys, not your coins.” You control everything. No one else can block your funds. But you also bear all the responsibility — and if your device’s firmware has had a flaw since 2021, you won’t know until the day your balance is zero.

Coldcard is not the first manufacturer to face this kind of problem. In 2020, Ledger — the French company — suffered a hack that exposed the personal data of over 273,000 clients. Physical addresses, balances, contact information. This led to a series of attacks against wallet holders, notably in France. Technically different — it was a data leak, not a key generation flaw — but the real-world impact for victims was just as harsh.

This sector changes quickly, and not always for the better.

The problem with hardware wallets is that users trust them precisely because they are supposed to be the ultimate solution. Offline, physical, impossible to hack remotely. Except “offline” doesn’t mean “flawless.” The firmware is indeed code. And code has bugs. Here, this bug lasted over four years without being detected — or without being made public, which is an important distinction.

It’s not yet clear if Coldcard knew before July 31.

Users who bought a Coldcard device between March 2021 and the firmware fix are potentially exposed. The company has not specified how many devices are affected or how many wallets have been compromised in total. The figure of 2,000 bitcoins stolen is circulating, but the source does not provide details on the number of individual victims beyond Goodman’s case.

What we know: the 24-word recovery phrase is the heart of any HD wallet system. If the way these words are generated is predictable — even slightly — an attacker with enough computing power can test combinations until they find the right one. That’s exactly what seems to have happened here. The flaw did not allow direct access. It made guessing feasible. Technical nuance, identical consequence.

Coldcard has asked its users to migrate their funds. Jonathan Goodman, however, lost $1.6 million.

Frequently Asked Questions

What flaw allowed the bitcoin theft at Coldcard?

A flaw in Coldcard’s firmware, present since March 2021, affected the generation of 24-word recovery phrases, making private keys easier to guess for malicious actors.

What should Coldcard users do after this incident?

Coldcard has asked its customers to create new strengthened private keys and transfer their bitcoins to new addresses to secure their funds.

How many bitcoins were stolen and what is their value?

Approximately 2,000 bitcoins were stolen, valued at over $100 million at the time the incident was revealed on July 31.

Community Trust IndexHigh Confidence
84%
Real
Real84%16%Fake
25 community signals

Jean-Luc Maracon

Jean-Luc Maracon is a French-Swiss expert in decentralized finance, known for his sharp analysis of Bitcoin, European Web3 projects, and crypto regulatory challenges. Splitting his time between Geneva and Paris, he brings a unique perspective blending traditional finance with blockchain innovation. He regularly collaborates with crypto platforms across Europe to help make digital investing more accessible. Specialties: Bitcoin, staking, European regulation, crypto security, Web3.

Advertisement

Related Stories