Coldcard users are sharing accounts of drained wallets across X and Reddit after a firmware flaw made seeds generated by the hardware wallet guessable. TheDefiant reported that attackers have swept about 1,816 BTC, valued in the article at roughly $114 million, from more than 5,200 addresses in four coordinated waves.
Canadian entrepreneur Jonathan Goodman said he kept 18.25 BTC on a Coldcard that had never touched the internet and was locked in a safety deposit box. Between 9:36 p.m. and 9:43 p.m. on July 29, every wallet he had was emptied. He put the loss at about 1.6 million Canadian dollars, gone in seven minutes.
In a post on X that drew 7.6 million views, Goodman wrote: “Perhaps the hardest part about this is that I did everything right. I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes. None of it mattered.”
His story is one of dozens that have appeared on X and the Bitcoin subreddit since the Coldcard exploit surfaced on July 30. The common thread in those posts is that users say they followed the usual self-custody playbook: they bought a hardware wallet from a respected manufacturer, generated seeds offline, stamped backups into steel, and never typed a seed phrase into a connected device.
Goodman said he learned about the hack days later while at his cottage and checked his balances expecting no issue. “Right away I saw lines of red transaction–withdrawals–and I knew,” he wrote. He said he is filing a police report and a report with the Ontario Securities Commission, though he does not expect to recover anything.
A race to move coins before attackers do
Because the flaw lets attackers reproduce private keys, affected holders are not only dealing with past theft. Many are in a live race to move funds before attackers reach them. Some missed that window by only a few hours.
Tim Lamb said he was on a family holiday when news of the hack broke on Friday. His Coldcard Mk3 and seed plate were hidden at home. “Not until Saturday evening did I get the idea to ask my neighbour with the house key to find the seed for me,” he wrote on X. By Sunday morning, when the neighbor found the plate and Lamb restored the wallet, the balance was already zero. The 2 BTC had been drained on Saturday afternoon.
Lamb wrote: “This 2 bitcoin was supposed to be to give to my 2 children to give them a good start in life. Makes me tear up to think of it.” He added: “@Coinkite, if there was any fairness, you would have to pay us our money back.”
A pseudonymous Bitcoiner posting as Marius Off Chain said a friend who could not access his device had his Mk2 drained on Sunday morning. The funds were then consolidated with 890 other inputs into a single address holding 64 BTC.
The scramble prompted blunt advice from Bitcoin Core developer Luke Dashjr, who wrote: “This is a tragedy. If you can't get to your Coldcard, find someone who can. Even if you don't trust them with your life savings, worst case at least you'd know who took it!”
“8 years of stacking, gone”
Posts on Reddit carried the same sense of shock. Pseudonymous investor Zynx wrote in a post viewed 3.6 million times: “The Bitcoin subreddit is absolutely heartbreaking right now. So many people have been destroyed.”
In a widely shared r/Bitcoin post titled “8 years of stacking, gone. I think it's time to move on,” a user named DuckDuckMoss said 2 BTC had been accumulated as a way to escape the inflation of a sanctioned country's currency.
“I'm 39, and I was hoping to have a good financial cushion before 50. But today, my 2 BTC were drained,” the user wrote. “I thought I was secure because Cold Card was always praised as one of the best and most secure wallets.” The post ended with a rejection of bitcoin itself: “I'm done with Bitcoin. I'm not even sure if I still believe in it. Maybe I should have just moved everything into a Bitcoin ETF when they launched.”
Another user, posting as Schtuff, said he had been saving since 2015 and had stamped his seed into a steel plate. “My life savings was taken from me today. I don't now what to do, I'm lost.”
Some users who saved funds are changing how they store bitcoin
For users who managed to save their coins, the episode is changing what they do next, often in ways that run against standard self-custody orthodoxy.
A user posting as ACEIN said a Coldcard Mk4 held retirement savings. While out of town for a conference, the user downloaded mobile hot wallet BlueWallet, imported the 12-word seed, and sent everything to Coinbase after a test transaction.
The next move, the user wrote, is still undecided: a multisig setup, Block’s Bitkey, or selling the bitcoin and moving into BlackRock’s IBIT ETF.
Calle, the pseudonymous developer of the Cashu ecash protocol, called the exploit “worse than any previous Bitcoin exchange hack.” He wrote that many affected users would not hear about the incident in time to react. “I am truly saddened for everyone affected, especially those who may have just lost their life savings. The worst part is that they did everything right.”
Coinkite patched firmware, but did not answer the compensation question
Coldcard maker Coinkite has released fixed firmware for every model, halted shipments, and destroyed remaining inventory carrying the affected firmware.
In an open letter, CEO Rodolfo Novak, known as NVK, wrote: “I'm sorry and I'm devastated. Our team is heartbroken about yesterday's news.” He urged anyone who generated a seed on a Coldcard to move funds immediately.
The letter did not address the question raised in posts such as Lamb’s: whether Coinkite will compensate users whose coins are already gone.

