Coldcard Bitcoin Wallet At Risk: Why Your Multisig Was Built for This
The Bitcoin world woke up to serious news today. Roughly 594 BTC, about $38 million, was swept out of around 500 wallets in a matter of minutes. The addresses had nothing in common except one thing: the private keys behind them were generated on a Coldcard hardware wallet running affected firmware.
If you are a SimplB client with your Bitcoin in a vault, the short answer is that your vault held and your coins are safe. The rest of this piece explains why.
What follows is what actually happened, who is at risk and why the custody structure I build at SimplB was designed for exactly this kind of day.
What went wrong
Every Bitcoin wallet starts with a seed, a string of randomness that everything else is derived from. The entire security of your coins rests on that randomness being unpredictable. The industry standard is 128 bits of entropy. That is a number so large that guessing it is impossible with any technology on the horizon.
The bug: certain Coldcard firmware stopped using the device's hardware random number generator and fell back to a weaker software one. The device gave no warning. Nothing on the screen looked any different. Instead of 128 bits, seeds were created with far less: around 40 bits on the older Mk3 and around 72 bits on the newer Mk4, Mk5 and Q models.
Forty bits sounds abstract, so make it concrete. It shrinks the number of possible seeds to roughly a trillion, which is well within reach of a determined attacker with ordinary computing hardware. You generate every seed in that range, derive the addresses each one would produce and check them against the public blockchain. Any address holding coins, you sweep. That is precisely what happened.
This was a remote attack
One dangerous misconception is doing the rounds and it needs correcting before anything else. This attack did not require anyone to touch a device. Nobody broke into a home or a safe or a vault. The weakness lives in the keys themselves and those keys sit on the public blockchain for anyone to test against. An attacker did the whole thing from a laptop.
That changes what actually protects you. Storing a hardware wallet in a secure facility defends against physical theft and tampering, which is a real and separate risk. It does nothing against a weak seed being guessed remotely. If your coins are reachable by this flaw, where the device is kept is irrelevant.
Why almost every drained wallet was single-signature
Look closely at the wallets that were emptied and a pattern jumps out: they were overwhelmingly single-signature. One device, one key, one point of failure. If that single key is weak, nothing stands between an attacker and the coins.
This is the whole reason I have argued for years, to anyone who will listen, that single-signature is not good enough for serious long-term custody. A single key is a single thing that can fail: through a firmware bug like this one, through loss, through theft, through a mistake. You do not want the safety of a life's savings resting on one component being flawless.
Why multisig held
My clients' coins are held in a 2-of-3 multisig setup with the three keys spread across three different hardware manufacturers. To move funds you need two of those three keys to sign. One key on its own can do nothing.
Now apply that to today's event. Suppose an attacker could reproduce one weak key in that setup. They would hold one signature of the two required.
The coins do not move.
The sweep hit single-sig holders and largely left multisig alone for exactly this reason.
Spreading the keys across different manufacturers is the second half of the design and today is the day it earned its keep. A flaw in one manufacturer's device weakens at most one of your three keys. The other two, built by other companies on other hardware, are untouched. The same catastrophic failure would need to strike two independent manufacturers at once, a far less likely event. Back those keys up on steel in separate locations and you have custody that resists fire, flood and rust as well as hackers.
I have said the same thing for years: three hardware wallets from three different manufacturers, precisely in case one of them turns out to have a backdoor or its entropy fails. It was never a comfortable point to raise. It always sounded a little paranoid. Today it stopped being hypothetical. And I will admit: of all the devices I thought might one day be the weak link, Coldcard was near the bottom of my list. That is exactly the point. You do not build this structure because you know which device will fail. You build it because you don't and you refuse to bet everything on being right.
Where this leaves my clients
I will be straight with you. The Coldcard is one of the three devices I use, so it is one leg of the multisig for clients who hold that combination. The model in my clients' vaults is the Q, not the older Mk3 at the centre of today's drain. That difference is worth understanding properly.
The wallets that were drained were Mk3 wallets with around 40 bits of entropy. Forty bits gives roughly a trillion possible seeds, a range an attacker can search with ordinary hardware in a reasonable time. The Q generated seeds with around 72 bits. Every additional bit doubles the search, so 72 bits is over four billion times harder to crack than 40. That range sits far beyond what any attacker can practically search today. Still short of the 128-bit standard your keys deserve and still nowhere near the open door the Mk3 turned out to be.
Add the structure on top of that. Even if an attacker could somehow reproduce a Q key, it is only ever one key of the required two. A single weakened key in a 2-of-3 cannot move a single satoshi. Put the maths and the multisig together and the practical risk to client vaults right now is very minimal. In practice it sits close to zero.
Close to zero is still not how I leave things. At your annual review or whenever I build you a new vault, I will move your Bitcoin into a vault where the Coldcard Q key has been replaced with one generated on the upgraded, fixed firmware. I will keep watching this as more detail comes out and I will tell you if anything changes the assessment above. There is no need for panic and no need to rush. The multisig is doing its job while I work through the reviews, carefully.
If you hold Bitcoin yourself
If your Bitcoin sits in self-custody on a single-signature Coldcard Mk1, Mk2 or Mk3, move your coins urgently, unless they have already been taken. Treat that seed as burned. Generate a fresh seed on a safe device and sweep everything to it today, not this weekend. If you are on a Coldcard Q, upgrade to the fixed firmware immediately and follow Coinkite's current guidance, which at the time of writing means generating a new seed on the fixed firmware and moving your coins across as a precaution. Mk4 and Mk5 holders should do the same. And if today has made you realise how much is riding on a single device, this is the moment to look at multisig.
If you have an older Coldcard and you are not sure what to do, do not guess with your savings. Book a call and ask. I would far rather answer a nervous question than watch someone lose coins they could have kept.
// this article is general information, not financial or security advice specific to your situation. for the technical specifics of the coldcard issue, refer to coinkite's official advisory. if you are unsure about your own setup, get help before you act.
Want to secure your Bitcoin properly?
SimplB builds 2-of-3 multisig vaults with keys spread across three hardware manufacturers, as a Juristic Representative of CAEP Asset Managers (FSP 33933).
Book a custody call