A flaw in one of Bitcoin's most trusted hardware wallets quietly drained more than $100 million, and most holders still don't understand how it happened.
Coldcard, long considered the gold standard for serious Bitcoin self-custody, has been hit by an exploit rooted in something most users never think about: entropy. Specifically, how private keys are generated, how many truly random bits go into that process, and what happens when that randomness is weaker than advertised.
What Actually Broke
Private keys are only as secure as the randomness used to create them. When entropy is low, predictable, or subtly flawed, attackers can narrow the universe of possible keys and brute-force their way to your funds. That is not a theoretical attack. It is what happened here.
The Coldcard vulnerability exposed a weakness in key generation that made certain wallets far more predictable than users believed. Attackers who understood the flaw could systematically scan for affected keys. The result: over $100 million in Bitcoin moved without owner consent.
The Dice Roll Debate Just Got Loud Again
For years, paranoid Bitcoiners have added their own dice rolls to the key generation process, treating hardware randomness as a liability. The logic was always sound in theory. This exploit just made it urgent in practice.
But here is the uncomfortable truth the community is now wrestling with: dice rolls introduce their own risks. Human-generated entropy is often less random than people assume. Patterns creep in. Rolls get recorded incorrectly. The very tool meant to add security can compress the keyspace if used carelessly.
This is not a comfortable answer. It means there is no perfectly simple path to trustless key generation, and that reality is rattling confidence across the self-custody space.
Why Bits Matter More Than Most People Know
A private key needs 256 bits of genuine randomness to be secure. Shave that number down, even slightly, and the attack surface grows exponentially. The difference between 128 bits and 256 bits of entropy is not twice the security. It is 2 to the power of 128 times more difficult to crack. When that entropy is compromised at the hardware level, the math works brutally fast against the victim.
What Holders Should Do Right Now
If you generated keys on a Coldcard, especially older firmware versions, treat this as a five-alarm situation. Check Coldcard's official channels for affected firmware ranges, verify whether your wallet generation falls inside the vulnerable window, and consider moving funds to a freshly generated wallet using patched hardware.
The broader lesson is colder than any hardware wallet: in self-custody, the weakest link is rarely where you are looking. The $100 million lost here was not lost to a hack of Bitcoin itself. It was lost to misplaced trust in a number that was never as random as it appeared.
Watch this space. More wallets, more audits, and very possibly more losses are coming.