594 BTC. Around 500 wallets. Roughly 25 minutes. The devices never needed to be touched. Here is the Coldcard security incident in plain English: A hardware wallet is supposed to create a secret key so random that nobody could ever guess it. A firmware bug meant some Coldcards generated keys using far less randomness than intended. Think of choosing a winning number from billions of billions of possibilities, only to discover that the machine was secretly choosing from a much smaller list. An attacker could calculate possible keys offline, compare them with Bitcoin addresses visible on the blockchain, and take the coins without touching the device or knowing its PIN. What is confirmed: • 594.48 BTC was swept from 1,324 old #Bitcoin outputs • The sweep involved roughly 500 single-signature wallets • 562 #BTC was later gathered into one address • Coldcard confirmed a serious seed-generation bug • Fixed firmware has now been released What is not yet fully proven publicly: That every wallet in the 594 BTC sweep came from this exact Coldcard bug. The connection is strong, but the investigation is continuing. Coldcard users should: 1. Update Mk3 to 4.2.0+, Mk4/Mk5 to 5.6.0+, or Q to 1.5.0Q+. 2. Do not stop after updating. An old weak seed remains weak forever. 3. Generate a completely new seed on the fixed firmware. 4. Verify the backup and receiving address, send a small test amount, then move the remainder carefully. At least 50 fair, private dice rolls materially protected against this specific flaw. A strong BIP39 passphrase adds another barrier, but Coinkite still recommends migration. Multisig helps only when enough keys were generated independently and securely. The uncomfortable lesson: An air gap can protect a strong key. It cannot rescue a weak key created at birth. Self-custody removes the bank. It does not remove software risk, human responsibility or the need for independent verification. Share this with anyone using a #Coldcard. Calm action protects funds. Panic attracts scammers. Credit to Rob from Anchor watch (tag him if you know his npub) for the sharp on-chain tracking behind the 594 BTC figure. Rob, flag anything here that needs tightening.

Replies (12)

I genuinely feel for everyone affected by the Coldcard security incident. Unfortunately, people often learn in one of two ways: through curiosity or through pain. This incident will make many Bitcoiners more serious about operational security. A smaller number may walk away from Bitcoin entirely, carrying anger, fear, or lasting distrust. I understand that too. But this is life. You learn, adapt and move forward, or you surrender. View quoted note →
"Self-custody removes the cex. It does not remove software risk, human responsibility or the need for independent verification." YES - PROBLEM IS EVERYONE HAS TO BECOME COMPUTING EXPERT JUST HODL BITCOIN - THEN NO NORMIE WILL BUY THIS MAXI SHIT LECTURE FROM HERE ON. THAT SIMPLE TO SUMMARIZE. ADOPTION OF BITCOIN WITHOUT TRUSTED INTERMEDIATOR IS SUPER LOW ANYWAY