Satoshi candidate Peter Todd says no Bitcoin is safe on singlesig after $38 million Coldcard drain
An automated attack drained exactly 594.48 BTC, worth about $38.3 million, from more than 500 Coldcard hardware wallets. Investigators traced the exploit to a firmware flaw dating back to March 2021. This was the nightmare those buyers paid to avoid. It happened anyway.

All the stolen funds ended up in one wallet. Block Security says the flaw affected nearly every Coldcard model: the Mk2, Mk3, Mk4, Q, and Mk5. The devices generated seed phrases incorrectly, but not in one uniform way. Older models disabled their hardware generator and fell back on predictable software. Newer models discarded data they needed. In each case, the pool of possible seed phrases became small enough for hackers to locate the correct ones within minutes.
Peter Todd, the Bitcoin developer named as a possible Satoshi Nakamoto in an HBO documentary, was not surprised. He has distrusted commercial crypto devices for years because few outsiders inspect their code or test the finished products. Most hardware-wallet advice treats the physical device as the reassuring part. That is only half right. As I read Todd’s argument, the opaque code inside the reassuring little box is precisely the problem.
The breach could push users toward open source wallets whose code is public and independently audited. Or it could send their Bitcoin straight back to centralized exchanges, replacing device risk with custody and counterparty risk. Fear has changed custody habits before: when Mt. Gox collapsed in 2014, Bitcoin’s price fell for a while, then recovered as the market changed and new services appeared. Is retreating to an exchange safer? In one narrow sense, perhaps; overall, it is simply a different bet.
Todd put his objection bluntly: “I’ve always been skeptical of hardware wallets. You pay a lot of money for a device running code that few people will ever look at, on hardware that could be backdoored with a supply chain attack.”
He wants developers to run deterministic tests on physical devices so users can verify where the randomness comes from. Todd has also demonstrated how to create a seed with a deck of cards. He once proposed a button-operated random number generator, too. Both ideas sound old-fashioned. I’ll be honest: after an alleged software failure cost users $38.3 million, shuffling cards no longer sounds especially eccentric.
The timing is rough for advocates of self-custody. Regulators are already examining crypto exchanges and custodians, and this exploit gives them a specific reason to ask how wallet makers test their products. The SEC has repeatedly raised concerns about investor protection. One theft involving 594.48 BTC and more than 500 wallets could pull hardware wallet audits into future debates over crypto rules. That part feels inevitable.
Block Security’s findings also puncture the belief that multisig always keeps funds safe. Counter to the usual advice, adding signatures does not repair weak key generation. If every key in a multisignature wallet came from an affected Coldcard, an attacker can crack the weak keys one at a time. Moving the same seed words onto another device changes nothing because the flaw entered at seed creation. That is the nasty part.
Institutions and wealthy holders often use multisig to reduce custody risk, so the exposure here deserves a technical review, not a quick device swap. Companies with Bitcoin treasuries may need to examine how each key was made, alongside where it is kept and who can access it. MicroStrategy, one of the largest corporate BTC holders, relies on strict custody procedures. My take: any corporate treasury team confronting a flaw like this should recheck both its hardware inventory and its seed generation process.
Users who added a separate BIP-39 passphrase during setup are reportedly protected because that passphrase adds another barrier to brute-force attacks. Everyone else should generate a fresh seed on unrelated hardware, then transfer the Bitcoin to new addresses. Why does new hardware alone not solve it? Because importing the old words preserves the weak seed. Skip that shortcut.
It’s reasonable to add a hardware wallet in a multisig configuration. But with singlesig, it is probably better to stick with well-audited software on commodity hardware.
— Peter Todd (@peterktodd) July 31, 2026
What this means
The Coldcard exploit blows a hole in a familiar sales pitch: buy a hardware wallet, take custody of your Bitcoin, and sleep better. A device can look secure while quietly producing weak secrets. More than 500 emptied wallets make that risk painfully concrete. Most users cannot realistically detect such a failure themselves.
BTC holders now need sharper questions. How does the wallet create seed phrases? Who tested that process, on which firmware version and physical device? Independent audits help, but the usual advice to “look for an audit” is incomplete. Researchers must also be able to reproduce the tests. I keep coming back to this: a security badge on the box proves very little by itself.
Trust in hardware wallets may take a short-term hit, and some holders could move BTC to established centralized exchanges while replacing their devices or rebuilding their setups. That move does not eliminate risk; it exchanges a potentially weak personal wallet for dependence on an exchange. Yes, that complicates the standard self-custody message. It should. There is no clean answer, because convenience and control pull in opposite directions.
Watch how other wallet manufacturers respond. Do they publish their audit methods and test results? Do they describe exactly how their devices generate seeds? After a $38.3 million breach traced to firmware dating back to March 2021, “industry-leading security” sounds hollow without evidence. Independent certification might help, provided it tests finished devices instead of merely reviewing paperwork. The distinction matters.
Traders may also watch Bitcoin around the $60,000 support level. A lasting move below that price could indicate that the breach has added to broader market nerves, although one wallet exploit may not explain the decline. Comments from the SEC or CFTC deserve attention as well; either agency could cite the incident when arguing for security standards or mandatory audits. Is that an overreaction to one exploit? Perhaps—but 594.48 BTC landing in one wallet gives regulators a vivid example. The next few weeks may show whether users treat this as Coldcard’s failure or as a broader warning about hardware wallets.
FAQ: Understanding the Coldcard vulnerability and its effects
What is the Coldcard vulnerability?
The flaw affected how certain Coldcard wallets generated seed phrases. Those phrases became predictable enough for attackers to discover through brute force. Simple, and devastating.
Which Coldcard models are affected?
Block Security identified the Mk2, Mk3, Mk4, Q, and Mk5. According to its report, the vulnerable firmware dates to March 2021.
How much Bitcoin was stolen in the Coldcard drain?
The attackers took 594.48 BTC from more than 500 wallets. At the reported valuation, the stolen Bitcoin was worth roughly $38.3 million.
What does Peter Todd think about hardware wallets after this incident?
Todd says the breach supports his longstanding distrust of commercial crypto devices. His objection centers on how rarely independent researchers inspect both the code and the physical hardware. I think that distinction is crucial.
Are multisig setups safe from this vulnerability?
Not when every key was generated by a vulnerable Coldcard. Because the defect weakened each seed at creation, an attacker may be able to crack the keys separately. Multisig is not magic.
Who is protected from this Coldcard vulnerability?
Users who added a separate BIP-39 passphrase during the original setup are reportedly protected. The extra passphrase makes a brute-force attack much harder.
What should Coldcard users do immediately?
They should create a new seed using unrelated hardware, then send their funds to addresses derived from that seed. Importing the old words into a different wallet does not repair the weakness. Start fresh.
What does this incident mean for hardware wallet security?
A hardware wallet is only as safe as its seed generator and firmware. Testing matters just as much. Users now have a concrete reason—more than 500 drained wallets—to demand independent audits of finished devices, not reviews confined to selected bits of code.
Could this incident increase demand for centralized exchanges?
It might, at least temporarily. Some users may leave more BTC on established exchanges while replacing their wallets, despite the custody and counterparty risks involved. That is not a cure; it is a tradeoff.
What regulatory impact could this incident have?
The SEC or CFTC may refer to the breach in future discussions about hardware wallet rules. The incident could also intensify pressure on manufacturers to follow consistent audit procedures. Clear, published security standards may become harder to avoid.
