The Coldcard Victims Did Everything Right
But they still lost everything.
Roughly 2,055 bitcoin worth approximately $130 million has been drained from more than 7,300 Coldcard-generated wallets since July 30, according to Galaxy Research’s most recent count. What started as three coordinated waves of sweeps has become a decentralized swarm, with Galaxy identifying at least fifteen independent attackers now racing to exploit any vulnerable wallets that remain unmigrated. The root cause, according to on-chain analysis from Galaxy and Block’s engineering team, is a firmware bug that caused Coldcard devices to fall back to a predictable software randomness source rather than the hardware component intended for the job. That reduced the entropy behind seed generation to a level attackers could reproduce offline. The flaw sat dormant in production firmware for over five years before being discovered and exploited. Coinkite has issued emergency firmware for every affected model, destroyed its remaining inventory of vulnerable devices, and published detailed migration guidance for affected users on their own site. If you own a Coldcard, that guidance is what you should be reading right now. Not this.
What I want to talk about is what makes this particular loss different from every other multi-hundred-million-dollar failure I have covered in this newsletter.
The victims here were not degenerate traders. They were not people who left their bitcoin on FTX chasing yield or convenience. They were not people who deposited into Celsius for the interest rate. They were not people who kept their coins on Mt Gox because moving them off felt like too much friction. They were the opposite of that. These were the people who read the same essays we all read, took the advice about not-your-keys-not-your-coins seriously, spent a couple hundred dollars on a hardware wallet with a strong reputation, generated a seed offline, wrote it down on paper or steel, put the device in a drawer, and did not touch it. They followed the general recommendation this industry has been making to retail holders for over a decade. And they lost their bitcoin anyway.
I told the Arch Public guys that my audience deserved a better shot at this. So for the next 24 hours, every entry counts double. $50K lifetime algo license + a Rolex. Free to enter at archpublicgiveaway.com
That is what makes this worse than an exchange failure.
When Mt Gox failed in 2014, when Celsius failed in 2022, when FTX failed six months later, the moral hook for the industry was available. Users had trusted a counterparty with their coins. The industry could say, honestly, that self-custody was always the answer. Every one of those failures came with warning signs beforehand. Regulatory actions. Executive departures. Withdrawal delays. Pause buttons on withdrawals. The people who lost money had, at some level, either ignored the signals or accepted the trade-off in exchange for convenience or yield. That framing is uncomfortable but it is honest. It gave the industry a story to tell about what went wrong and what to do differently next time.
The Coldcard victims have no such story available to them.
Their bitcoin was offline. Their device was not connected to the internet. Their seed was not typed into any website. They did nothing wrong in any behavioral sense. One of them, Jonathan Goodman, said publicly on X that he lost $1.6 million in bitcoin from his Coldcard wallet. He wrote that he had never shared his seed phrase with anyone, that his devices had never touched the internet, that his backups were kept in multiple safes and safety deposit boxes. “None of it mattered,” he wrote, because one line of code from 2021 in the hardware that created his seed carried the vulnerability. His loss came from a firmware bug he had no way to detect, in a device from a respected manufacturer with a strong security reputation, running production code that had been publicly reviewable the entire time. The advice he followed, the general recommendation that self-custody beats leaving coins on an exchange, was correct. The specific tool that many holders like him chose to act on that advice failed at the level of the underlying cryptography. The gap between those two things is the whole problem.
I have talked about self-custody in this newsletter and on the show for years. The industry as a whole has been telling retail holders that self-custody is the answer to counterparty risk for longer than that. That message, in the aggregate, remains right. Most bitcoin, most of the time, is safer in cold storage than on an exchange. But the aggregate answer being right does not do anything for the specific people who lost $130 million between July 30 and this week. They are owed an acknowledgment, not a lecture about what they should have done differently. Most retail holders bought a hardware wallet, generated a seed, and moved on with their lives, exactly as the industry told them to. This attack broke a foundational assumption underneath a specific product line, and the fallout for the industry’s credibility on self-custody is worse than any of the recent exchange failures because there is no clean story to tell about what the victims did wrong.
In a social media post over the weekend, Coinkite said the last three days had been some of the hardest in the company’s history, and for a lot of the people reading, they had been something much worse. That is one of the more honest things a crypto company has said all year. Galaxy Research is now working with 73 confirmed victims, has coordinated with law enforcement and exchanges, and reports that roughly 90 percent of the stolen bitcoin remains static and traceable on-chain, which means recovery of some portion is genuinely possible over time. That is a real effort worth naming. It also does not resolve the framing question, because the moral asymmetry remains whether or not the coins come back.
The broader lesson is worth stating because we will hear it again over the next two years. Hardware wallets are not magic. They are small computers running firmware, and firmware has bugs, and bugs can sit dormant for years before someone notices. That does not make self-custody wrong. It makes self-custody a discipline rather than a purchase, and it puts more weight on things retail holders have historically not thought much about. Redundant hardware. Verified randomness. Continuously updated firmware. Multi-signature setups for meaningful amounts. Actual attention to what the device is doing rather than trust in what the box says. Everything I just listed is friction that most retail holders will not do, which is the honest gap between the self-custody promise and the retail self-custody reality. This incident just made that gap visible in the ugliest possible way.
The behavioral response is already visible on-chain. Net Bitcoin transfers from self-custody wallets to centralized exchanges have been positive every day since July 31, reversing a two-year outflow trend that began after the FTX collapse in November 2022. OKX has reported record exchange inflows in the wake of the exploit, with its chief compliance officer Jonathan Brockmeier telling The Block that it is “sort of the flip side of FTX.” Some of that flow is retail panic moving smaller balances onto exchanges out of an abundance of caution. Some of it is deliberate, from holders who did the math and decided that the operational risk of self-custody is now higher for them personally than the counterparty risk of a regulated exchange they know. That calculation is worth naming even if you disagree with the answer, because it tells you the credibility damage from this incident is not confined to the specific victims. It has already changed how a meaningful group of holders is thinking about the trade-off.
The people who lost bitcoin here did not deserve to lose it. And the industry that has told them for years to move their coins into cold storage owes them the honesty of saying so.
Bitcoin Has ZERO Bank Liquidity - That’s About To Change | Christopher Perkins
My Platforms And Sponsors
Arch Public - It’s a hedge fund in your pocket. Built for retail traders, designed to outperform Wall Street. Try emotionless algorithmic trading at Arch Public today.
Promote your brand with The Wolf of All Streets. For sponsorship and partnership opportunities, contact info@thewolfofallstreets.io.
The Wolf Pack - My Telegram group where I share daily market updates, real-time observations, and ongoing discussions with the community. There’s a dedicated channel and group chat, and it’s completely free to join.
X - I spend most of my time on X, contributing to CryptoTownHall every weekday morning, sharing random charts, and responding to as many of you as I can.
YouTube - Home of the Wolf Of All Streets Podcast and daily livestreams. Market updates, charts, and analysis!
The views and opinions expressed here are solely my own and should in no way be interpreted as financial advice. Every investment and trading move involves risk. You should conduct your own research when making a decision. I am not a financial advisor. Nothing contained in this e-mail constitutes or shall be construed as an offering of financial instruments or as investment advice or recommendations of an investment strategy or whether or not to "Buy," "Sell," or "Hold" an investment.
Thanks for reading The Wolf Den! Subscribe for free to receive new posts and support my work.



while your essay is very sympathetic, it remains deficient in highlighting adequately, a risk underlying the entire crypto world - the nearly universal risk in almost all software of some kind of undiscovered exploitable flaw. I had owned bitcoin, stored on an exchange at first -watched that and found they could be hacked - moved to a cold wallet but still felt uncomfortable with the general nature of cryptocoin being nothing more than hopefully well written software and decided this was not the kind of money I felt comfortable owning in any large quantity. I can't claim any wonderful solution but so far I don't feel $ accounts at major banks and brokerages seem less subject to hacks leaving me to deal with strategies to offset government currency depreciation at the paper currency level with more traditional strategies but at least i don't feel like the uneducated puppy in the contest.