Jonathan Goodman followed the rules for keeping his bitcoin safe.
The hardware wallet holding his keys, a Coldcard, had never been connected to the internet. He kept it stored in a safe deposit box. The seed phrase, which he’d never shared with anyone, was stored in a second safe deposit box. But on July 29, Goodman said, every wallet he had was emptied, every last satoshi stolen. The Toronto entrepreneur reported losing 18.25 bitcoin, worth just over $1.17 million at the time of the attack.
“Perhaps the hardest part about this is that I did everything right,” he wrote in an Aug 1 X post.
Goodman’s loss was part of a much larger hack impacting thousands of Coldcard users. Galaxy Research said it had high confidence that 1,596 bitcoin — worth over $100 million — had been stolen from about 7,300 addresses in a series of attacks. Galaxy research head Alex Thorn estimated on Aug. 4 that at least 15 different attackers were exploiting the flaw. None of them needed physical access to a device.
A hardware wallet’s entire security premise is that its secrets never leave the chip. With no internet connection, there’s no way in beyond physical access to the device. Though the physicality of a hardware wallet carries its own risks for users — as banal as misplacing the device and as frightening as a wrench attack — their major selling point is that they are safe from hackers and other online bogeymen.
But, in the case of Coldcard, this security promise fell short. The vulnerability was not in the wallet itself — it was in how the secret password, or seed phrase, protecting users’ coins was generated.
Wallets 101
Bitcoin wallets can come in different forms. Software wallets, also called “hot wallets,” run on an internet-connected device, making them easy to use but exposed if the device is compromised.
Hardware wallets, or “cold wallets,” such as Coldcard keep the keys on a separate device that’s not connected to the internet. One of the earliest forms of cold wallets were so-called “paper wallets,” where users wrote down the keys needed to access their wallets on a piece of paper. Though safe from hackers, these wallets carried an enormous risk of being damaged or lost.
Randomness is critical because a new wallet must select a seed from an enormous number of possible values. The unpredictability of that selection is measured in bits of “entropy,” used to refer to a lack of predictability. Every additional bit doubles the number of possibilities, making a seed harder to guess.
Coldcard was supposed to obtain that randomness from a dedicated hardware generator inside the device. Instead, a configuration error sent the wallet to a simpler software generator that used information including device and timing data.
That information isn’t completely random, so it could be narrowed down or reproduced, sharply reducing the number of seeds an attacker needed to test.
Put simply, Coldcard’s code was supposed to pick each wallet’s secret from a pool of possibilities so vast that no computer could ever try them all. Instead, a wiring error sent it to a smaller, weaker source that shrank the pool enough for an attacker to work through it.
Where things went wrong
The error came down to how two pieces of software communicated to read a setting, according to Block’s Bitcoin engineering and security team.
The setting was meant to turn off one source of random numbers after Coldcard added another. Libngu checked only whether the setting existed, not whether it was on or off. The firmware therefore built normally while using the wrong generator.
coindesk.com





