This Coldcard incident is suffocating. A group of people who believe in BTC’s core value were hurt the most deeply.

You are a BTC hodler. You have long practiced self-custody. You don’t trust exchanges. You’ve kept your seed phrase well and never exposed it to the internet. You chose a secure, long-running, Bitcoin-only, well-established hardware wallet—trusted by a large number of OGs—that has supported multiple BTC cycles...

You thought you had already considered everything thoroughly and avoided all risks.

But you never imagined the problem was in the most fundamental layer: the random number generation.

This issue has existed since 2021. Due to a random-number generation problem in a certain version of Coldcard firmware, the randomness used to generate private keys was insufficient. An attacker could recover the private keys by computation.

The amount of BTC that has been stolen is now up to 1,367.05 BTC, involving 4,585 wallets.

This is the harshest lesson of Bitcoin self-custody: whether your BTC is safe depends not only on whether you’ve protected your seed phrase.

It depends on the entire chain: randomness generation, hardware wallet firmware, backup and private key management strategies, and your everyday usage habits and security awareness...

Self-custody isn’t as simple as “buy a hardware wallet and then transfer coins into it.” A hardware wallet is not absolutely secure.

Bitcoin gives us ultimate ownership of our assets, but it also requires us to take full responsibility for that ownership.

The Coldcard incident has driven an on-chain migration of about 77,400 BTC that had been dormant for years. It is the largest on-chain migration since the FTX collapse. Some people, while reconsidering moving their BTC back into CEXs or buying ETFs and abandoning self-custody, is truly a pity.