AI Just Cracked Coldcard's Security
July 31, 2026
On this episode of The Last Trade, Onramp Media's hosts break down the Coldcard entropy flaw that let attackers drain more than 1,000 bitcoin from vulnerable wallets. They argue single-vendor multisig can be reconstituted from a wallet's own configuration, and point to Onramp's Multi-Institution Custody, spread across independent keyholders, as a fault-tolerant alternative.
Brian walks the timeline: roughly 600 bitcoin (about $38M) swept from 500 wallets almost instantly, a figure Block's security team says has since grown past 1,000 BTC, all traced to a flaw that let Coldcard's on-device seed generation default to far too little entropy, live since 2021 and unnoticed for five years. Coinkite first said only the MK3 was affected, then aligned with Block's finding that the MK4, MK5, and Q are exposed too, deprecating the MK3 and pushing firmware updates. Michael lays out the math: a real key is 256 bits and effectively uncrackable, while this exploit collapsed entropy into the 30-to-40-bit range, and the hosts warn single-vendor multisig can be reconstituted from the wallet's own configuration, echoing Wizardsardine's call for affected users to move to new devices quickly. The hosts argue the deeper shift is AI: cheaper compute has lowered the barrier for digital, social, and physical attacks, so an old setup no longer holds up at today's prices. They close by contrasting it with Onramp's Multi-Institution Custody: bitcoin secured across three independent institutions in a 2-of-3 design, with custody insurance through Lloyd's of London covering Onramp's operations against private-key compromise (not client assets), and the client retaining title throughout.
Chapters
00:00 - Introduction to the Cold Card Exploit and Its Impact 02:18 - Technical Breakdown of the Firmware Vulnerability 05:11 - Implications for Hardware Wallet Security and Industry Risks 08:45 - What the Exploit Means for Cold Card Users and the Industry 11:01 - The Changing Landscape of Bitcoin Custody and Security Strategies 20:18 - Potential Impact on Other Hardware Wallets and Industry-Wide Risks 22:39 - Adapting Custody Strategies: Multi-Sig and Distributed Security 33:22 - The Future of Bitcoin Security and Industry Evolution
Read our full breakdown: The Coldcard Exploit, Explained.
Frequently Asked Questions
What caused the Coldcard exploit?
The hosts explain the flaw traced back to Coldcard's on-device seed generation defaulting to far too little entropy, a bug live since 2021 that collapsed key strength from 256 bits down to roughly 30 to 40 bits (02:18-05:11).
Which Coldcard models are affected by the exploit?
Coinkite first said only the MK3 was affected, but the hosts note it later aligned with Block's finding that the MK4, MK5, and Q are exposed too, prompting Coinkite to deprecate the MK3 and push firmware updates (05:11-08:45).
Does the Coldcard exploit put multisig wallets at risk too?
The hosts warn that single-vendor multisig isn't automatically safe, since a wallet's own configuration can be used to help reconstruct compromised keys, echoing Wizardsardine's call for affected users to move to new devices quickly (22:39-33:22).
How does Onramp's custody model address single-vendor key risk?
The hosts contrast the exploit with Onramp's Multi-Institution Custody, a 2-of-3 design spread across independent institutions rather than one vendor, with custody insurance through Lloyd's of London on Onramp's operations and the client retaining title throughout (33:22 onward).
This episode is editorial and educational content. Onramp does not provide tax, legal, or investment advice. Bitcoin is volatile and may lose value. Past performance does not guarantee future results.