None
EN
Coldcard’s Hidden Flaw Triggered a Self-Custody Crisis
[]
FinanceFeeds
Coldcard’s Hidden Flaw Triggered a Self-Custody CrisisEnglish 日本語한국어ไทย繁體中文PortuguêsDeutschItalianoFrançaisEspañolA build configuration error in Coldcard hardware wallet firmware allowed attackers to drain approximately 1,816 BTC worth $116 million from over 5,200 addresses starting on 30 July 2026.
Mk4 and Mk5 models on firmware below 5.6.0, along with Q models below 1.5.0Q, retained approximately 72 bits.
Coinkite also said that using a strong BIP-39 passphrase creates a separate wallet that compromised seed words alone cannot access.
Self-Custody Faces Its Stress TestThe breach exposes a structural risk in single-device self-custody that no amount of personal security hygiene could have prevented.
Related: Coldcard’s Five-Year Vulnerability Exposes RNG Failure, Four Suspected Attack Waves and Reignites Self-Custody DebateBitcoin flows reversed from self-custody back to exchanges for the first time since the FTX collapse in November 2022.