Is Any Cold Wallet Safe? Inside the Coldcard Hack's Wave Three artwork

Is Any Cold Wallet Safe? Inside the Coldcard Hack's Wave Three

Unchained

August 4, 2026

📢 Bits + Bips has its own channel now — full episodes here: https://www.youtube.
Speakers: Laura Shin, Austin Campbell, Alex Thorn, Chris Perkins
**Laura Shin** (0:00)
You're listening to a brief segment from one of the Bits and Bips episodes this week. The full show is now only available on its own dedicated Bits and Bips channels. So be sure to go to X, YouTube, and your favorite podcast platform and search for Bits plus sign Bips, spelled B-I-P-S, and subscribe.

**Austin Campbell** (0:21)
So, Coldcard was a hardware wallet largely marketed in some places as the gold standard in the Bitcoin ecosystem, and it had a deep systemic flaw. So an exploit tied to entropy, aka key generation, Coldcard Mark III, Mark IV, Mark V had Bitcoin drained from, I believe, well over a thousand wallets at this point, and the reported total has been climbing throughout the week up, up, up, up. CZ Vi of Zero Hedge said nothing is 100% warning Bitcoin holders after the exploit. We also have an expert who's been commenting on it extensively here, Alex Thorn, who, Alex, I saw on Cointelegraph, you said a fourth organized wave is likely in progress. 208 transactions across some specific blocks sweeping about 389 Bitcoin from 462 suspected victim addresses. In roughly 2.5 hours.
Human cost is real here. Good example, the Retail Bull had said, I've had all my Bitcoin stolen while away on holiday. It was on a Coldcard Mark III. I was led to believe this was really secure. The two Bitcoin was supposed to be to give to my two children to give them a good start to life. And the ETF crowd has been speaking up here.
Eric Balanchunas said, such an intermediary upgrade for Bitcoin, safer, more secure and almost always cheaper. Speaking about ETFs, 33 year old industry, 15 trillion in AUM and never once lost someone's money. So I could go on and on about this, but Alex, you've been observing the whole thing. Could you start by telling us like the core of how did people get this wrong? Why was all this money sitting out there in a way that it could be stolen?

**Alex Thorn** (2:20)
Yeah, it's been a brutal four days. This sort of started early in the morning Thursday UTC time and is still on goings before I even go. If any viewer or listener has funds on a cold card and a single signature address, as in not part of a multi-sig quorum, you should move those coins off as soon as possible.
By the way, I like Eric Valchunas quite a lot, but obviously in ETF holding, a DTC registered stock inside it is not the same thing as one that holds a digital bearer asset. But we move on. The saddest part is that to your direct question, Austin, these people did nothing wrong. In fact, they did everything right and the cold card itself is very popular among a cultural demographic in Bitcoin. That believes in cold storage, self-custody, stacking sats, working hard. Not that anyone deserves to have their money stolen, but this isn't a drain of a DeFi bridge where you were bridging between Ethereum L2s to harvest altcoin inflation yield. This is not people speculating on crypto exchanges, on meme coins. These are people by and large, I can tell you, I know this community quite well, that are working hard and saving and stacking sats, and then putting them away for a long period of time. The average dormancy of coins that has been siphoned like almost four years. So these are not short-term holders. That makes it particularly devastating because they did nothing wrong. To your point, just to underline it a little bit of how this happened, when you generate cryptographic keys, you need entropy. You need a random number generator to seed the key generation with randomness, which is what makes it difficult to brute force attack.
And Coldcard had updated their firmware on March 17th, 2021 to add their own version of a random number generator. And it's not even that that version wasn't good. They miswired it into the firmware in such that it would fail. It would never be routed through that random number generator. And it would fail silently. And it would back fall to this other crappy random number generator that has way too weak entropy to create secure keys. That means that attackers with compute that know this vulnerability can go and use that random number generator that it did end up using and compute billions of public keys, then go and private key seeds, seed phrases, and then derive the public keys across the whole derivation space, and then go and see if any of them have coins. And if they do, bam, submit transactions to move those coins to new locations. It's the worst type of attack. These people did not accidentally drop their hardware wallet on the ground or post their private key in a chat. They didn't even click a link, a phishing link that siphoned their MetaMask, right? Like so many that we see.

11 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID