The hardware crypto wallet market has been hit by a severe crisis of confidence as a technical flaw in Coldcard devices allowed hackers to completely drain more than 500 Bitcoin addresses. In a single automated attack, the perpetrators transferred 594.48 BTC, worth about $38.3 million, to one wallet.
The discussion was quickly joined by well-known Bitcoin developer Peter Todd, whom an HBO documentary previously identified as Bitcoin creator Satoshi Nakamoto. For Todd, the incident became yet another confirmation of his long-standing skepticism toward commercial crypto gadgets.
Wallet security depends entirely on randomness during seed phrase generation. However, as it turned out, this mechanism had not been functioning properly in Coldcard firmware since March 2021. According to Block Security, nearly all models are vulnerable: Mk2, Mk3, Mk4, Q and Mk5.
In older devices, an error in the codebase disabled the built-in hardware generator, causing the wallet to create keys through a predictable software algorithm. In newer models, critical portions of the data were truncated.
As a result, the number of possible secret phrase combinations fell to a minimum, allowing hackers to brute-force them on a computer within minutes.
Todd's position: The codebase lacks enough eyes
"I've always been skeptical of hardware wallets. You pay a lot of money for a device running code that few people will ever look at, on hardware that could be backdoored with a supply chain attack," Peter Todd said on X.
According to the developer, this incident is a perfect example of the fatal lack of independent scrutiny and auditing of the project's codebase.
The industry now needs to move toward end-to-end deterministic testing of real hardware, which would make it possible to know exactly where the entropy comes from. As an alternative to blindly trusting chips, Todd demonstrated a physical generation method using a deck of cards and recalled his earlier proposal for a button-based RNG.
It's reasonable to add a hardware wallet in a multisig configuration. But with singlesig, it is probably better to stick with well-audited software on commodity hardware.
— Peter Todd (@peterktodd) July 31, 2026
The new data from Block Security also undermines hopes that multisig setups remain safe. If all multisignature keys were generated on vulnerable Coldcard devices, hackers can compromise them one by one. The flaw is introduced at the moment the seed phrase is created, and simply exporting the words to another device does not fix it.
The only way to protect Bitcoin now is to fully evacuate the assets. Experts are urging users to immediately generate a new seed phrase on third-party hardware and physically transfer all funds to new addresses.
Only users who added an additional BIP-39 passphrase during the initial setup remain protected, as it creates another barrier against brute-force attacks.
coindesk.com
decrypt.co
bitcoinworld.co.in