🧵 The Fall of the King: What Happened to ColdCard
(A thread for anyone to understand)
1/ If you asked on Bitcoin Twitter in the last 5 years, "Where do I store my sats?", you'd get only one answer: ColdCard. It wasn't just another option. It was "The Option."
2/ Why? Because it was bitcoin only (no shitcoins), truly air-gapped (you never plugged it into your computer, everything was via microSD), Canadian, independent, and had no investment backing. It had features for the professional paranoid: emergency PIN, PIN to brick the device, and double secure element.
3/ Anyone who used Ledger was a normie. Anyone who used Trezor didn't understand anything. Anyone who used ColdCard knew what they were doing. Criticizing it on Twitter guaranteed you'd be attacked by a mob.
💥 And on July 30, 2026, everything went down.
4/ Reports start surfacing of people having their wallets emptied. Wallets that had been dormant for years. People who never connected anything, who never clicked on a suspicious link, who did EVERYTHING right.
5/ The Block team (yes, Jack Dorsey's team) starts investigating and finds the bombshell: ColdCard had been generating malicious code since March 2021.
🎰 What is a "bad seed"?
6/ Your wallet doesn't store Bitcoin. It stores 24 words derived from a giant random number. If that number is truly random, it's impossible to guess. Period.
7/ But if the number is NOT random—if it comes from a formula—anyone who discovers the formula can recreate those 24 words at home and drain your wallet. They don't need to touch the device or even come near you.
8/ What exactly happened? The ColdCard has a chip that actually generates randomness. But in a 2021 code refactor, a poorly written line of code caused the device to silently stop using it and switch to using a toy software generator.
9/ What was that toy generator powered by? The chip's serial number and the system clock. In other words: public and guessable data. Nothing secret. The seed was deterministic.
10/ You'd press "generate new seed," 24 beautiful words would appear, and there was absolutely no way to tell. They looked perfect. They were predictable.
📉 The Damage
11/ ~594 BTC confirmed (around $38-$40 million) from approximately 500 wallets, in a matter of hours. On-chain suggests it could reach 1,082 BTC.
12/ Affected Models: Mk2 and Mk3 with firmware v4.0.0 and later are the worst (zero real randomness). Mk4, Q, and Mk5 attempted a patch with the secure element, but it truncated the randomness to 32 bits—that is, 4.3 billion combinations. A graphics card will crash them.
13/ And the worst part: if you exported that seed phrase to another wallet (Sparrow, Electrum, any other), you're still at risk. The problem is the seed phrase, not the device. You can buy ten new hardware wallets: if you use the same 24 words, you're just as vulnerable.
14/ Multisig won't save you either if all the keys came from vulnerable ColdCards. You need at least a quorum of keys to come from a healthy device.
🚩 The "open source" detail
15/ Here's where it gets uncomfortable. For years, the main argument against Ledger was: "It has closed firmware, you can't audit it, ColdCard is open source."
16/ First: ColdCard isn't open source in the strict sense. It has its own restrictive, "source-available" license: you can look at the code, but it's not free. It's not MIT, it's not GPL. In fact, the bug was included in a refactor precisely to get rid of GPL code. Take that.
17/ And second, more importantly: "public code" ≠ "audited code." The bug was in plain sight for more than 5 years and nobody noticed it. Not the community, not the audits, not even Coinkite's internal reviews (including some done with AI).
18/ Reviewable, not reviewed. Just because you can look at it doesn't mean someone actually looked at it.
19/ And the greatest irony: in the end they were saved by Block/Bitkey - that is, the "corporate" side that ColdCard's maxis looked down upon.
🎲 Now then: the dice
20/ The ColdCard always had a somewhat hidden option: generating the seed by rolling dice. Instead of relying on the chip, you introduce randomness.
21/ It's literal: you take a physical 6-sided die, roll it, and tap the number that comes up on the screen. You repeat this 99 times. Then the device hashes that entire sequence, and that becomes your seed.
22/ Why 99? Each roll contributes ~2.58 bits of randomness. 99 rolls = 256 bits, the maximum Bitcoin uses. With 50 rolls, you're already decent (~129 bits). With 25, you're weak.
23/ A physical die rolled by you is physically unpredictable. There's no firmware, no poorly written line of code, and no manufacturer that can ruin it. It's real-world randomness.
24/ HERE'S THE POINT: those who used dice didn't lose a penny. Even though the device's internal generator was predictably unreliable, the ColdCard mixes (XOR) your randomness with its own. And in an XOR, if one of the two is good, the result is good.
25/ Rolling a die 99 times and writing down each number takes half an hour. It's tedious, boring, and you feel like a lunatic. For years, people mocked those who did it: "Why bother? The chip has a certified generator."
26/ Well. The lunatics were right.
⚠️ If you're going to use dice:
- Use casino dice if you can (balanced). A regular plastic one will do too.
- Roll it seriously, let it roll. Don't always drop it the same way.
- Never use a pattern (1, 2, 3, 4, 5...) or a digital die from an app.
- Never write down the sequence. Those 99 numbers ARE your seed. Whoever has them, has your money.
🧠 The Moral of the Story
27/ It's not that Bitcoin failed. It's not that self-custody failed. A specific implementation failed, and it failed silently for 5 years in the product we all considered the most secure on the market.
28/ What remains:
- Don't rely on a single layer of security
- "Open source" won't save you if no one audits
- Even the most beloved manufacturer can make mistakes
- You create the entropy.
29/ Half an hour rolling a die. That was the difference between losing everything and losing nothing.
If you have or had a ColdCard: check which firmware you used to generate the seed phrase. If it was v4.0.0 (March 2021) or later and you didn't use dice or a strong passphrase, move to a new wallet. Now.
