The Coldcard Hack That Broke Self-Custody
August 4, 2026
The Coldcard exploit has escalated: nearly 2,000 bitcoin drained and counting, passphrase wallets confirmed compromised, MK4s and Qs exposed alongside the deprecated MK3, and Coinkite confirming a five-year-old flaw in on-device seed generation. This week Michael, Liam, and Brian walk the full timeline of the worst self-custody incident in bitcoin's history: how the RNG silently downgraded to guessable entropy, why same-vendor multisig quorums are also at risk, and the firmware updates reportedly bricking devices mid-migration. Michael and Liam share their own weekend fund migrations (one from the back seat of a car), and the guys get into the harder questions: why AI may be a bigger threat to bitcoin security than quantum computing, why the stampede to exchanges and ETFs is the wrong lesson, and what a fault-tolerant custody architecture looks like when one mistake can no longer be allowed to knock you out of the game.
Chapters
00:00 - The Coldcard exploit: what happened and who is affected 02:20 - Move your funds: urgent guidance for Coldcard holders 05:09 - Technical breakdown: how the RNG flaw was exploited 10:17 - Passphrases, firmware bricking, and the silent downgrade 17:14 - Earlier warnings and why same-vendor multisig is exposed 21:22 - Weekend migrations: Michael and Liam's personal anecdotes 30:26 - AI vs quantum: the real threat to Bitcoin security 33:25 - Single-vendor risk, single-entity risk, and custody honeypots 44:03 - Silver linings: the end of the custody purity test 50:26 - Where the industry goes from here 56:15 - One mistake can't knock you out of the game 59:05 - Final guidance and staying vigilant