Share
Subscribe to the AlphaWire Newsletter
Coldcard, one of Bitcoin’s most widely used hardware wallet manufacturers, is facing intensifying scrutiny after new allegations suggest it ignored an early warning about the very component now linked to one of the largest hardware wallet security incidents in recent years.
The controversy comes as blockchain analytics firms continue to measure the fallout from the exploit, with estimated losses climbing above $100 million and onchain data showing Bitcoin holders abandoning affected wallets at a pace not seen since the collapse of FTX.
Bitcoin developer James O’Beirne (@jamesob) revealed that he audited Coldcard firmware in May 2025 and flagged concerns surrounding libngu, the cryptographic library responsible for random number generation (RNG).
🚨BITCOIN DEV WARNED COLDCARD ABOUT RNG FLAW IN 2025, TEAM DISMISSED IT!@jamesob says he audited Coldcard firmware in May 2025, flagged the low-star libngu library handling RNG as shady, and reported doubts the true hardware randomness was even active.
He advised ripping it… pic.twitter.com/OkVqlQQFt7
— Crypto Banter (@crypto_banter) August 4, 2026
According to O’Beirne, the library appeared poorly maintained and raised questions about whether the wallet’s hardware random number generator was actually being used when generating wallet seeds.
He said he recommended removing the implementation altogether.
Instead, O’Beirne claims the Coldcard team responded that “if something was wrong we’d already know about it by now,” declining to act on his recommendation.
He further alleged that GPG signatures on libngu commits suggest the library’s pseudonymous maintainer, known as DocHex, is Coinkite Chief Technology Officer Peter Gray.
The claims surfaced only days after researchers disclosed that a firmware flaw had allowed certain Coldcard devices to generate wallet seeds using predictable software randomness instead of dedicated hardware entropy, significantly weakening private key security.
The financial impact continues to grow as investigators trace affected wallets.
Blockchain analytics firm Chainalysis said Canadian Bitcoin holders appear to be the hardest hit, accounting for roughly 25% of all attributable losses linked to the incident.
Drawing on Galaxy Research’s estimates, the firm said total losses could reach as much as $110 million.
Australia, the United States and Thailand also rank among the countries suffering significant losses, highlighting the global nature of the breach.
While investigations remain ongoing, researchers have not yet finalized the exact amount stolen or identified every affected wallet.
The market reaction has been almost as striking as the exploit itself.
According to CryptoQuant, wallets holding less than one Bitcoin transferred 39,600 BTC on July 31, only days after the vulnerability became public.
Coldcard users are fleeing at FTX-collapse speed.
Sub-1 BTC transfers hit 39.6K BTC on July 31, days after the hack disclosure.
That's just shy of the 39.9K BTC moved when FTX collapsed in Nov 2022. Small holders haven't moved at this scale in nearly 4 years. pic.twitter.com/g5AIgsOpLM
— CryptoQuant.com (@cryptoquant_com) August 4, 2026
That compares with 39,900 BTC transferred by small holders during the collapse of FTX in November 2022, one of the largest self-custody migrations in Bitcoin’s history.
CryptoQuant noted that retail investors have not moved funds on this scale in nearly four years, suggesting the Coldcard incident has triggered one of the biggest confidence shocks ever experienced by the hardware wallet sector.
Rather than selling Bitcoin, users appear to be rapidly migrating funds into newly generated wallets or alternative custody solutions.
The latest revelations have shifted attention beyond the exploit itself toward Coldcard’s development and security review processes.
If O’Beirne’s account is accurate, the RNG concerns were raised more than a year before the vulnerability became public, prompting questions about whether additional code review or remediation could have reduced the eventual impact.
The incident has also reignited debate over hardware wallet security. While self-custody remains a cornerstone of Bitcoin ownership, the breach underscores that hardware wallets are only as secure as the firmware responsible for generating their cryptographic keys.
For now, the combination of an alleged ignored warning, estimated nine-figure losses, and FTX-era levels of wallet migration has turned the Coldcard incident into one of the most closely watched security events in Bitcoin’s history.
Neither Coinkite nor Coldcard had publicly responded to O’Beirne’s allegations at the time of writing. The company has previously acknowledged the firmware vulnerability and published guidance for affected users to migrate funds from vulnerable wallets.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share