Three weeks after an attacker began draining Coldcard devices, the argument circulating among long-time bitcoin holders had shifted. The question stopped being which hardware wallet to buy and became whether a device you hold yourself can be trusted at all, with more than a few people concluding that a regulated custodian sounds appealing after watching offline storage fail. That conclusion is understandable, and it hands the outcome to the wrong party. Hardware wallet security failed in a specific way here, and the specifics point somewhere other than back to a bank.
What broke
The flaw sat in firmware version 4.0.1, shipped in March 2021. A configuration error caused affected devices to fall back on a weak software random number generator instead of the hardware entropy source when creating a wallet seed, and TRM Labs found the resulting keys carried as little as 40 bits of strength against the 128 bits they should have had. That gap is the whole incident: 40 bits is brute-forceable by anyone with patience and a machine, and nobody needed to touch the device.
Exploitation started on 30 July 2026 and moved fast. The first wave took roughly 594 BTC from about 500 wallets inside 25 minutes, three more waves followed over four days, and the total reached around 1,816 BTC across more than 5,200 wallets, worth about 116 million USD. Researchers at Block identified the underlying weakness, and TechCrunch reported that at least a dozen separate attackers piled in once the method was understood.
The detail that makes this sting: a firmware update fixes nothing for keys already generated. Anyone whose seed was created on vulnerable firmware has to move funds to a wallet generated on patched hardware, because the weakness lives in the seed itself rather than in the software running today.
Why the custodian reflex is understandable
Watching an air-gapped device leak keys undermines the premise people were sold. You were told the danger lived on the internet, that keeping keys offline removed it, and then keys generated offline turned out to be guessable from a laptop. If the promise was wrong, why carry the burden?
Wall Street has noticed the opening. Citi announced on 18 August that it expects to go live with bitcoin custody for institutional clients before the end of 2026 under a platform it calls Custody+, and the pitch writes itself when self-custody is in the news for the wrong reasons.
What a custodian changes
Handing your coins to a company swaps one failure mode for a different one. A custodian removes the risk that you mismanage a key, and it introduces the risk that the company fails, freezes withdrawals, gets ordered to hand assets over, or discovers a hole in its own accounting. FTX customers were owed roughly 8 billion USD, and every one of them had chosen the option that felt like less responsibility.
The comparison worth drawing is about who absorbs a mistake. When a hardware vendor ships a bad build, the loss lands on the people who generated seeds during that window, which is terrible and also bounded and discoverable. When a custodian fails, the loss lands on everyone holding a balance, and you learn about it after withdrawals stop.
Neither model is risk-free. The choice is which risks you can inspect, and a device you control is one you can audit, replace, and migrate away from on your own schedule.
What to demand from hardware instead
The Coldcard incident is a strong argument for asking harder questions of wallet makers rather than abandoning the category. Start with where entropy comes from and whether key generation happens inside a certified secure element, since that is the layer the Coldcard bug bypassed. Ask whether an outside firm has audited the firmware, and whether the resulting report is published in full or paraphrased in a press release. The last question is about failure: if one component of your setup breaks or turns out to be flawed, what does the vendor expect you to do about it?
On the Ryder One, keys are generated inside an EAL6+ certified Infineon SLC38 secure element and never leave the chip, which is the layer that a build-configuration mistake in application firmware cannot reach into. Our firmware was independently audited by Halborn, and the full report sits online for anyone who wants to read the findings themselves. The button on the device is wired directly to the secure element, so no software path can sign without a deliberate press, and every transaction renders in readable detail on the 1.6-inch AMOLED screen before you approve it.
Recovery that survives one bad component
The deeper lesson of the past three weeks is about concentration. Thousands of people lost everything because one value, created once, in one moment, on one device, turned out to be weaker than advertised. Any setup where a single artifact carries the entire wallet has that shape, whether the artifact is a seed generated by flawed firmware or twelve words on a card in a drawer.
TapSafe Recovery spreads restoration across pieces so that no one of them is the wallet. Your Recovery Tag holds 50%, your paired phone holds the other 50% encrypted into your own iCloud or Google Drive rather than on the handset, and optional Recovery Contacts hold 25% each while seeing nothing about your holdings. Two pieces restore, one piece reveals nothing, and a failure in any single place becomes a replacement rather than a loss. Your seed phrase stays on the device as a last resort under the BIP-39 standard, so migrating to other hardware is always available to you.
Setup takes about 60 seconds across three NFC taps, and the Starter Combo is 149 USD with the Recovery Tag, wireless charger, and pouch included.
A bad firmware build is a reason to raise your standards for hardware. Giving your keys to someone else answers a different question than the one this incident asked.
Hold your own keys on hardware that shows its work. Get your Ryder One.
Meta description: The Coldcard hack has bitcoin holders eyeing custodians again. What broke in firmware 4.0.1, and what hardware wallet security should look like instead.




Share: