A firmware bug hiding in Coldcard hardware wallets since March 2021 finally bit. Starting July 30, attackers exploited a randomness flaw in the popular cold storage device to drain approximately 2,100 BTC, worth between $116M and $130M, from over 5,200 addresses.
What happened next, according to Casa CEO Nick Neuman, matters far more than the theft itself. Roughly 233,000 BTC moved from long-term holder wallets in the days that followed, as users scrambled to rotate funds into safer setups. For every Bitcoin stolen, more than 100 were proactively secured.
The exploit and the exodus
The vulnerability traced back to a flaw in how Coldcard’s firmware generated randomness for private keys. Devices running affected firmware versions produced keys with insufficient entropy, making them guessable given enough computing power and time. The bug had been sitting in production code since March 2021, meaning wallets generated over a five-year window were potentially at risk.
Coinkite, the company behind Coldcard, issued an emergency firmware patch on July 31, one day after the exploit began. The company advised users to immediately update and migrate their funds using freshly generated keys.
But Coinkite also suggested that users who wanted extra assurance could use dice rolls to introduce additional randomness into key generation. Neuman was not impressed by that recommendation. He called dice-roll entropy “impractical for the majority of users,” arguing that telling people to physically roll dice and manually input results is the kind of advice that sounds robust in a forum post but collapses under real-world conditions.
Small transfers spike to FTX-collapse levels
On-chain data painted a vivid picture of the community’s response. Small Bitcoin transfers, those under 1 BTC, surged to approximately 39,600 BTC on July 31 and August 1. That volume hadn’t been seen since the FTX collapse in November 2022, when users across the ecosystem rushed to pull funds off exchanges.
The case for distributed custody
Neuman framed the episode as validation for distributed self-custody models, particularly multisig wallets that require multiple keys stored on different devices in different locations to authorize a transaction. Under a multisig setup, a single compromised device doesn’t give an attacker access to funds. They’d need to breach multiple independent security layers simultaneously.
Neuman argued that self-custody is Bitcoin’s “immune system,” not its vulnerability, pointing to the 233,000 BTC that moved to safety as proof the system worked as designed.
His framing is deliberate. Casa sells multisig custody services, so he has a commercial interest in the narrative. But the on-chain evidence does support his core claim: the Bitcoin network itself was never compromised. No consensus rules were broken. No blocks were reorganized. A third-party device had a bug, and the network’s users adapted in real time.
What this means for custody going forward
Companies offering multisig and distributed custody solutions, including Casa, Unchained, and others, stand to benefit from the renewed anxiety around single-point-of-failure setups. Hardware wallet manufacturers, meanwhile, face uncomfortable questions about firmware audit practices and how long critical bugs can go undetected.
For the market, the short-term disruption appears contained. The stolen amount, while significant at $116M to $130M, represents a fraction of Bitcoin’s total market capitalization. And the rapid migration of 233,000 BTC suggests that holders are engaged and responsive, not complacent.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 day ago
16









English (US) ·