Coldcard2026-08-03 15:55:47Coldcard users recount losing life savings after wallet-seed flaw surfacedColdcard users are posting detailed accounts of drained wallets after a firmware flaw made some seeds generated by the hardware wallet guessable, according to TheDefiant. The report says attackers have swept about 1,816 BTC, valued in the article at roughly $114 million, from more than 5,200 addresses in four coordinated waves. Victims say they followed standard self-custody practices: buying from a well-known manufacturer, generating seeds offline, engraving backups into steel, and never entering seed phrases on internet-connected devices. Among the cases cited, Canadian entrepreneur Jonathan Goodman said 18.25 BTC was taken from wallets linked to a Coldcard that had never touched the internet and was stored in a safety deposit box. Other users described racing to recover seed backups while away from home, only to find their balances already at zero. On Reddit and X, posts from affected holders describe losses tied to retirement savings, family wealth plans, and years of bitcoin accumulation. Coldcard maker Coinkite has released patched firmware for all models, paused shipments, and destroyed remaining inventory carrying the affected firmware. CEO Rodolfo Novak, known as NVK, said the team was devastated and urged anyone who generated a seed on a Coldcard to move funds immediately. The open letter did not say whether users whose coins were already stolen would be compensated.1950
Binance2026-08-03 00:52:00CZ shares hardware wallet failure story and warns over seed phrase securityBinance co-founder Changpeng Zhao, widely known as CZ, reposted an X thread from user Rager describing a hardware wallet failure and used the case to highlight the difficulty of protecting wallet backup seed phrases. CZ said safeguarding a seed phrase is extremely challenging because it has to stay out of sight of other people, who could copy or misuse it, while also remaining safe from physical damage caused by accidents such as fire or flooding. He added that users also need to prevent hackers from gaining access to the phrase. His final point was simple: the owner cannot lose it either. The remarks focused on the practical trade-offs involved in self-custody, where backup information must remain both accessible to the holder and protected from theft, exposure, and destruction.1720
Coldcard2026-08-03 02:09:22Coldcard destroys inventory made with vulnerable firmware, urges affected users to move fundsBitcoin hardware wallet maker Coldcard said Aug. 3 that the past three days had been among the hardest in the company’s history, with some users losing savings accumulated over many years. The company said it has been contacting customers since last Friday to help them move funds that remain safe and to provide recovery guidance. Coldcard also said it has destroyed the remaining COLDCARD inventory produced with the vulnerable firmware and has halted shipments. According to the company, Satscard, Opendime and Tapsigner are not affected. A patched firmware release is now available and can prevent newly generated seed phrases from being exposed to the issue. Still, seed phrases that were generated earlier on the vulnerable firmware remain at risk. Coldcard said affected users need to create a new wallet and transfer their funds. As temporary alternatives, the company pointed users to Bitkey, Ledger, Trezor, Jade and Bitbox, and asked affected users to keep their devices to support any later recovery efforts.2400
Changpeng Zha2026-08-03 00:57:06CZ says safeguarding recovery seed backups is difficultBinance co-founder Changpeng Zhao, better known as CZ, reposted a post from user Rager about an experience involving a hardware wallet failure and used it to comment on the challenge of securing recovery seed backups. Zhao said the task is difficult because the phrase must not be exposed to other people or remembered by them, must not be destroyed by disasters such as fire or flooding, and must not be obtained by hackers. He added that the most important thing is that the owner must not lose it. The remark was made in response to a discussion around hardware wallet failure and seed phrase storage, based on Zhao’s post on X.1730
CZ2026-08-02 23:57:36CZ says the hardest part of self-custody is keeping seed phrases safeBinance co-founder Changpeng Zhao, widely known as CZ, commented on one of the core risks in self-custody after reposting X user Rager’s account of a hardware wallet failure. In his remarks, CZ said safeguarding a wallet backup seed phrase is an extremely difficult task. He said the phrase must not be seen by others, because it could be copied or exploited, but it also cannot be destroyed in accidents such as fires or floods. He added that users must also keep hackers from gaining access to it. Just as important, he said, is that the owner must not lose the seed phrase themselves. The comments were made in response to a user experience involving hardware wallet malfunction and focused on the operational burden that comes with holding crypto assets through self-custody.1830
COLDCARD2026-08-02 16:52:47Old COLDCARD weak-seed warning draws fresh attention after RNG flaw disclosureA 2023 video warning about wallet creation on the COLDCARD Mk4 has resurfaced after the discovery of an RNG flaw tied to the device. In a post on X, Bitcoin News said hardware wallet educator @YTCryptoGuide had previously warned that the Mk4 allowed users to create a wallet after a single dice roll, a setup that could lead people to generate an extremely weak seed. He also said the interface could give users the impression that their dice input would be mixed with the device’s hardware random number generator, while that was not the case in some user flows. The clip is drawing renewed scrutiny because many advanced users choose dice-based entropy precisely because they do not fully trust hardware RNG systems. The renewed attention does not add new claims beyond the earlier warning, but it places that 2023 explanation back in focus as users revisit how entropy is handled on the device.1890
Bitcoin2026-08-02 09:39:27Fake Trezor support scam drains $282 million in Bitcoin and LitecoinA Bitcoin and Litecoin holder lost about $282 million after handing over a 12-word seed phrase to attackers posing as Trezor support on Jan. 10, according to Odaily. The stolen assets included roughly $139 million worth of Bitcoin and $153 million worth of Litecoin. Blockchain forensics firm ZeroShadow said the case was the result of a social engineering attack rather than a breach of wallet software or private key infrastructure. The firm said the funds were broken up within minutes through the THORChain cross-chain bridge and then converted into Monero using instant swap services. ZeroShadow also said its monitoring team flagged and froze about $700,000 within 20 minutes. The report added that under the BIP39 standard, a 12-word seed phrase contains about 128 bits of entropy, while a 24-word phrase contains 256 bits. Chainalysis has estimated that as much as 23% of mined Bitcoin may be permanently inaccessible because of lost keys, including cases involving forgotten seed phrases, damaged backups, and missing inheritance arrangements.1950
Bitcoin2026-07-31 15:22:26COLDCARD Seed Vulnerability Puts Wallets at Risk as Funds Are Already Moving On-ChainBitcoin Magazine, citing an official announcement posted by Coinkite, warned that a serious security flaw is affecting COLDCARD MK3, MK4, MK5, and Q devices. The report says some wallets generated on those devices are being drained because attackers can recover the seed phrase without any action from the user. According to the article, the only wallets considered safe are those created with the dice roll method, provided the user supplied at least 50 rolls of entropy. The piece says any word seed generated after the end of 2020 on a Coldcard is not secure if the user did not add the recommended 50-plus dice rolls. It also says the flaw extends to ephemeral keys and session keys used for Clone Coldcard or Key Teleport, as well as BIP 85 seeds derived from a compromised seed. The attack is described as active, with around 1,000 BTC seen moving on-chain in connection with the issue. For affected users, the article urges an immediate move of funds to a newly generated seed or to a wallet created on a different device. If another hardware wallet is available, the report says that is the fastest option. If not, it outlines a temporary passphrase-based workaround and also mentions Nunchuck, Blockstream Green, and Bluewallet as software wallet options. The article adds that a firmware patch has already been released and says Coldcard remains usable after the update if a new seed is generated securely.2470