FF News — The Fintech News Network

Coldcard Firmware Flaw Leads to $70M Bitcoin Theft: Is Self-Custody Still Safe?

By Lauren Towner · 3 August 2026

Press Release: Coldcard Firmware Flaw Leads to $70M Bitcoin Theft: Is Self-Custody Still Safe? | Featured Image by FF News

Quick Summary

A critical Coldcard firmware flaw enabled attackers to drain $70 million in Bitcoin by exploiting weakened cryptographic seed randomness. The vulnerability, present since 2021, allowed remote key reconstruction. Experts recommend immediate firmware updates and seed regeneration to secure affected self-custody hardware wallets.

How Does the Coldcard Firmware Flaw Impact Bitcoin Security?

The Coldcard firmware flaw represents a significant failure in hardware wallet security, where an implementation error bypassed the device's hardware random number generator. Instead, the system relied on a weak software fallback, creating predictable seeds that attackers could reconstruct without physical access to the devices. This vulnerability affected Mk3 and Mk2 models running specific firmware versions released since March 2021.

  • $70 million stolen across 1,196 Bitcoin addresses.
  • 1,082.65 BTC consolidated into four attacker-controlled addresses.
  • 41-minute window used to execute the massive drain.

"The entropy used to generate a seed should not depend on the device that holds it. If the device’s internal generator is the only source of randomness, it becomes a single point of failure: a flaw weakens its output without any subsequent check being able to reveal it, because a weak key is indistinguishable from a strong one until the moment someone guesses it. This is not a theoretical risk, it is what has just happened. A sound procedure combines entropy from sources independent of the device, within formalized procedures, with segregation of duties and independent controls over the related processes, as we do at CheckSig", explains Paolo Mazzocchi, chief operating officer of CheckSig.

What Should Affected Coldcard Users Do Immediately?

Investors using vulnerable firmware versions (4.0.0 to 4.1.9) must take proactive steps to secure their assets. Simply updating the firmware is insufficient for existing keys; users must generate new seeds and migrate funds to fresh addresses. The industry consensus highlights that external entropy sources, such as manual dice rolls, could have mitigated this specific failure by adding layers of randomness independent of the device's internal software.

  • Update firmware to the latest corrective version immediately.
  • Create new seeds as old ones remain permanently compromised.
  • Use dice rolls to ensure entropy is independent of hardware flaws.

"Self-custody transfers control to the investor, but along with control come technical and operational risks the investor is often in no position to observe: ‘your keys, your coins’ then becomes ‘your keys, your problems’. The problem is not self-custody, which must always remain possible, but the idea that holding the keys automatically equals security. The affected users did nothing wrong, and our solidarity goes to them, as to all savers who are asked to assess what they lack the expertise to assess. It is reasonable to demand that this assessment be carried out by qualified, independent third parties, and that it be documented. Better, then, to rely on professional custody with no single points of failure, with documented controls, independently verified, and with contractual liability and insurance coverage: it cannot eliminate every risk, but it governs them effectively", comments Ametrano.

How Does Multi-Signature Custody Prevent Similar Thefts?

The incident has reignited the debate over self-custody vs. professional custody. While single-signature wallets were the primary targets, multi-signature authorization stages provide a robust defense by ensuring no single point of failure can compromise funds. Professional setups, like those at CheckSig, utilize eleven distinct keys and hardware from multiple manufacturers to ensure that a single firmware flaw cannot lead to a total loss of assets.

  • 11 total keys used in CheckSig's three-stage authorization.
  • Zero Coldcard keys were used in CheckSig’s specific custody setup.
  • SOC 1 & SOC 2 Type II attestations provide independent verification of security controls.

"We do not promise the infallibility of a device, a key, or a person: we build custody in which none of these elements, on its own, is sufficient to move funds, in which the failure of any one of them can be detected, and in which controls are documented and verified by independent parties. Ours is a verifiable promise", concludes Ametrano.

FF NEWS TAKE:

This Coldcard firmware flaw is a wake-up call for the entire Bitcoin self-custody movement. While "your keys, your coins" is a foundational crypto tenet, this $70 million exploit proves that hardware wallet security is only as strong as the underlying code. The industry must move toward multi-vendor multi-sig solutions and independent entropy verification to eliminate single points of failure. CheckSig’s analysis correctly identifies that professional, audited custody is no longer just an option for institutions—it is a necessity for risk mitigation.

Companies in this story: CheckSig, Block, Coinkite, Trezor, Ledger

People in this story: Paolo Mazzocchi, Ferdinando Ametrano, Clay Garrett

More from News