David Schwartz weighs in on $100M Coldcard hack
David Schwartz said the Coldcard breach shows that rare custody failures can produce devastating losses, comparing the incident with past breakdowns in traditional finance.
- Coldcard-related thefts have exceeded $100 million, according to Galaxy Research.
- Schwartz compared the custody risk with MF Global’s 2011 collapse but pointed to differences in insurance protection.
- A firmware flaw allowed attackers to reconstruct vulnerable wallet seeds without accessing the physical devices.
- Coinkite said affected users must create new seeds and move their funds because firmware updates cannot repair old seeds.
Schwartz compares Coldcard breach with TradFi failures
Ripple CTO Emeritus David Schwartz framed the Coldcard attack as an example of outlier risk—the possibility that a rare technical failure can cause losses far beyond what users expect.
Schwartz compared the incident with the 2011 collapse of MF Global, where customers temporarily lost access to funds after the brokerage misused money that should have remained segregated. His comments challenged the assumption that self-custody removes every form of counterparty or operational risk.
Hardware wallets allow users to control their private keys without relying on an exchange or other financial intermediary. However, owners must still trust that the device’s hardware and firmware generate and protect those keys correctly.
Schwartz also pointed to a major difference between traditional finance and crypto self-custody. Customers of regulated financial institutions may have access to insurance, bankruptcy proceedings, or other recovery mechanisms. Coldcard owners whose Bitcoin was stolen through compromised seeds currently have no comparable safety net.
What is the Coldcard hack?
Coldcard is a Bitcoin-only hardware wallet made by Canadian manufacturer Coinkite. The device stores private keys offline and can sign transactions without directly connecting to the internet.
The current breach did not involve attackers remotely accessing Coldcard devices. Instead, it resulted from a seed-generation flaw introduced through firmware released in March 2021.
According to Coinkite’s technical review, affected firmware used a software-based pseudorandom number generator rather than obtaining sufficient randomness from the device’s hardware generator. The problem affected seeds created on certain Coldcard firmware versions, including Mk2 and Mk3 releases from version 4.0.1 through 4.1.9.
Seed phrases should contain enough randomness to make guessing them computationally unrealistic. The Coldcard flaw reduced that protection, allowing attackers to generate possible seeds offline and compare their derived Bitcoin addresses with publicly visible addresses on the blockchain.
Once attackers found a match, they could recreate the wallet’s private keys and transfer its Bitcoin. They did not need to steal the hardware wallet, know its PIN, or compromise the Bitcoin network.
Coldcard losses exceed $100 million
As reported by crypto.news earlier, Galaxy Research said it had identified 1,596 BTC stolen from about 7,300 addresses across three confirmed attack waves. The firm also linked roughly 14 smaller incidents to the same seed-generation flaw.
A suspected fourth wave could raise the total to about 2,055 BTC, worth close to $130 million. However, Galaxy has not yet confirmed those additional losses.
The first major sweep occurred around July 30, when more than 1,000 BTC was removed from over 1,200 addresses in less than an hour. Two additional waves later targeted other wallets created using vulnerable seeds.
Galaxy shared hundreds of suspected attacker addresses with U.S. federal investigators, exchanges and blockchain security companies. About 90% of the Bitcoin stolen during the confirmed waves had not moved again at the time of its latest update.
The Bitcoin protocol was not compromised. The theft resulted from weak wallet-seed generation, meaning Bitcoin held in wallets created through unaffected software or hardware was not exposed by this specific flaw.
Coldcard owners must replace vulnerable seeds
Coinkite has released corrected firmware for affected Coldcard models. However, installing an update does not make an existing vulnerable seed secure.
The company’s security advisory instructs Mk2 and Mk3 owners who created seeds using firmware versions 4.0.1 through 4.1.9 to update to version 4.2.0 or later, generate a completely new seed and transfer their Bitcoin.
Users should first send a small test transaction and verify the receiving wallet before moving the remaining balance. Coinkite said its corrected seed-generation process is sufficient, while adding at least 50 private dice rolls remains an optional method for users seeking independent entropy.
The breach shows that air-gapped hardware can reduce online attack exposure without eliminating firmware, manufacturing, or seed-generation risks. For affected owners, moving funds to a newly generated wallet remains the only way to remove the immediate threat.