Coldcard Hardware Wallet Exploit
Following a significant exploit affecting Coldcard hardware wallets, Casa’s CEO Nick Neuman monitored a troubling trend beyond the theft of Bitcoin. As the attacks unraveled—starting on July 30—approximately 233,000 BTC, valued at around $15 billion, began to shift to safer addresses. This security breach has already resulted in nearly $130 million in losses, linked to vulnerabilities found in Coldcard devices, manufactured by the Canadian firm Coinkite.
Root Cause of the Security Breach
The root of the issue stems from a firmware error integrated back in March 2021, which rerouted the process of key generation through a flawed software random number generator, thereby compromising the strength of private keys. Initially designed to offer a security level of 128 bits, these keys were reduced to a measly 40 bits, akin to a bank vault secured only by a four-digit code.
Impact on Bitcoin Addresses
Analytics firm Galaxy Research observed a concerning impact on over 5,200 Bitcoin addresses, as the attacks unfolded in three distinct waves, resulting in losses of about 1,596 BTC. In a bid to highlight Bitcoin’s resilience amidst these challenges, Neuman shared on-chain data gleaned from analyst James Check of Checkonchain. He noted that despite the breach, the principle of self-custody—where users manage their private keys rather than leaving them with an exchange—remained intact and adaptable.
Metrics and User Response
According to Neuman, the metrics indicated that 2,100 BTC were stolen, surpassing Galaxy’s figures, while 22,000 BTC were transferred to exchanges. More significantly, a staggering 233,000 BTC was relocated from long-term holders—those who had maintained their investment in dormant wallets for over 155 days—demonstrating a proactive safety measure from serious investors by seeking refuge for their assets. This volume significantly eclipsed the amount pilfered by the attackers.
Some users of Coldcard opted to transition to multisig wallets, which mandate multiple approvals to execute transactions, effectively safeguarding against single-device compromise. Others, utilizing entirely different devices such as Ledger and Trezor, recognized the severity of the threat and took action. Neuman confirmed these shifts in strategy through dialogues with concerned customers, estimating that for every Bitcoin lost, 10 to 100 times that amount was successfully relocated to secure venues.
Resilience of Self-Custody
In contrast to centralized exchange hacks, where all assets can be at risk simultaneously, this attack unfolded gradually, allowing more users to react and protect their assets in a timely manner.
“This is a powerful testament to the resilience offered by self-custody within the Bitcoin ecosystem,”
Neuman stated, underscoring that, had these assets been held at a custodial service, the situation could have been far worse.
Market Analysis and Recommendations
Supporting this perspective, analytics from Glassnode noted a dramatic decrease in long-term holder supply, dipping from around 15 million BTC to nearly 14.7 million, marking the sharpest weekly drop since December 2024. This occurrence transpired while Bitcoin’s trading price remained approximately 50% lower than its all-time peak of $126,000, recorded in October 2025.
In light of the exploit, Coinkite has advised any user who set up a wallet on firmware versions 4.0.1 to 4.1.9—spanning from March 2021 to July 2026—to immediately consider their wallets compromised and to proceed with generating a new seed for security purposes.