COLDCARD: THE GHOST OF DOUBT

Illustration by Shirley Yu for Sum of Parts

GHOSTS EXIST


Imagine yourself an aspiring oligarch — many Bitcoiners do.


It’s the mid-19th century. As a scientific materialist, you understand that the industrial revolution is coming. You have put every spare cent into bearer shares of the newfangled railroad firms. You favor the anonymous, self-custodied bearer assets – banks, after all, have a tendency to fail.

So you buy a safe. The best safe on the market — the Sovereign Safe.

It’s marketed directly to people like you. Its slogan is “Trust in Steel Alone.”

Nobody but you and the pair of workmen even know the safe exists. They tuck it into a small back room. You bury them with it, concealing them and your riches behind a false wall.

Utterly secure, you start stacking stocks: the Baltimore and Ohio, the Chattanooga. And the gold standard: The Union Pacific. All of it on sheets of paper in a hidden, bomb-proof safe.

Time flies. You’ve been saving for a decade. The smell has faded, while those bearer stocks have soared in value. Your children will go to Harvard, to Yale, to Europe. You’ve built a legacy that the march of history will turn into a generational fortune.

Then you open up your Sovereign Safe — and it’s all gone.

No one has drilled into it, or wedged it open. The lock hasn’t budged. You are in a daze. Your stomach is in your knees.

You hear laughter behind you — a chuckling pair. You turn to confront the thieves of your legacy, to beat them half to death, to take it back, to send them to prison for life.

Instead you see the bearer stocks fluttering in midair, clutched in greedy claws of haze.

Above them float the spectral leers of the workmen. Then they disappear with your stocks.

You’ve just learned that ghosts exist — and they’re thieves.

This story is about the Coldcard attack.



NIGHT OF THE ZOMBIE WALLETS

Beginning on July 30, a lot of very sleepy Bitcoin suddenly started to wake up. In four waves of attacks, it was moved from thousands of individual wallets into the wallets of a still-unknown attacker or attackers.

Estimates of the damage vary, but they’re all huge. TRM Labs claims 1,816 BTC have been stolen, worth roughly $116 million, from 5,200 addresses. Galaxy Research, who have taken the lead in tracing the stolen funds, believes a minimum of 1,730 BTC are gone. The attack only impacted Bitcoin, not any other cryptocurrency, because Coldcard only supported Bitcoin.

Galaxy’s research revealed other critical details. The median “dormancy” of the stolen coins, which is the time since they had last moved, was 3.5 years. 88% of the coins hadn’t moved in more than 1 year. And the median loss per wallet was 1.022 BTC. These were long-term bitcoin savers, the mythical HODLers who exemplify Bitcoin virtue, at least in the maximalist community.

These were nominally very secure wallets. Their “seeds,” the root codes that gave access to the Bitcoin in an on-chain wallet, had never touched the internet. Hardcore users etched their seeds into steel plates and buried them. It was physically impossible that the numbers had been remotely extracted in a hack at this scale.

Yet attackers somehow had the keys to all of them.

The extent of the damage is foggy because Coldcards are self-custodial tools. The money was moved from thousands of individual, separate wallets. There is no central record of wallets created with the vulnerable Coldcards, nor of the amounts held in each one. This has made it difficult for forensic researchers to trace the full scale of the stolen funds. Some people may not even be aware they have been victimized yet. The moving coins aren’t directly recognizable as thefts in on-chain records, either, because the attacker had the keys.

No, they look like regular transactions. After all, isn’t that how bitcoin works? If you have the keys, you own the coins.

Coldcard is the cruel inverse of the old adage “not your keys, not your coins”; here, someone who wasn’t supposed to have them found the keys.

How? The attacker or attackers were able to “guess” the keys because a critical random-number generator in the Coldcard hardware was broken. Private keys generated from Coldcard seeds could simply be reproduced through computational brute-force. This flaw appears to impact every Coldcard wallet from 2021 onwards.

Coldcard users should move their Bitcoin to entirely new wallets, generated from new seeds using non-Coldcard technology, immediately.




I’M NOT LIKE THE OTHER GIRLS HACKS

Hacks in crypto are a dime a dozen. They’re often so large the numbers become meaningless, much like trading volumes. For example, I’ve been writing a lot this year about the $600M Ronin Bridge/Axie Infinity hack of 2022… and there have been at least five other hacks of the same scale.

By comparison, the roughly $130M so far tallied in the Coldcard attack may seem less significant in comparison. However, scale isn’t what makes it such a big concern, and in terms of the count of individual wallets connected, here the carnage is significant.

Crypto’s other big hacks almost exclusively targeted large, concentrated pools of money with discrete security vulnerabilities: DeFi liquidity, bridge contracts holding assets shared across networks, or centralized exchange deposits. Often, those hacks boil down to stealing the private keys of a negligent worker or three through complex social engineering attacks, such as North Korea’s Lazarus Group scamming their way into remote jobs. This is a failure of centralized infosec, and often, a human behavioral issue more than a hack.

The Coldcard compromise was different: this drained thousands of small to medium-sized individual wallets.

In a painfully ironic twist, the perceived vulnerability of those big targets was the exact reason people were using Coldcard. Coldcard was the product for people who utterly loathed the idea of letting anyone else custody their funds for them, and particularly those who had seen exchange hacks again and again.

Moreover, the targeted wallets had largely never touched the internet, so it also should have been impossible to break into anyone’s computer and steal the seed numbers or the private keys generated from them. As many commentators have put it, Coldcard users “did everything right.”

The flaw, instead, was in Coldcard’s seed generation system. Encryption depends on large amounts of true randomness, but a bug in Coldcard’s code effectively turned off its random-number chip.

This means an attacker only had to randomly generate private keys and see if they opened any wallets with money in them.

They did.

WHAT IS COLDCARD?

Coldcard is (or was?) a Bitcoin hardware wallet manufactured by the firm Coinkite. Hardware wallets are devices used to segregate a crypto wallet’s seed phrase from internet-connected devices. The seed phrase is the root of the “private keys” that act as passwords to individual on-chain Bitcoin wallets. 

Coinkite is (or was?) something of an institution in Bitcoin circles, also producing the iconic Block Clock data display.

Coldcard, to be clear, is not actually a “card,” either physically or conceptually. Its form factor is more like a calculator, and its purpose is the exact opposite of a credit or debit card. It’s for storing money you don’t want to spend, and best described as a kind of digital safe.

WHAT IS A COLD WALLET?

A physical safe relies on the strength of its tempered steel. Coldcard was also supposed to be secured by a physical barrier: the air.

The name “Coldcard” is a reference to a “cold wallet,” a type of crypto wallet that keeps sensitive private keys (and seeds) completely segregated from the internet. In theory, that means they can’t be “hacked” in the conventional sense of infiltrating a system and stealing data.

Very broadly, a cold wallet works because it can “sign” a transaction without exposing the underlying passcodes that prove ownership. The critical codes can be used without anyone, including even the owner, actually seeing them. That contrasts with software or “hot” wallets like Metamask, many integrated into browsers or “always on” in a way that can increase their vulnerability to hacks or malicious contracts.

And it’s true, Coldcard users’ private keys weren’t stolen or exfiltrated. Instead, attackers were able to simply guess them, like someone guessing your luggage combination.

This is the core of the terror the incident has caused: cold wallets were supposed to be completely secure. However, it turns out you still have to trust the manufacturer not to make a gargantuan error.


WHAT IS A SEED?

A “seed” is either a number or a 24-word phrase used to generate the public/private key pairs that secure cryptocurrency wallets. They’re roughly equivalent to the “secret” that acts as an encoding/decoding key in public-key cryptography. Anyone who knows a seed phrase can derive and gain control of any wallet generated from that seed, and the crypto secured by that wallet and private keys.

The additional twist is that a seed can be used to generate any number of wallets, each with their own private key. This can feel like a crypto holder is spreading risk, but a compromise of the seed then compromises all wallets created from it.

WHO DID IT?

That’s a burning question, but the nature of the Coldcard attack makes it particularly difficult to answer.

Because the private keys were generated rather than being stolen, there is no way to trace an initial incursion back to any online source. The money was/is also being pulled directly from individual wallets, so there’s no single origin to trace the funds moving out of, either. 

In short, these will look pretty much exactly like standard Bitcoin transactions, by the rightful owners of the wallets. The biggest obvious exception is that a lot of these coins haven’t moved in a long time.

The coins could sit in their new destinations dormant for years, giving no new data for sleuths. This was why the 2016 Bitfinex hack of 119,756 Bitcoin went unsolved for about seven years. Those hackers finally exposed themselves by selling some of their haul. It’s generally fairly difficult to capitalize on stolen Bitcoin, which has limited anonymizing options. Trying to move the money to an exchange or similar service would likely reveal the culprit’s identity - eventually.

We probably don’t have to wait very long for answers, though. Clay Garrett of Bitkey claims to have confirmed that at least one of the Coldcard attackers used a private data service to scout wallets ahead of and during the attack. They used a paid account, which strongly suggests there may be a way to determine the attacker’s identity.

This would be a really staggering misstep by the attacker. But Alex Thorn at Galaxy, among others, doesn’t believe this was the work of a single attacker. Instead, he sees a mix of initial attacks and copycats, some of them less sophisticated.

There have been a few other fringe theories - most notably, speculation that this was an “inside job” by someone at Coldcard. While that would possibly explain some of Coldcard’s lax security (see below), there’s no real evidence for it.

HOW DID THEY GET THE KEYS?

The Coldcard attack should have been physically impossible – or more precisely, it should have been mathematically and computationally impossible. 

A 24-word Bitcoin seed phrase has 1.15 × 10⁷⁷ possible combinations. A Bitcoin private key is 256 bits long, creating 2²⁵⁶ possible combinations. According to Gemini, this can also be expressed as “Roughly 115 quattuorvigintillion.” That sounded like an AI hallucination to me – but no, “quattuorvigintillion” is an actual number.

Seeds are meant to be generated based on true randomness, which private keys inherit. True randomness is vital in cryptography: anything at all that’s predictable or guessable is a huge vulnerability. The Allies beat Nazi Enigma machines by tracing small, predictable patterns that emerged across thousands of messages.

If a computer guessed one trillion numbers per second, it would still take longer than the life of the universe to guess a truly randomly generated 256-bit key or a similarly complex seed.

The problem was that Coldcard’s seeds were not even close to properly generated. 

Getting true randomness is very difficult in a digital environment, so the Coldcard included a “noise chip” that generated random numbers based on sounds. But a software update pushed way back in 2021 effectively removed that physical noise chip from the seed-generation flow. 

Instead of a truly incalculably large number of possibilities, this reduction in randomness made Coldcard keys guessable by computational brute force. Without the added bits from the randomness chip, in the loop, possible seeds generated from some compromised Coldcards could be as low as one trillion. 

In some cases, engineers at Block found that the number of possible outputs from the compromised seed generator was as low as 80,000-120,000, which makes them about as secure as your school locker.

THE END OF BITCOIN MAXIMALISM?

Our little horror tale was meant to convey just how completely unexpected and deeply unnerving the Coldcard attack is. It is being widely described as“the worst event in Bitcoin’s history”. That’s not because of its scale, but because it challenges our basic understanding of cryptocurrency and cybersecurity. The numbers don’t entirely tell this story.

The hack, at this publication, might not be over. It’s not even clear that the successive “waves” of attacks have been executed by the same attacker. Once the technique and vector were known, someone new could pick it up and find more vulnerable wallets that haven’t yet been drained.

The attack doesn’t reveal a critical flaw in the Bitcoin code itself – that would certainly be worse. But the Coldcard compromise deeply undermines some of the basic assumptions that make the system trustworthy. It is arguably a radically new security vector – like suddenly discovering that ghosts exist, and that they like digital cash.

The attack’s implications are particularly bad for hard-core Bitcoiners committed to total self-custody and anti-state or radical libertarian ideas. These are broadly the bitcoin “Maximalists” who either believe that Bitcoin is the inevitable money of the future, or at least a gold-like hedge against coming social instability.

Henrik Andersson, CIO of Apollo Crypto, lays the blame squarely on this subculture.

“It was Toxic Bitcoin Maximalists that led people to use Coldcard. They ignored science for virtue signaling.”

That “virtue signalling” took a very specific form, including slogans like "Don't Trust – Verify" and “Trust No One,” using “honey badger” imagery, and selling “Little HODLer” merch for infants. 

Perhaps above all, Coldcard was vocally Bitcoin-only, and cited that as a security advantage. "Unlike Trezor and Ledger, COLDCARD supports only Bitcoin to reduce the attack surface.” 

The current versions of the Coldcard wallet, the Q and Mk5, are even made of see-through orange plastic, evoking both Bitcoin and transparency.

The implication of transparency was specifically misleading - as we’ll explore, Coldcard’s software wasn’t open-source, and the critical glitch wasn’t discovered largely because of the organization’s lack of transparency and collaboration with others. More broadly, Coldcard’s security culture and practices were weak in specific ways that have been highlighted since the attack - but which were seemingly papered over by such signalling.

Critics view this self-siloing as a synecdoche for the broader isolation of Bitcoin Maximalists from “crypto” writ large, and the fragility that may result. The painfully ironic consequence of Coldcard’s sloppy self-righteousness was to make Bitcoin as a whole less secure. The Coldcard glitch couldn’t be used to steal Ethereum or Solana – not even “shitcoins” like ObamaSonicInu, Melania Coin, or Cardano.

Bitcoin can’t become the world’s currency, a reserve asset, or even a doomsday escape hatch if nobody can trust the methods used to secure it. Though it’s not the first time he’s said it, there was a real basis for Nic Carter’s assessment that“maximalism is over”.

Maximalism is under added threat because many of its most prominent leaders endorsed Coldcard as the gold standard of security. This was largely without direct sponsorship relationships, but it still reflects very badly on them. One of the most widely-read statements from a victim of the hack came from an investment advisor named Tim Lamb, who wrote that he was “led to believe this was really secure. It was recommended by experts including @saifedean.”

That’s Saifedean Ammous, author of The Bitcoin Standard – generally considered the Bible of Bitcoin maximalism. He’s just one of dozens of Bitcoin-forward thought leaders (also including Alex Gladstein of the Human Rights Foundation) who have had to apologize for recommending the tool.

That’s just one aspect of a much larger destruction of trust within the tight-knit community – not just trust in individuals, but trust in ideas. As one Redditor put it bluntly, the hack is making people lose faith in the entire idea of self-custody.

This self-siloing is tempting to view as a synecdoche for the broader isolation of Bitcoin Maximalists from the broader crypto sphere, and the fragility that may result. The painfully ironic consequence of Coldcard’s sloppy self-righteousness was to make Bitcoin as a whole less secure. The Coldcard glitch couldn’t be used to steal Ethereum or Solana – not even “shitcoins” like ObamaSonicInu, Melania Coin, or Cardano.

Bitcoin can’t become the world’s currency, a reserve asset, or even a doomsday escape hatch if nobody can trust the methods used to secure it. Though it’s not the first time he’s said it, there was a real basis for Nic Carter’s assessment that“maximalism is over”.

Some of Maximalism’s most prominent leaders endorsed Coldcard as the gold standard of security. This was largely without direct sponsorship relationships, but it still reflects very badly on them. One of the most widely-read statements from a victim of the hack came from an investment advisor named Tim Lamb, who wrote that he was “led to believe this was really secure. It was recommended by experts including @saifedean.”

That’s Saifedean Amous, author of The Bitcoin Standard – generally considered the Bible of Bitcoin maximalism. He’s just one of dozens of Bitcoin-forward thought leaders (also including Alex Gladstein of the Human Rights Foundation) who have had to apologize for recommending the tool.

That’s just one aspect of a much larger destruction of trust within the tight-knit community – not just trust in individuals, but trust in ideas. As one Redditor put it bluntly, the hack is making people lose faith in the entire idea of self-custody.

SELF-CUSTODY AND WHY IT MATTERS

There are very sensible general reasons that self-custodying your own cryptocurrency or digital assets is straightforwardly useful. These include small miscellaneous payments, or for users without access to trusted conventional services.

But the specific Bitcoiners catered to by Coldcard are motivated to self-custody unusual amounts of cryptocurrency because of their beliefs about politics and economics.

Maximalists overlap in a few ways with the preppers and gold bugs of previous eras. Highly simplified, they believe that mounting national debts will render every “fiat” currency worthless, and Bitcoin the only common, trusted, global medium of exchange. In that sort of situation, when rule of law and institutional trust would evaporate, “maximalists” want to have direct control of those precious coins.

PLAGUE UNLEASHED: THE MANY FAILURES OF COLDCARD

Events are still unfolding. But it is increasingly clear that Coldcard manufacturer Coinkite was substantially responsible for the flaws that enabled the theft of more than $130M worth of self-custodied digital assets, 

Their internal controls failed to catch a devastating, core bug for five years. Worse, a pattern of silencing critics, avoiding oversight, and alienating allies appears to have helped keep the vulnerability circulating in the wild, infecting new wallets.

According to an excellent code-level deconstruction by Harry Donnelly, the critical bug arrived in a March 2021 update. In effect, the flawed code thought it was getting physical randomness from Coldcard’s onboard noise chip during the seed-generation process, but was actually getting a far less random return. 

This in turn created the much smaller set of seeds generated by the devices, making them vulnerable to brute-force number guessing.

The vulnerability may have been exploited very soon after it was introduced. One Coldcard user reported the draining of a Coldcard as early as 2022 – which does line up with the timing of the flawed software update. More conclusively, a developer named James O’Beirne has shared evidence that he highlighted the issue in May of 2025 and was, according to him, dismissed by the Coinkite team.

Any early reports weren’t met with warnings or fixes.

There have also been reports that Coinkite failed to pay researchers who reported bugs going back to 2019, setting a precedent that reduced researchers’ future incentive to disclose their findings to the company.

Alex Thorn of Galaxy has also alleged that Coinkite had a bad reputation in the broader security community because of the somewhat unusual licensing status of their code. A lot of crypto and Bitcoin software is open-source because it is crucial that users can actually verify that the code is trustworthy and safe - obviously important when money and multiple parties are involved. With open source, everyone using related components and libraries can interface easily, and watch each other’s proverbial backs.

Yet Coldcard declined to fully participate in the collaborative system that its "Don't Trust – Verify"  marketing alluded to. 

Though it launched as fully open-source, Coldcard backtracked. From FOSS/GPL, its license changed to “source-available” with a “Commons Clause.” This meant the source could be compiled and reviewed, but not re-used in any competing commercial project.

This is not “open source” in any meaningful sense, because it removes the incentive for community review. The neighbor isn’t going to do a free code review for you unless you let them borrow a cup of sugar in return.



THE AI FACTOR

It is not known, and may never be known, whether AI was critical to the discovery of this bug by the attackers. As noted above, human researchers had raised concerns.

But it is very plausible that a bad actor pointed an advanced LLM at the Coldcard codebase and identified a weakness that had lain dormant for five years. A Claude Code instance without access to current discussions of the hack found it in eight minutes, according to a developer going by Medusa On Chain.

The universal and near-instantaneous consensus has been that all Bitcoin and crypto developers need to be pointing LLMs at their own code to search for bugs.

Rather than wait for projects to undertake and fund that effort on their own, a team of white-hat hackers (good guys) going by Bitcoin Red Team has been scanning code proactively and responsibly notifying developers. As of last week, they already reported identifying 85 critical vulnerabilities across projects.

That’s how cybersecurity in general works all of a sudden: it all comes down to who unleashes the bots first, and in force.

This suggests that the real threat of AI, not just in crypto but in general, is exactly to smaller and scrappier projects like Coldcard, or tools that aren’t considered critical. 

Big institutions would seem to benefit from that dynamic, which again drives home how toxic this incident is for the individualistic and decentralized ethos of Bitcoin.


LEGAL RAMIFICATIONS

A court or three may have the chance to hammer out whether this and subsequent evidence amounts to negligence with liability implications. 

Discussions and even announcements of several class action or similar lawsuits have commenced, including one in Canada being publicly spearheaded by FTX liquidation recovery figure Thomas Braziel.

But the stakes here are also very different than in the hacks of exchanges and even DeFi pools. Even if they were successfully sued, it seems extremely unlikely that Coinkite itself has the assets to help victims meaningfully recover - they are essentially a niche hardware manufacturer, not a financial entity.


SHOULD YOU JUST BUY A BITCOIN ETF?

A point being widely made in the wake of this hack is that a Bitcoin ETF has never been hacked or otherwise lost underlying funds. We have some visibility into how these entities secure their assets, and there is little chance that a non-expert with an at-home setup can come anywhere close.

But more to the point, the Coldcard hack drives home that no individual, possibly not even a genuine expert, can fully vet all of the code of all of the tools they’re using in their self-custodial setup.

Of course, that doesn’t mean self-custody is irrelevant. If you think the world is going to end and property rights evaporate, or are in a jurisdiction where banks truly can’t be trusted? If so, the inherent risks of self-custody might be worth it.

But even if you’re a regular user of Bitcoin for transacting, you may not want to self-custody the bulk of your holdings. 

Equally to the point, the industry around Bitcoin may not want to keep promoting self-custody to a mass of people who can’t themselves verify their setups — and apparently can’t trust vendors endorsed by the biggest names in Bitcoin.

For political dissidents in Russia, women in Afghanistan, or guys who murdered their construction crew and fled the scene, full self-custody is an invaluable feature. But for many others, the unfortunate truth is that the anti-authoritarian BTC maximalist movement is likely increasing, not decreasing, the risk of loss for most people who take their message to heart.

The irony, of course, is that self-custody is a large part of Bitcoin’s core value proposition. What happens if it becomes irrelevant or extinct? Does Bitcoin held in an ETF have value as Bitcoin — or is it just a speculative option on the future adoption of Bitcoin?

We won’t really know until we figure out how to keep these damn ghosts out of the safe.












Next
Next

AI 2060: The Dystopia of Closed Gates