David Schwartz Highlights Risks Behind $100M Coldcard Security Breach
A firmware flaw in Coldcard hardware wallets has enabled the theft of over $100 million in Bitcoin, prompting Ripple CTO Emeritus David Schwartz to warn that self-custody does not eliminate operational risk. The breach highlights how rare technical failures can circumvent even the most rigorous offline security measures.
By WildWeb24·August 4, 2026·2 min read·1,177 reads
The incident centers on a vulnerability in firmware versions 4.0.1 through 4.1.9 for Mk2 and Mk3 devices. According to manufacturer Coinkite, these versions relied on a software-based pseudorandom number generator rather than the device’s hardware-level entropy. This weakness allowed attackers to recreate private keys offline by matching them against publicly visible addresses on the blockchain, bypassing the need for physical access or PINs.
Schwartz drew parallels to the 2011 collapse of MF Global, where customers lost access to funds due to brokerage mismanagement. He noted that while hardware wallets protect against exchange-based hacks, they introduce a reliance on firmware integrity. Unlike traditional finance, where bankruptcy proceedings and insurance often provide a safety net, Coldcard users currently lack any recovery mechanism for assets lost to this specific exploit.
Galaxy Research estimates that 1,596 BTC have been stolen across three confirmed attack waves, with a potential fourth wave pushing total losses toward 2,055 BTC, or roughly $130 million. While federal investigators and exchanges have been alerted to the attacker addresses, 90% of the stolen funds remain stationary. Coinkite has issued a patch, but warns that firmware updates cannot secure existing seeds. Owners of affected devices must generate entirely new seeds and migrate their holdings to ensure the safety of their Bitcoin.
Comments (0)
No comments yet. Be the first!