This week, the Bitcoin community experienced one of its most serious security events.
A firmware flaw in Coldcard hardware wallets, present since March 2021, caused affected devices to generate seed phrases using predictable randomness rather than true hardware randomness. Attackers were able to reconstruct private keys and drain wallets remotely. No phishing. No malware. Just a flaw in how the seed was originally created.
The losses so far stand at approximately 1,431 BTC, around $89 million, across nearly 5,400 compromised addresses. The situation is still unfolding.
We are devastated for everyone who has been affected. These are people who did everything right. They used hardware wallets. They kept funds in cold storage. They followed the advice. And the device they trusted failed them quietly, for years, without any visible sign.
If you use a Coldcard, please act now. Move your coins off a ColdCard if you have one. Updating your firmware is not enough. If your seed was generated on an affected device during the vulnerable period, you must generate a completely new seed on a patched device and move your funds immediately.
Self-custody is one of Bitcoin's most powerful innovations. The ability to be your own bank, hold your own keys and answer to nobody is genuinely revolutionary.
But it is not for everyone. And that is okay.
What matters is finding a custody setup that works for you. Whether that is a patched hardware wallet, multisig, collaborative custody, an insured solution, a Bitcoin bank or something else entirely. Secure options exist at every level of technical comfort. There is no one-size-fits-all.
This is a moment for the community to come together. To help each other understand the options, ask the right questions and find what is right for each individual situation.
The team at The Bitcoin Collective is here for anyone who has been affected, has questions or simply needs someone to talk to. Please reach out.