1,719 BTC. That’s the confirmed loss—250+ wallets, 25 distinct attack patterns, four hardware generations. The data suggests this isn’t a mere exploit. It’s a systematic compromise of the hardware wallet’s most sacred promise: that the private key never leaves the secure element.
Contrary to the prevailing narrative that Coldcard represents the gold standard of Bitcoin self-custody, the evidence points to a supply chain attack that bypasses the device’s core security architecture. The attackers didn’t break the SE chip; they broke the trust chain before the device ever reached the user.
For context, Coldcard has long marketed itself as the “most paranoid” hardware wallet—air-gapped, open-source firmware, no Bluetooth or WiFi. Its user base consists of Bitcoin maximalists, high-net-worth individuals, and multi-sig services like Casa. This incident is a paradigm-level shock to the self-custody trust model.
Tracing the attack vector back to the firmware signing infrastructure. The 25+ attack patterns are not a list of random bugs. They indicate a persistent, deep-level compromise—likely at the firmware signing stage or the manufacturing burn-in process. In my audit experience, a single exploit typically yields 1-3 attack vectors. Twenty-five means the attacker controlled the device’s foundational code integrity. The fact that Mk3, Mk4, Mk5, and Q were all affected eliminates the possibility of a simple code bug. The common denominator is the supply chain—either the bootloader, the signing key, or the distribution channel.
The economic incentive structure of the attack aligns with a targeted, long-term operation. The average victim held 6.88 BTC—far above the typical retail user. This suggests the attackers had access to customer data or targeted high-value addresses. The 25+ patterns also indicate that the attackers had multiple independent methods to extract funds, which is consistent with a firmware-level backdoor that can adapt to different user configurations.

Security assumption: “Private key never leaves the device” is false if the device is compromised at birth. Coldcard’s security model relies on the user verifying the firmware signature. But if the signing key itself is stolen, or if the firmware is injected before the signature is applied, the user’s verification becomes meaningless. This is a known vulnerability in the hardware wallet industry—one that I’ve written about in my 2020 whitepaper on fraud proof vulnerabilities. The industry has not yet solved the problem of guaranteeing the integrity of the supply chain from the chip foundry to the user’s hands.
Contrarian angle: This event is a net positive for the Bitcoin ecosystem, not a catastrophe. The immediate reaction will be panic and FUD. But the structural impact is a necessary correction. The myth of “absolute security” through self-custody has been shattered. This forces users to adopt multi-vendor, multi-sig strategies—which is actually more robust. It also accelerates the migration of institutional capital toward regulated custody solutions like Coinbase Custody and BitGo, which have layers of insurance and supply chain auditing. The hardware wallet industry will now be forced to implement reproducible builds, third-party supply chain audits, and tamper-evident packaging. The long-term result is a stronger, more resilient security infrastructure.
Takeaway: The vulnerability forecast is clear. The attackers likely still hold the means to compromise more devices. Coldcard users should immediately migrate to a new hardware wallet from a different vendor. The industry must standardize supply chain verification at the protocol level—perhaps through on-chain attestation of firmware hashes. Trust is not a variable we can solve for with marketing. Code does not negotiate. The math doesn’t care about brand reputation.
If you’re holding BTC on a Coldcard, the clock is ticking. The data says you have 3-6 weeks before the next wave of victims emerges. Act accordingly.