David Schwartz weighs in on $100M Coldcard hack, and why self-custody still has teeth
A Coldcard firmware flaw tied to seed generation has been linked to large Bitcoin thefts, and Ripple CTO Emeritus David Schwartz used it as a reminder that self-custody removes middlemen, not risk.
- Galaxy Research says the losses tied to the Coldcard issue have climbed past $100 million in Bitcoin terms, with estimates still evolving.
- David Schwartz framed the incident as a case of outlier risk: rare custody failures can still cause massive damage.
- The problem was a seed-generation flaw in vulnerable Coldcard firmware, not a break of Bitcoin itself.
- Affected users must generate a new seed and move funds; a firmware update alone does not repair an already compromised seed.
The Coldcard mess is a blunt reminder that hardware wallets are tools, not magic shields. They can cut exposure to exchanges and other custodians, but if the seed is weak, the whole setup is compromised no matter how “air-gapped” the device looks on your desk.
Coldcard is a Bitcoin-only hardware wallet made by Coinkite. The issue centers on vulnerable firmware that affected seed generation on specific models and versions, allowing attackers to target wallets whose recovery material was created with insufficient randomness. Coinkite’s Firmware Update Advisory for Coldcard Mk2, Mk3, Mk4, Mk5 lays out the relevant firmware ranges and the steps users need to take.
According to Coinkite, affected firmware includes Mk2 and Mk3 versions 4.0.1 through 4.1.9, with the flaw introduced in firmware released in March 2021. Coinkite also says similar issues affected other Coldcard model tracks, and that TAPSIGNER, OPENDIME, and SATSATARD are not affected because they use different codebases. For background on one of the newer devices in the lineup, see Coldcard MK5 Launches as Bitcoin-Only Hardware Wallet with better usability and security.
The company’s guidance is blunt: users on affected firmware should update to version 4.2.0 or later, generate a completely new seed, and transfer their Bitcoin. Coinkite also recommends a small test transaction before moving the full balance, and says adding at least 50 private dice rolls is an optional way to introduce independent entropy. For people looking at the broader user fallout, Mk3 Security Advisory has been circulating among affected users as the practical checklist gets passed around.
What went wrong
The failure was not a remote hack of the Bitcoin network or a break in the protocol. The problem sat in the wallet layer, where the software that creates new seeds was not generating enough randomness.
A seed phrase is the recovery material that can recreate a wallet’s private keys. If that seed is predictable or weak, an attacker can potentially narrow the search space and reconstruct it offline. Once that happens, the wallet is effectively poisoned from birth. In the context of this mess, Coldcard Seed Flaw May Have Drained 1, 367 BTC as Users were urged to migrate funds is the kind of headline nobody wants attached to their cold storage setup.
That is why a firmware update alone does not solve the problem. A patch can help future seed generation, but it cannot repair a seed that was already created with weak entropy. If the foundation is cracked, repainting the walls is not a fix.
Coinkite’s own guidance reflects that reality: generate a new seed, move the funds, and do not assume the old recovery phrase is safe just because the device now runs corrected firmware.
Galaxy Research’s estimate keeps moving
Galaxy Research has linked multiple on-chain sweep waves to the vulnerability and shared hundreds of suspected attacker addresses with U.S. federal investigators, exchanges, and blockchain security companies. One separate account of the incident, Coldcard firmware bug may have exposed Bitcoin holders to a large theft, shows how quickly the numbers started climbing once the pattern became clear.
The size of the losses is still being refined. In the materials available, Galaxy’s estimates range from roughly $88.6 million to more than $100 million, depending on which suspected waves are included and whether address clusters overlap. The clean takeaway is that the thefts are large; the precise final total is still being worked out.
Galaxy has identified thousands of affected addresses in its analysis, but on-chain attribution has limits. Blockchain data can show sweeping patterns and probable control of funds, but it does not magically turn every suspicion into courtroom-proof certainty. Useful? Absolutely. Omniscient? Not even close.
At the latest update cited in the research notes, about 90% of the Bitcoin stolen in the confirmed waves had not moved again. That does not make the coins less stolen. It just means they were sitting still when the data was last reviewed. That’s where Two More Waves Raise Suspected Coldcard-Linked Losses to even more suspicion comes in, because fresh waves tend to turn “maybe” into “oh, this is getting ugly.”
Why Schwartz’s comment lands
Schwartz used the Coldcard failure to make a broader point: rare custody failures can still produce devastating losses. He described that kind of event as outlier risk, meaning a failure that seems unlikely until it wipes out a lot of value in one shot. His framing also echoed a related take on inheritance and storage planning in David Schwartz Proposes Bitcoin Inheritance Setup with a cold-storage angle, which makes the point that key management problems do not stop being problems just because the coins are “safe.”
He compared the broader lesson to traditional finance custody failures such as MF Global’s 2011 collapse, which is fair enough as a reminder that centralized systems are not inherently safer just because they come with suits and compliance departments. Different wrappers, same human fallibility.
The important nuance is that self-custody does not eliminate operational risk. It removes counterparty risk by cutting out the middleman, but it also shifts the burden onto the user. There is no friendly help desk to restore a compromised seed phrase. There is no insurance fairy waiting to patch over bad entropy.
That is the tradeoff many Bitcoiners accept for sovereignty. It is also why self-custody demands discipline, not just ideology.
Why this is not a Bitcoin failure
Bitcoin itself was not hacked. The protocol worked. Transactions worked. The failure came from a wallet implementation that did not generate seeds with sufficient randomness.
That distinction matters because every wallet problem tends to get stapled onto Bitcoin by people who either do not understand the difference or prefer not to. A broken wallet is not proof that Bitcoin is broken. It is proof that wallet security is hard, and that bad firmware can wreck people just as effectively as a thief with a wrench.
Hardware wallets exist to reduce online exposure. An air-gapped device is kept off the internet, which lowers the attack surface. But if the seed generation process is flawed, that air gap is cold comfort. The attacker does not need to “hack” the device if the device hands them a guessable seed in the first place.
What affected users need to do
Coinkite’s instructions are not subtle, because they do not need to be:
• Update to v4.2.0 or later
• Create a new seed
• Move funds to the new wallet
• Send a small test transaction first
For users who are not deep in wallet security jargon, the key term is entropy. That is simply the randomness used to generate a seed. The more reliable the entropy, the harder the seed is to predict. If the entropy is weak, an attacker may be able to reduce the search space enough to make recovery feasible.
Coinkite says adding at least 50 fair, independent, private dice rolls can provide enough independent randomness if used correctly. In plain English: it gives the seed another source of randomness outside the device’s firmware. That is a useful mitigation, but it is not a reason to get lazy about migration if your seed was already created on vulnerable firmware. The original Coldcard MK5 Launches as Bitcoin-Only Hardware Wallet with pitch still holds for the device class overall, but no hardware wallet gets a free pass when its seed math is busted.
A strong BIP-39 passphrase can also add another layer of protection, but it does not fix a seed that was already generated poorly. The rule here is the same one that applies to every compromised secret: once it may be exposed, treat it as exposed.
What this says about self-custody
Self-custody is still the right direction for people who want real ownership of Bitcoin. It removes counterparty risk, keeps control in the hands of the holder, and avoids handing your coins to an exchange that may or may not be run by clowns with a balance sheet.
But self-custody is not a slogan. It comes with operational duties that are easy to ignore until they bite you in the wallet. Firmware matters. Backups matter. Entropy matters. Migration after a vulnerability disclosure matters. The glamorous part is owning the keys; the unglamorous part is not losing them through carelessness or broken randomness.
The Coldcard flaw is a good reminder that “secure by design” is not a force field. It is a promise that has to survive firmware updates, implementation mistakes, and human assumptions. When that promise fails, the damage can be enormous.
Key questions and takeaways
-
Was Bitcoin itself hacked?
No. The issue was in Coldcard firmware and seed generation, not in the Bitcoin protocol. -
Which Coldcard firmware was affected?
Coinkite says Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 were affected, with the flaw introduced in March 2021. -
Can a firmware update fix an exposed seed?
No. Users must generate a completely new seed and move funds to it. -
How large are the reported losses?
Galaxy Research says the losses tied to the flaw have risen past $100 million, though its estimate has been updated several times and remains under refinement. The broader address-level analysis from Coldcard firmware bug may have exposed Bitcoin holders to a major theft underscores just how much value was at risk. -
What is the real lesson for Bitcoin holders?
Self-custody reduces dependence on intermediaries, but it does not remove operational risk. If firmware, entropy, or backups fail, the user eats the loss.
The takeaway is uncomfortable but useful: hardware wallets are only as strong as the randomness behind them. When a flaw is disclosed, the right move is not denial, and it is definitely not hoping the old seed magically becomes safer. Verify the firmware, generate fresh entropy, and move the funds.