- The Bitcoin Compass ๐งญ
- Posts
- A hardware wallet just got hacked for $88 million (and counting)
A hardware wallet just got hacked for $88 million (and counting)
It wasn't the box that failed. Here's what actually did, and what protects you regardless.
You Already Have a Take on What AI Does Next
OpenAI or Anthropic? Which model leads the next benchmark? Which company ships the next major breakthrough?
If you follow AI closely, you already have opinions on where the industry is headed. Kalshi lets you trade on real-world AI and technology events, with markets that move as models launch, benchmarks drop, and announcements happen.
The people who follow this space most closely often see the story developing before everyone else. Put that knowledge to work and trade what you think happens next.
Bonus credit varies from $15 to $500. Terms apply.
Two weeks ago, pseudonymous blockchain investigator ZachXBT said hardware wallets weren't as safe as everyone assumed. He got dragged for it.

Then just last week, one of the most trusted names in hardware wallets disclosed a flaw that allowed an attacker to drain roughly $88.6 million in Bitcoin from hundreds of wallets. Not through a hack, not through phishing, but through a bug in how the seed itself got created, sitting quietly in the software since 2021.

So here's the real question this issue answers: if the thing you were told couldn't be hacked just got hacked, what actually still protects you? Keep reading.
๐ The Translation
A hardware wallet flaw just cost users an estimated $88 million in Bitcoin. Here's what actually went wrong. ๐
What happened: Coinkite, maker of the Coldcard hardware wallet, disclosed that certain devices had a firmware bug going back to 2021 that weakened the randomness used to generate wallet seeds. Instead of the intended 128 bits of security, affected Mk3 devices had roughly 40 bits, and Mk4/Mk5/Q devices had roughly 72 bits, meaning some seeds could theoretically be guessed by a well-resourced attacker.
On July 30, an attacker drained hundreds of wallets in a tightly coordinated sweep. Early reports estimated $38 million; Galaxy Research later traced the total to roughly $88 million across nearly 4,585 addresses.
Why it matters: This wasn't a hack, a phishing scam, or a stolen device. The wallets themselves were never touched by anyone but their owners. The problem was inside the software that created the seed in the first place, so the flaw existed the moment those seeds were generated, years before anyone took anything.
The Compass take: Coinkite's CEO published a public apology and took full responsibility, which is the right response, and firmware updates alone don't fix this. Anyone who generated a seed on affected firmware needs to create an entirely new one and migrate funds, not just update and carry on. If you own a Coldcard device from this era, this is worth checking today, not eventually.
๐ญ The Long View (Expanded) โ "Cold storage can't be hacked" was never quite true. Here's the history behind that promise, and what this week actually broke.
For years, the pitch behind hardware wallets has been almost absolute: your keys never touch the internet, so they can't be stolen remotely.

It's why people trust these devices with meaningful amounts of Bitcoin, ourselves included. And it's mostly true. The physical device really is offline. What this week showed is that "offline" was never the only thing that mattered.
Here's the part that's easy to miss. A hardware wallet's security depends on two separate factors working correctly: the device's physical isolation and the quality of the randomness used to create your seed in the first place.
Coldcard's air-gap held up fine. The problem was upstream of that, buried in a 2021 software bug that silently swapped a proper hardware random number generator for a weaker software one. The seeds it produced looked completely normal. They just came from a far smaller pool of possibilities than anyone was told.
Two weeks before any of this became public, on-chain investigator ZachXBT reportedly said that hardware wallets weren't as safe as people assumed and faced serious pushback online.
Nobody could point to a specific incident yet, so it read as an overreach. That's worth sitting with. It's exactly the pattern behind almost every "unhackable" claim in this space: confidence runs highest right before the exception shows up, and the people willing to question it early rarely get thanked for it in the moment.
In the days since Coldcard's advisory, other hardware wallet manufacturers have moved quickly to explain how their approaches differ.
Ledger stated that its devices use a certified hardware random number generator built into a secure chip, producing the full 256 bits of entropy the standard requires.
Trezor said it has always combined multiple independent sources of randomness, rather than relying on a single path, as Coldcard's flawed firmware did.
Tangem also said its private keys are generated entirely inside a certified secure element and never leave the chip, and pointed to independent audits of that process.
These are each company's statements about their products, worth reading in full before drawing conclusions, but they point to the same underlying lesson: the randomness of your seed matters as much as the box it's stored in.
Here's the throughline since 2017: every "unhackable" claim in crypto eventually meets a real-world exception, and the response that matters isn't the marketing that follows. It's about whether the company takes responsibility and shows its work, as Coinkite did. Cold storage is still dramatically safer than leaving funds on an exchange. It was never a guarantee against every possible failure, and it still isn't.
If you're choosing a hardware wallet for the first time or wondering whether it's time to move off one, Tangem is worth a look, given its published approach to key generation.

๐ง Reader's Question
You may be asking: "If Coldcard can have a flaw like this, how do I know any hardware wallet is actually safe?"
You don't get certainty, and nobody selling you a wallet should promise it either. What you can do is stack the odds in your favor: buy from a manufacturer that's been independently audited, add your own randomness through dice rolls or a passphrase if the device supports it, and never assume "offline" means "nothing can ever go wrong."
The goal was never a guarantee. It was always reducing the ways this can go wrong, and this week just added one more thing worth checking.
๐ One Thing To Do
If you own a Coldcard device, check Coinkite's official advisory today and confirm whether your firmware and seed generation date fall in the affected range. If you don't own one, take five minutes to check the firmware version your hardware wallet is running, since "I'll get to it eventually" is exactly how this became an $88 million problem for others.
๐๐ป The Close
Incidents like this one are uncomfortable, and they should be. Nobody wants to hear that the thing they trusted with their savings had a blind spot. But the discomfort is the point. It's what makes you actually check, instead of assuming.
To everyone who lost Bitcoin this week, we empathize with you.

You did the responsible thing. You bought a respected hardware wallet and followed the standard advice. That should have been enough, and it wasn't.
Some of the people affected by this may never buy another hardware wallet again. Some may even walk away from Bitcoin and crypto entirely. That's an understandable reaction, and every setback like this slows the whole industry down because trust is the hardest thing to rebuild once it's shaken.
That's exactly why we keep showing up here every week. Not to promise you nothing will ever go wrong, but to make sure you're never finding out the hard way.
Reply and tell us what wallet you're using and whether this week changed how you think about it. And if this issue helped, forward it to the one friend who's been putting off checking their own setup.
โ The Bitcoin Compass
UseTheBitcoin.com ยท Trusted since 2017
PRDs by voice. Bug reports by voice. Ship faster.
Dictate acceptance criteria and reproductions inside Cursor or Warp. Wispr Flow auto-tags file names, preserves syntax, and gives you paste-ready text in seconds. 4x faster than typing.


