River has published a breakdown of the Coldcard hardware wallet exploit, offering lessons for anyone practicing bitcoin self-custody.
The attack began on July 30, targeting people holding bitcoin on Coldcard devices made by Coinkite, a bitcoin-only hardware wallet manufacturer founded in 2012.
According to Galaxy Research, more than 1,816 bitcoin were stolen from over 7,000 addresses.
Where the wallets fell short
Coinkite’s Coldcard wallets had long been recommended by influential Bitcoiners for their security-first reputation and open-source software.
The problem came down to how the devices generated private keys. Since 2021, affected firmware used a random number generator with very low randomness.
River explained the danger with a simple analogy:
“Imagine if you made a private key by flipping a weighted coin that always fell on heads; it would be quite easy for someone to access your bitcoin.”
As a result, every seed generated on the affected firmware was at risk of being guessed.
Not a Bitcoin protocol issue
River stressed that the flaw was isolated to the hardware, not the network itself:
“The Coldcard vulnerability does not affect the Bitcoin protocol or anything related to how Bitcoin works.”
The firm noted that bitcoin’s price stayed flat in the weeks following the attack, suggesting the market did not view the event as damaging to bitcoin’s value proposition.
Two lessons for self-custody
River drew two conclusions from the episode, warning that removing exchange risk does not remove all risk:
“Cold storage is not inherently secure. Your self-custody setup can be completely air-gapped from the internet, safe from malware and phishing attacks, but can still be vulnerable to theft depending on the hardware you use.”
The firm added that Bitcoiners still face third-party risks when relying on wallet manufacturers or intermediaries, and encouraged users to learn how to custody their bitcoin safely.