Coldcard losses remained active while the story expanded
The incident was a real capital-loss event first
This started as a live capital-risk event, not a theoretical security scare. Attackers hit Coldcard in four waves of thefts across more than 5,200 individual addresses, with losses reaching nearly $114 million. Coinkite is still in the middle of an ongoing investigation, so the situation remains unresolved rather than fully contained.
The flaw struck at the recovery phrase layer
The most damaging point was not a smart-contract bug; it was in Coldcard's recovery phrase generation. According to reports cited in the coverage, the device stopped using strong randomness and fell back to a more predictable process. That meant "offline" did not automatically mean "safe keys." Once attackers understood the pattern, they could reproduce it locally and test which wallets held funds.
Why confidence matters as much as the loss itself
The immediate impact was financial, but the secondary impact was credibility. Self-custody advocates argue that users need full control; this incident shows the other side of that trade-off when the randomness layer fails. With losses still being tracked as ongoing, that confidence hit can matter just as much as the direct capital loss in the short term.













