₿ BTC Loading... via Binance

Sunday, August 2, 2026

Nobody Has a Safe Place to Put It: What Coldcard Actually Proved

BitBrainers - Nobody Has a Safe Place to Put It: What Coldcard Actually Proved

By BitBrainers Editorial

Coinkite shipped the code that lost other people's money, and nothing in what follows takes that off them. But the same category of failure has already hit the other side of the argument, the exchanges, and it hit harder. Blaming one company is correct and it is not sufficient. There is no side of this that is actually safe. Only different ways to lose.

The Number That Should Have Been the Headline

In the first half of 2026 the crypto sector recorded a record number of hacks, 207 by TRM Labs' count, most of them smart contract exploits. But the money did not follow the count. Infrastructure and key-management failures were about 15 percent of incidents and roughly 76 percent of the money stolen.

Coldcard sits in the second group, and so does every exchange breach in that same data. The exposure begins at the exact place the industry keeps losing the most money, which is how a key gets made and who holds it. That is not an obscure corner of the product. For a device whose entire purpose is generating and protecting a key, it is the product. For a custodian, it is the whole job.

We do not sell a safe answer here.

We read the failures honestly and tell you what they actually mean. That is the whole newsletter.

Subscribe

Why This Keeps Happening to Regular People

The people who lost coins on Coldcard were not careless. Many followed the exact advice the most respected names in Bitcoin were giving. The device sat on recommended-wallet lists for years. Trusting the consensus pick is not negligence.


This Was Coinkite's Failure, Start to Finish

The firmware was theirs. The change that routed seed generation away from the hardware random number generator, the device's only source of real entropy, and into a predictable software fallback went out in March 2021 under their name, in a product sold on the single promise that it would generate a key no one could guess. CEO Rodolfo Novak has said the company takes full accountability and that its review process failed to catch it. That much is not in dispute.

The context deserves more attention than it is getting. Coldcard was GPL-licensed until a competitor, Foundation, built a device on that code. Novak said publicly that he regretted the license. Coinkite moved to MIT plus Commons Clause, blocking competing derivatives, and stripped out the crypto libraries inherited from Trezor. Foundation has published a timeline showing the entropy bug entered in the same 120-file commit that removed those GPL dependencies. Foundation is a competitor with an obvious interest in that framing, but the commits are public and the dates line up.

The licensing choice has a second cost that nobody priced at the time. Source-available is not open source. Under the Commons Clause, other developers could read the code but could not legally build on it, which quietly thins out the population of people with any reason to read it closely. Five years is a long time for a seed generation routine to go unexamined in a Bitcoin product, and the license is part of why.

Then there is the response. Coinkite's first advisory on July 30 told Mk4, Q and Mk5 owners they were not affected. That was wrong, and the advisory had to be expanded the next day. In the interval, an attack was actively running and people with newer devices were reading an official statement telling them to stand down. One prominent developer publicly told Novak he had spread misinformation and said someone he knew personally had been robbed from a Mk4 seed within hours of that advisory. Samson Mow ended up telling people to migrate off every Coldcard model regardless of version, because the vendor's own guidance could no longer be relied on.

One more detail worth noting, because the week's commentary got it backwards. Coinkite's minimal data retention was treated as the reason it could not warn its own customers. In fact the company has now said it emailed every address it could reach through its store and newsletter systems, and its own store notice explains that Canadian law requires eight years of business records, so names and addresses were blanked while the email field was kept. Reaching customers during an active theft is the right call. It also means the privacy posture that was part of the pitch was never quite what buyers understood it to be.

Novak's other public framing was that the bug was likely found using AI, calling it a sober reality of the new paradigm. Read plainly, that is a company whose code lost roughly $88 million pointing at the tool that found the flaw rather than at the five years in which it did not find it itself. We covered that response in detail in our breakdown of Coinkite's statement.

The deeper issue is that the security model was never built for a normal person. Entropy bits, firmware version tracking, BIP-39 passphrases, multisig quorums, dice rolls to seed your own randomness. That is a specialist's checklist wearing consumer packaging, and most people bought the packaging.


It Is Not Over, and That Is the Point

The first wave was a clean $70 million sweep in 41 minutes. By August 2, Galaxy Research was tracking three waves totalling 1,367 BTC, roughly $88.6 million, across 4,585 addresses. The number has moved every day since the story broke, and it will likely move again after this is published.

Watch the direction of travel. The first wave went after the largest balances, pulling $30 million in ten minutes. The third is emptying wallets worth a few thousand dollars each. That progression only makes sense if the operator holds a long list of compromised seeds and is working down it by value, monetising the tail after the whales are gone.

The third wave also broke the fingerprint. The first two shared a hardcoded fee and identical batching, which is how researchers linked them. The third uses more complex, harder-to-trace patterns, and Galaxy says it cannot confirm the same operator is behind all three. Either the attacker is adapting, or others have worked out the same flaw independently. Neither is reassuring.

The reason this keeps going is structural. Coinkite's emergency firmware cannot repair a seed that was already generated. Every vulnerable seed still holding funds stays vulnerable until its owner moves the coins, and Galaxy has warned that future sweeps need not resemble the ones already mapped. This is not an incident that concluded. It is an exposure that stays open until every affected person acts, and most of them do not know they are affected.


So What Does a Normal Person Actually Do

Watch what has happened on the timelines since. Within two days, people who had just seen a consensus recommendation fail were issuing new consensus recommendations. Name a replacement device, argue that the answer is firms large enough to employ cryptographers, move on. Almost none of it comes with more verification than the advice that put Coldcard on every recommended-wallet list to begin with.

That is the mechanism, and it is running again right now. The problem was never that people picked the wrong brand. It was that a brand recommendation was ever load-bearing for something this consequential.

So the honest answer is that there is no zero-risk option, and anyone selling you one is selling something. What exists is a set of trade-offs you get to choose between with open eyes.

Self-custody removes the counterparty who can freeze or lose your funds, and hands you the entire job of key security, firmware, and backups. An exchange removes the technical burden, and reintroduces the counterparty, the honeypot, and the interface you cannot see behind. Both are real risks. Neither is theoretical.

The most defensible posture is not picking a winner. It is refusing to concentrate. Do not put everything on one device, one vendor's firmware, one exchange, or one signing method. Spreading holdings across independent failure modes will not stop a loss. It stops a single loss from being total.

For anyone rebuilding after this, the concrete version is keys split across manufacturers, a Trezor hardware wallet beside a different vendor in a multisig quorum. Not because that vendor is trustworthy. Because no single vendor has to be.


Why This Does Not End With Everyone in Custodians

Follow the argument to its usual conclusion and you get: most people cannot do this safely, so most people should hand their coins to someone who can. A lot of this week's commentary lands exactly there, and the ETF and treasury-company flows suggest the market already agrees.

The objection is concentration. Enough Bitcoin in a few custodians rebuilds the seizure risk the thing was built to route around. What stops that from being terminal is a property gold never had. You can leave. Any holder can open a wallet, demand settlement, and have final possession in minutes, globally, for a few dollars. Most gold was never in its owner's hands, and you could not demand it be moved from London to Singapore this afternoon.

So custody concentrates only as long as the custodians stay worth using. The exit is what keeps them honest, and the exit only exists because self-custody remains possible for anyone who wants it. That is the case for keeping these skills alive even in a week that made them look dangerous.


The Part Nobody Wants Printed

Here is the sentence the industry avoids. In its current form, self-custody asks for a level of technical fluency that most people holding Bitcoin do not have and should not be expected to acquire overnight.

Read the failures, spread the risk, and distrust anyone who tells you one product ends the problem. That is not a satisfying conclusion. It is the accurate one, and the accurate one is the only kind worth publishing.


TRM LabsH1 2026 Crypto Hacks Reach Record High as Losses Fall Below $1 Billion

Crypto BriefingCrypto Records Most Hacked Half-Year Ever With 212 Exploits and $1.1 Billion Stolen

CoinDeskHow Bitcoin Cold Wallets Lost $70 Million in an Attack That Never Touched the Devices

CoinDeskBitcoin Cold-Wallet Attack Spreads to 4,500 Addresses as Losses Near $89 Million

The BlockCoinkite Issues Warning for Coldcard Mk3 Users Amid 594 BTC Theft Reports

ForbesUrgent Warning Issued After Sudden Spread Of Massive Bitcoin Attack

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Weekly Brief: July Closed Green. August Has a Record to Defend

By BitBrainers Editorial Bitcoin closed July at roughly $63,000, up about 7% for the month. That makes three consecutive green Julys, a...