Jonathan Goodman followed the rules for keeping his bitcoin safe.
The hardware wallet holding his keys, a Coldcard, had never been connected to the internet. He kept it stored in a safe deposit box. The seed phrase, which he’d never shared with anyone, was stored in a second safe deposit box. But on July 29, Goodman said, every wallet he had was emptied, every last satoshi stolen. The Toronto entrepreneur reported losing 18.25 bitcoin, worth just over $1.17 million at the time of the attack.
“Perhaps the hardest part about this is that I did everything right,” he wrote in an Aug 1 X post.
Goodman’s loss was part of a much larger hack impacting thousands of Coldcard users. Galaxy Research said it had high confidence that 1,596 bitcoin — worth over $100 million — had been stolen from about 7,300 addresses in a series of attacks. Galaxy research head Alex Thorn estimated on Aug. 4 that at least 15 different attackers were exploiting the flaw. None of them needed physical access to a device.
A hardware wallet’s entire security premise is that its secrets never leave the chip. With no internet connection, there’s no way in beyond physical access to the device. Though the physicality of a hardware wallet carries its own risks for users — as banal as misplacing the device and as frightening as a wrench attack — their major selling point is that they are safe from hackers and other online bogeymen.
But, in the case of Coldcard, this security promise fell short. The vulnerability was not in the wallet itself — it was in how the secret password, or seed phrase, protecting users’ coins was generated.
Wallets 101
Bitcoin wallets can come in different forms. Software wallets, also called “hot wallets,” run on an internet-connected device, making them easy to use but exposed if the device is compromised.
Hardware wallets, or “cold wallets,” such as Coldcard keep the keys on a separate device that’s not connected to the internet. One of the earliest forms of cold wallets were so-called “paper wallets,” where users wrote down the keys needed to access their wallets on a piece of paper. Though safe from hackers, these wallets carried an enormous risk of being damaged or lost.
Randomness is critical because a new wallet must select a seed from an enormous number of possible values. The unpredictability of that selection is measured in bits of “entropy,” used to refer to a lack of predictability. Every additional bit doubles the number of possibilities, making a seed harder to guess.
Coldcard was supposed to obtain that randomness from a dedicated hardware generator inside the device. Instead, a configuration error sent the wallet to a simpler software generator that used information including device and timing data.
That information isn’t completely random, so it could be narrowed down or reproduced, sharply reducing the number of seeds an attacker needed to test.
Put simply, Coldcard’s code was supposed to pick each wallet’s secret from a pool of possibilities so vast that no computer could ever try them all. Instead, a wiring error sent it to a smaller, weaker source that shrank the pool enough for an attacker to work through it.
Where things went wrong
The error came down to how two pieces of software communicated to read a setting, according to Block’s Bitcoin engineering and security team.
The setting was meant to turn off one source of random numbers after Coldcard added another. Libngu checked only whether the setting existed, not whether it was on or off. The firmware therefore built normally while using the wrong generator.
Block said affected Mk2 and Mk3 devices received no secure randomness through that process. Mk4, Q and Mk5 devices received some, but the software kept only a small share.
Coinkite estimates that those newer devices produced seeds with 72 bits of randomness instead of the intended 128. That left about 72 quadrillion times fewer possible seeds.
Block traced the vulnerable code to firmware version 4.0.0, released on March 17, 2021. Coinkite identifies version 4.0.1 as the first affected release for Mk2 and Mk3 users.
The source code was publicly available, and the correct hardware generator was present in the finished firmware. Reviewers confirmed that the component existed but failed to follow the seed-generation process from beginning to end and determine which generator the device actually used.
The company said AI-assisted reviews it ran before the theft also missed the error. Tests using several leading AI models after the incident failed to identify it as well.
Coinkite has promised to publish a fuller account of the failure. It has said it is supporting affected customers directly.
The company did not respond to CoinDesk’s request for comment.
Coinkite has released fixed firmware for all affected Coldcard models and release tracks. The update fixes future seed generation but does not strengthen seeds already created with vulnerable software.
Affected users must install the corrected firmware, generate a new seed and move their bitcoin to addresses derived from it, according to Coinkite's advisory.
A different kind of counterparty risk
Coldcard was built on the idea that Bitcoiners could remove custodians and reduce the number of parties they needed to trust. The incident does not restore confidence in an exchange or bank as counterparty. It shows that self-custody substitutes a different dependency: Users hold the keys, but the wallet manufacturer still determines whether those keys were created safely.
The key to Jonathan Goodman’s million-dollar stash of bitcoin sat in a safe deposit box, inside a device that never went online. But, due to the flaw in Coldcard’s seed generation software, Goodman’s effort to physically protect his fortune made no difference.

-
1The Coldcard hack proves reputation is not a security model
-
2Tom Lee's Bitmine now owns 4.8% of Ethereum supply after latest ETH purchase
-
3No change in bitcoin holdings as Strategy boosted dollar reserve, bought back more STRC last week
-
4Ethereum’s next big upgrade has 66 proposals, including a major privacy fix
-
5Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers
-
6Bitcoin options remain expensive despite summer calm. Here's why it matters
-
7Bitcoin's biggest holders, Strategy and Metaplanet, are betting on math, not price
-
8Bitpanda fined 70,000 euros in Austria’s first published MiCA enforcement case
-
9Bitcoin tracks equity bounce, but $390 million ETF outflow week keeps bulls on back foot
-
10Binance handed user data to Russia that led to a Ukrainian donor's arrest

Building the Zcash Machine: Tachyon and Quantum Readiness

Building the Zcash Machine: Tachyon and Quantum Readiness
Zcash’s Tachyon upgrade aims to scale shielded payments, improve quantum readiness, and test whether its funding, security, and governance can hold.
Zcash’s Tachyon upgrade aims to scale shielded payments, improve quantum readiness, and test whether its funding, security, and governance can hold.
Why it matters:
Zcash’s Tachyon upgrade aims to scale shielded payments, improve quantum readiness, and test whether its funding, security, and governance can hold.

Ethereum’s next big upgrade has 66 proposals, including a major privacy fix

Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers

coindesk.com