You had one job. That, no doubt, is what Coldcard customers are thinking about the company now. If you’re not familiar, Coldcard makes devices to store crypto in an offline wallet—and is now notorious for a security lapse that let thieves plunder at least $100 million of Bitcoin from unsuspecting customers. Most times, news of a crypto hack is met with a “well, that’s what happens” shrug, but this one stands out because it affects a group of security-conscious Bitcoin owners who did everything right. Or so they thought.
Ordinarily, hardware wallets like Coldcard provide top-notch security, since they store crypto offline, and a wallet owner is the only one who knows the seed phrase that will unlock it. This should make the wallets virtually unhackable. Unfortunately, the company behind Coldcard made a colossal screw-up by failing to provide a randomized process for creating seed phrases. Instead, that process was based on a predictable pattern, allowing hackers who possessed a sample seed phrase to use trial-and-error to guess others—and clean out Coldcard owners in the process. (You can read a full technical breakdown here.)
The question is how much this hack matters. On one hand, you can say it doesn’t matter much since, compared to Ledger or Trezor, Coldcard is an obscure brand that accounts for less than 2% of the hardware wallet market. And while the hack is a devastating event for those who got robbed, the episode affected only a relative handful of Bitcoin owners, which is likely why the broader crypto market barely moved.
On a symbolic level, though, the Coldcard breach matters a lot. That’s because the vast majority of hacks you read about involve insecure technology like bridges, or befall people slinging weird alt-coins on some platform they shouldn’t have messed with in the first place. This hack was different. The victims in this case were OG Bitcoiners who understood the technology and who kept their stash in cold storage. They behaved like true Satoshi disciples and got mugged nonetheless.
This is why some are viewing the Coldcard debacle not as just another security incident, but as something closer to a crisis of faith. The sentiment is understandable, but also overblown. The Coldcard hack didn’t occur because of any failure in Bitcoin, but because of the negligence of a single manufacturer who had one job and didn’t do it.
And for better or worse, the incident points to an awkward truth: Keeping your coins in an offline hardware wallet stays true to the spirit of Bitcoin, but it is also a nuisance. I love the idea of self-custody and have tinkered with hardware wallets in the past. But I found it’s just easier to rely on a reputable exchange to hold my very modest stash of crypto. Many of you likely feel the same. If the day comes when our political and economic system takes a dramatic turn for the worse, I’ll likely put some Bitcoin on a physical device—after I make sure the device maker is up to the job.
Jeff John Roberts
jeff.roberts@fortune.com
@jeffjohnroberts
DECENTRALIZED NEWS
The Trump media company that owns Truth Social is calling off deals with Crypto.com related to prediction markets and a proposed DAT for Crypto’s tokens (Axios)
Dinari, a startup founded by Apple and Stripe alums, is partnering with Circle to offer tokenized versions of every stock on the S&P 500 (Fortune)
A new exposé reveals how a dodgy Chinese national with a string of failed ventures bought $100 million of Trump WLFI tokens despite obvious KYC concerns (NYT)
The DOJ accused an NFT startup founder of blowing $10M of his investors' money on a Miami condo and his DJ habit (Fortune)
A rebel faction of Bitcoin developers finally launched an "anti-spam" soft fork, but their rival chain sputtered out after only two blocks (Decrypt)
MEME O' THE MOMENT
Another take on the Coldcard hack: