Coldcard2026-08-31 00:12:42Coldcard entropy flaw shakes self-custody confidence, but experts still favor holding your own keysA flaw tied to entropy handling in Coldcard hardware wallets has triggered Bitcoin losses and reignited a core debate in crypto: whether users are still better off keeping assets in self-custody after a wallet failure of this scale. According to the report, the issue stemmed from a deep firmware bug that remained hidden for five years and affected private-key generation on Coldcard Mk3 devices. During a code migration from Python to C, developers unintentionally disabled the built-in secure random number generator, causing the device to fall back to a highly insecure algorithm and reducing cryptographic entropy from 256 bits to just 22 bits. Speakers at Bitcoin Asia said the incident exposed weak spots in vendor maintenance, including code review, bug bounty design, and broader management practices. Even so, they argued that centralized exchanges still carry greater counterparty risk than hardware defects. The discussion centered on multi-vendor multisig setups using devices from different manufacturers, along with passphrase protections and modern coordination tools such as Liana, Unchained, and Casa. The report also said development teams are increasingly turning to AI-assisted code auditing to scan large legacy codebases and catch logic errors earlier. In that view, the Coldcard incident has damaged trust, but it has also pushed the ecosystem toward stricter security practices rather than away from self-custody.860
Blockstream2026-08-31 00:17:49Blockstream Says Jade Not Affected by Coldcard RNG Flaw, Releases Firmware 1.41Blockstream announced that its Jade hardware wallet is not affected by the Coldcard random number generator vulnerability. Following extensive AI-assisted security reviews, the company released firmware 1.41 with enhanced stack protection, updated dependencies, and a revamped runtime environment.830
Bitcoin2026-08-29 04:48:09Six Dormant Bitcoin Wallets Move 553.59 BTC Worth About $40MSix long-dormant bitcoin wallets, last active between 2011 and 2014, transferred 553.59 BTC between Aug. 16 and Aug. 26, worth about $40 million, according to a CoinDesk report cited by ChainCatcher. Five of the wallets sent coins to addresses not linked to any known exchange; the sixth sent 40 BTC to Germany's Boerse Stuttgart Digital. Two of the wallets are connected to a New York lawsuit in which pseudonymous plaintiff Noah Doe is seeking control of bitcoin in 39,069 dormant addresses under the state's abandoned-property law. Galaxy Research data show dormant bitcoin on-chain moves hit their lowest second-quarter level since 2022, and full-year 2026 transfers are expected to be less than half of last year's. Galaxy head of research Alex Thorn said no whale clients cite quantum-computing risk as a sell reason, although some institutions avoid buying bitcoin for that reason. Separately, roughly 210,000 BTC left long-term holder wallets in the week after the Coldcard hardware wallet vulnerability disclosure.940
Coldcard2026-08-28 21:58:49Coldcard Hacker Still Active, Stolen Key Built With Dice EntropyChainCatcher reports that, according to Galaxy's head of research, the Coldcard hacker remains active. A hacker stole a key that had extra entropy added from five dice throws.860
Bitcoin2026-08-26 23:39:32Coldcard entropy flaw pushes multi-vendor multisig to the forefront of Bitcoin custodyBitcoin Magazine argues that the fallout from Coinkite’s Coldcard entropy bug has forced a broad rethink of Bitcoin self-custody practices, especially for users relying on single-signature setups. The article says the flaw, which reportedly went unnoticed since at least 2021, exposed how much trust single-seed users place in one hardware wallet maker’s key generation process. In response, self-custody advocates and industry participants are increasingly treating multi-vendor multisignature setups as a stronger default, because they spread signing authority across devices and manufacturers rather than concentrating it in one place. The report walks through the threat-modeling framework behind that shift. It highlights backup failures, forgotten passwords and theft as recurring causes of fund loss, then places bad entropy attacks alongside incidents involving Trust Wallet and fake wallet apps. It also explains how 2-of-3 and 3-of-5 multisig arrangements work, why providers such as Casa, Nunchuck, Sparrow and Unchained Capital are part of the discussion, and how advanced multisig designs can add resistance to coercion, phishing and social engineering. At the same time, the article notes a key tradeoff: users must preserve not only threshold signing access, but also a copy of the multisig script or template needed to reconstruct spending conditions independently.930
Coldcard2026-08-26 23:44:03Coldcard entropy flaw tied to over $100 million in stolen Bitcoin as multisig gains attentionColdcard, the hardware wallet brand owned by Coinkite, has been linked to a serious entropy flaw that reportedly went undetected since 2021 and led to more than $100 million worth of Bitcoin being stolen. According to the report, most victims were users relying on single-seed-phrase wallets, where weak entropy made it possible for attackers to guess private keys through customized methods. The incident has pushed the Bitcoin community to revisit the reliability of single-signature self-custody setups. In that context, multi-vendor multisignature arrangements are being presented as a new baseline for long-term holders. The model uses keys from different wallet makers to reduce dependence on any one hardware provider, with one example combining Trezor Safe 7, Ledger Nano and a Casa recovery key in a 2-of-3 setup. The report also notes that multisig can help defend against wrench attacks and has supported services such as BTC-denominated Bitcoin insurance from firms including AnchorWatch. At the same time, it adds operational overhead because users must keep threshold keys safe and also retain a copy of the multisig script or template for independent recovery if wallet services go offline.930
Bitcoin2026-08-26 20:01:23BTC Sessions says tens of millions in Bitcoin were moved to safety after Coldcard flawBTC Sessions said his team spent weeks helping Bitcoin holders affected by the Coldcard vulnerability move funds to safer storage, with an estimated tens of millions of dollars in BTC protected during the process. The update was shared by Bitcoin News on X. He said the response still came too late for some users. One member of his local Bitcoin community reportedly lost 90% of their Bitcoin, while a woman he spoke with lost all of hers. BTC Sessions described the incident as possibly the most serious self-custody event in Bitcoin’s history. He added that the episode forced him to rethink how assets should be held, saying the main lesson was the need to diversify security measures rather than rely on a single setup.870
Bitcoin2026-08-26 20:01:51BTC Sessions says Coldcard flaw may rank as Bitcoin’s worst self-custody incidentBitcoin News said in a post on X that BTC Sessions described a weeks-long effort by his team to help Bitcoin holders affected by the Coldcard vulnerability move funds to safety. He estimated that the work protected tens of millions of dollars worth of BTC during that period. Even so, he said the response came too late for many users. According to his account, one member of his local Bitcoin community lost 90% of their Bitcoin, while another woman he spoke with lost all of hers. BTC Sessions said the episode could be the most severe self-custody incident in Bitcoin’s history. He added that the experience pushed him to rethink asset custody, with diversified security measures standing out as the main lesson.880