Is Any Cold Wallet Safe? Inside the Coldcard Hack's Wave Three

Watch on YouTube ↗  |  August 04, 2026 at 23:54  |  18:40  |  Unchained (Chopping Block)
Speakers
Austin Campbell — Founder, Zero Knowledge Group; Co-host Bits+Bips (Unchained); Adj. Prof. NYU Stern
Chris Perkins — President, CoinFund

Summary

Alex Thorn of Galaxy Digital details the Coldcard hardware wallet exploit, in which a firmware bug allowed attackers to drain over $100 million in Bitcoin from cold storage. The discussion covers the flawed random number generator, three confirmed attack waves, forensic tracing, and broader implications for self-custody, ETF safety, and future quantum and AI threats.

  • Coldcard wallets (Mark III and later) had a firmware bug that silently weakened key entropy starting March 2021.
  • Attackers exploited weak random number generation to derive private keys and sweep approximately 1,600–2,000 BTC.
  • Three distinct attack waves have been identified, with a possible fourth wave under investigation.
  • Victims were long-term holders with dormant coins, not speculative traders, making the hack especially devastating.
  • Alex Thorn is tracing attacker addresses on-chain and helping victims file reports with law enforcement and exchanges.
  • Eric Balchunas' claim that Bitcoin ETFs are safer than self-custody is discussed, with Alex noting the difference between bearer assets and registered securities.
  • Chris Perkins raises the concern that the exploit previews what quantum computing could do at scale.
  • AI is being used to audit hardware wallet codebases to find similar vulnerabilities before attackers do.
Up Next