Coldcard Hack Becomes a Self-Custody Situation

By Max Moeller // August 29, 2026 @ 05:39 PM Make AlphaWire Logo preferred on Google News

Share

More Markets Exploit Drains $9.3M in WFLOW as FLOW Drops 9%

Share

Points of Focus

  • Goodman lost 18.25 BTC from three wallets in seven minutes.
  • All three wallets relied on seeds created through the same vulnerable process.
  • Backups cannot repair a seed that lacked enough randomness.

 

Jonathan Goodman stored 18.25 Bitcoin (BTC) across three offline Coldcard wallets, kept his backups in separate places, and stamped his seed phrases into metal. The so-called pinnacle of self-custody best practices.

Goodman discussed the loss in a new interview with host Natalie Brunell, revealing that several security plans can still fail when they depend on the same technology.

 

 

Three safes with the same faulty lock

Goodman said that 18.25 BTC, worth around 1.6 million Canadian dollars at the time, was taken from his three wallets on July 29. It happened in seven minutes.

 

 

His Coldcard devices had stayed offline, and his backups were still hidden. Instead, the issue began at the seed phrase.

Coldcard manufacturer Coinkite later confirmed that some firmware created seeds with much less randomness than expected. The process was closer to shuffling from a smaller set of possible word orders.

 

 

A smaller set of word orders means attackers have fewer combinations to check. They could search for weak seeds and compare the resulting Bitcoin addresses with the public blockchain. Physical access to a Coldcard wallet is not required.

So, the problem is, Goodman had three separate Coldcard wallets, but they were all created with these weaker seed phrases. It was like buying three safes with the same, faulty lock.

 

Backups solve a different problem

A backup protects an owner from losing access to a safe wallet, but it cannot protect against a weak seed phrase.

Coldcard’s Seed XOR guide warns that splitting a seed does not add more randomness or fix one covered by the company’s advisory.

Installing new firmware does not repair an old seed either. Coinkite said in an article on X that affected owners must create a fresh seed with fixed software and move their Bitcoin to the new wallet.

Some holders may also spread their risk across different devices. A multisignature wallet, for example, can require two separate keys before any Bitcoin moves. One key might come from a Coldcard, while another comes from a different wallet maker.

That setup isn’t accessible for less technically inclined users, however. Holders must protect several keys and test that they can still recover the wallet. One lost key or poorly planned backup could result in a new problem.

Backups still protect owners from lost devices, fires, and other physical damage. Goodman’s case shows that every copy can share a weakness, even if it isn’t always apparent.

Share

Default avatar

Max Moeller

Max Moeller is a Chicago‑based writer and video editor passionate about games, tech, and crypto. Whether it’s crafting clear, insightful articles or piecing together engaging video retrospectives, he’s driven by curiosity and takes pride in keeping things human. Since 2017, Max has been published in a variety of notable crypto magazines.

Table of content

Ad

Related Articles