What is Coldcard?
Coldcard is a Bitcoin hardware wallet whose security record came under scrutiny in 2026 after a long-undetected flaw in its firmware was exploited.
Release history
- Aug 2026 - Shin said a five-year-old bug was “wrecking everyone” and the team had no way to warn users to move their money.
- Aug 2026 - Shin said those affected were “in almost all cases” the dice rollers.
- Aug 2026 - Shin said pointing an analysis tool at the code base found the flaw in about 10 minutes.
In the discourse
Attributed discussion of Coldcard.
Coldcard. A five-year-old unaudited vulnerability in the hardware wallet allowed remote compromise. The no-user-data policy prevented post-discovery warnings, and losses are projected to grow for months or years.
“These guys didn't have a single security audit.”Laura Shin · 7 Aug 2026
Coldcard secured billions in Bitcoin without ever undergoing a single security audit.
“These guys didn't have a single security audit.”Laura Shin · 7 Aug 2026
Coldcard's privacy-first data-deletion policy, marketed as a security feature, became a critical liability. When a five-year-old vulnerability was found, the company had no user contact data to issue warnings and could not tell holders to move their funds.
“Now they have this 5-year-old bug that's wrecking everyone and they have no way to warn people to like move their money.”Laura Shin · 7 Aug 2026
Laura Shin on Coldcard's data-deletion policy backfiring when a critical vulnerability was found.
“Now they have this 5-year-old bug that's wrecking everyone and they have no way to warn people to like move their money.”Laura Shin · 7 Aug 2026
Early Coldcard hack victims were almost exclusively users who had used the dice-rolling entropy feature, inverting the assumption that dice entropy made wallets safer.
“In almost all cases those people were the dice rollers.”Laura Shin · 7 Aug 2026
Laura Shin on the Coldcard community failure: trusting ideological credentials instead of security evidence.
“I think it's also a failure of just like the community for trusting that these guys because they're such hardcore Bitcoiners or that they had it on lock and they did not at all have it on lock.”Laura Shin · 7 Aug 2026
A sandboxed AI agent pointed at the Coldcard codebase found the critical vulnerability in approximately 10 minutes.
“Even then when pointed at the code base someone was like, yeah, like stripped in a sandbox it took 10 minutes or something like that for it to find it.”Laura Shin · 7 Aug 2026
Over 1.5 million Bitcoin lost to hacks and frauds at centralized exchanges and CeFi lenders (Mt. Gox, Celsius, BlockFi, Voyager, QuadrigaCX), roughly 1,000x the coins lost in the Coldcard self-custody incident.
“Something like north of 1.5 million coins have been lost to hacks and frauds at centralized exchanges and you know, CFI lenders. So if you actually add up Gauss and Celsius and BlockFi and Voyager and on it quadrea and all the rest, it's over 1.5 million coins that have been lost. So it's a thousandx the number lost to these trusted third parties versus what was lost in this cold card incident.”Corey · 2 Sep 2026
Laura Shin on North Korea attribution being wrong for the Coldcard hack.
“North Korea just doesn't do these types of attacks.”Laura Shin · 7 Aug 2026