The Coldcard Hack That Broke Self-Custody
August 4, 2026
Onramp's Final Settlement podcast breaks down the Coldcard hardware wallet exploit: Coinkite confirmed a five-year-old flaw in on-device seed generation, and the hosts report nearly 2,000 bitcoin drained across affected devices. They argue the incident exposes deeper risk in same-vendor multisig setups and urge holders to migrate funds immediately.
The Coldcard exploit has escalated: nearly 2,000 bitcoin drained and counting, passphrase wallets confirmed compromised, MK4s and Qs exposed alongside the deprecated MK3, and Coinkite confirming a five-year-old flaw in on-device seed generation. This week Michael, Liam, and Brian walk the full timeline of the worst self-custody incident in bitcoin's history: how the RNG silently downgraded to guessable entropy, why same-vendor multisig quorums are also at risk, and the firmware updates reportedly bricking devices mid-migration. Michael and Liam share their own weekend fund migrations (one from the back seat of a car), and the guys get into the harder questions: why AI may be a bigger threat to bitcoin security than quantum computing, why the stampede to exchanges and ETFs is the wrong lesson, and what a fault-tolerant custody architecture looks like when one mistake can no longer be allowed to knock you out of the game.
Chapters
00:00 - The Coldcard exploit: what happened and who is affected 02:20 - Move your funds: urgent guidance for Coldcard holders 05:09 - Technical breakdown: how the RNG flaw was exploited 10:17 - Passphrases, firmware bricking, and the silent downgrade 17:14 - Earlier warnings and why same-vendor multisig is exposed 21:22 - Weekend migrations: Michael and Liam's personal anecdotes 30:26 - AI vs quantum: the real threat to Bitcoin security 33:25 - Single-vendor risk, single-entity risk, and custody honeypots 44:03 - Silver linings: the end of the custody purity test 50:26 - Where the industry goes from here 56:15 - One mistake can't knock you out of the game 59:05 - Final guidance and staying vigilant
Read our full breakdown: The Coldcard Exploit, Explained.
Frequently Asked Questions
What caused the Coldcard hack?
Coinkite confirmed a five-year-old flaw in on-device random number generation that made seed entropy guessable, compromising both passphrase and standard wallets across MK4, Q, and the deprecated MK3. The hosts break down the technical failure starting at 05:09.
How many bitcoin were affected by the Coldcard exploit?
The hosts report nearly 2,000 bitcoin drained and counting from affected Coldcard devices as of this episode. Final Settlement covers the ongoing timeline starting at 00:00.
Does the Coldcard flaw put multisig setups at risk?
The hosts argue that same-vendor multisig quorums are also exposed, since a shared RNG flaw across devices from one vendor can compromise multiple keys in a single quorum. This risk is discussed starting at 17:14.
What should Coldcard holders do now?
The hosts urge affected holders to migrate funds immediately, sharing their own weekend migration experiences, and discuss firmware updates reportedly bricking devices mid-migration. Guidance begins at 02:20.
This episode is editorial and educational content. Onramp does not provide tax, legal, or investment advice. Bitcoin is volatile and may lose value. Past performance does not guarantee future results.