1,800 BTC stolen from self-custody. Takeaways from the Coldcard hack.

On July 30, an attack began on people holding their bitcoin in self-custody using Coldcard hardware wallets. More than 1,816 bitcoin have been stolen from over 7,000 addresses, according to Galaxy Research.

This is a saddening event for the Bitcoin community. But like all such episodes, it’s worth reflecting on what happened and how we can learn and improve in the future.

Coinkite is a bitcoin-only hardware wallet manufacturer founded in 2012. Their product, Coldcard wallets, have been widely recommended by influential Bitcoiners for years. Coldcards were a popular choice for self-custody among Bitcoiners because of their security-first reputation and open-source software. 

The most important job of hardware wallets

A hardware wallet is a device that generates and stores a private and public key. In theory, the private key is accessible only to you, allowing you to securely hold your bitcoin without any counterparty risk to an exchange or third-party custodian.

A bitcoin private key is 256 bits long (equivalent to 43 password characters). If generated with true randomness, it is practically impossible for anyone to guess what your private key is. This is the power of cryptography.

You can generate your own private key by flipping a coin 256 times, or by rolling dice. Hardware wallets use random number generators inside their firmware.

But if the way you generate a private key isn’t truly random, other people can guess what your private key is. Imagine if you made a private key by flipping a weighted coin that always fell on heads; it would be quite easy for someone to access your bitcoin.

Where Coldcard wallets fell short

This was the issue with Coldcard wallets. Since 2021, wallets used a random number generator with very low randomness. As a result, every seed generated on the affected firmware was at risk of being guessed.

On July 30, attackers began draining Coldcard wallets. Hundreds, perhaps thousands, of Coldcard users who seemingly followed the best practices for bitcoin self-custody had their funds stolen. 

The Coldcard vulnerability does not affect the Bitcoin protocol or anything related to how Bitcoin works. The vast majority of bitcoin users are unaffected, and the network continues to function normally. In fact, bitcoin’s price has remained flat over the past few weeks, indicating that the market does not view the event as damaging to bitcoin’s value proposition.

Two lessons from this event:

  • While self-custody can eliminate counterparty risk with exchanges and custodians, Bitcoiners still face third-party risks if they rely on wallet manufacturers or other intermediaries.
  • Cold storage is not inherently secure. Your self-custody setup can be completely air-gapped from the internet, safe from malware and phishing attacks, but can still be vulnerable to theft depending on the hardware you use.

At River, we actively encourage the use of self-custody. However, self-custody should be practiced with care, and is not for everyone. That is why we’ve built a platform with a security-first mindset from day one. For clients who prefer to keep their bitcoin with an exchange, our mission is to provide them with the safest possible experience.

However you choose to custody your bitcoin, we encourage you to learn how to do it safely. We recommend starting with our research on bitcoin custody options and best practices.

Stay up to date on Bitcoin through River's newsletter

Discover more from River

Subscribe now to keep reading and get access to the full archive.

Continue reading