Points of Focus
- Goodman lost 18.25 BTC from three wallets in seven minutes.
- All three wallets relied on seeds created through the same vulnerable process.
- Backups cannot repair a seed that lacked enough randomness.
Jonathan Goodman stored 18.25 Bitcoin (BTC) across three offline Coldcard wallets, kept his backups in separate places, and stamped his seed phrases into metal. The so-called pinnacle of self-custody best practices.
Goodman discussed the loss in a new interview with host Natalie Brunell, revealing that several security plans can still fail when they depend on the same technology.
Jonathan Goodman lost more than 18 bitcoins he was saving for his family in the #Coldcard hack.
He shares why he isn’t angry, whether he’s joining the lawsuits forming, his opinion now of self-custody, and the lessons he took from the experience.
He’s also treating what… pic.twitter.com/HCoZedOubo
— Natalie Brunell ⚡️ (@natbrunell) August 25, 2026
Three safes with the same faulty lock
Goodman said that 18.25 BTC, worth around 1.6 million Canadian dollars at the time, was taken from his three wallets on July 29. It happened in seven minutes.
$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack.
My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet.
This part's nerdy, but here's… pic.twitter.com/Lf9kJv9Jo4
— Jonathan Goodman 🇨🇦 (@itscoachgoodman) August 1, 2026
His Coldcard devices had stayed offline, and his backups were still hidden. Instead, the issue began at the seed phrase.
Coldcard manufacturer Coinkite later confirmed that some firmware created seeds with much less randomness than expected. The process was closer to shuffling from a smaller set of possible word orders.
We are all hands on deck doing a deep dive on everything, technical post soon.
all the channels are bombarded. https://t.co/710hfMUArj
— nvk (@nvk) July 30, 2026
A smaller set of word orders means attackers have fewer combinations to check. They could search for weak seeds and compare the resulting Bitcoin addresses with the public blockchain. Physical access to a Coldcard wallet is not required.
So, the problem is, Goodman had three separate Coldcard wallets, but they were all created with these weaker seed phrases. It was like buying three safes with the same, faulty lock.
Backups solve a different problem
A backup protects an owner from losing access to a safe wallet, but it cannot protect against a weak seed phrase.
Coldcard’s Seed XOR guide warns that splitting a seed does not add more randomness or fix one covered by the company’s advisory.
Installing new firmware does not repair an old seed either. Coinkite said in an article on X that affected owners must create a fresh seed with fixed software and move their Bitcoin to the new wallet.
Some holders may also spread their risk across different devices. A multisignature wallet, for example, can require two separate keys before any Bitcoin moves. One key might come from a Coldcard, while another comes from a different wallet maker.
That setup isn’t accessible for less technically inclined users, however. Holders must protect several keys and test that they can still recover the wallet. One lost key or poorly planned backup could result in a new problem.
Backups still protect owners from lost devices, fires, and other physical damage. Goodman’s case shows that every copy can share a weakness, even if it isn’t always apparent.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


