A hardware wallet exploit tied to faulty random number generation has cost Coldcard users more than 1,596 Bitcoin — roughly $130 million at current prices — across three confirmed attack waves and 14 smaller incidents. Thousands of addresses were compromised. Yet Korean Bitcoiners, many of whom were early adopters of the device, suffered virtually no direct losses. The divergence highlights a cultural gap in how different communities approach the 'not trust, verify' ethos.
How the bug worked
The vulnerability stemmed from Coldcard's internal random number generator in certain devices. Attackers exploited the weak entropy to derive private keys, sweeping funds in at least three distinct waves. A potential fourth wave remains unconfirmed but is being watched. Coldcard responded by destroying remaining vulnerable inventory and urging all users to generate fresh seeds immediately.
Why Korean users dodged the bug
Korean community leaders had long advocated generating seed phrases and entropy independently — using physical dice or coin flips rather than relying on the vendor's internal randomness. Their recommended method: flip a coin 128 or 256 times for a 12- or 24-word seed, convert the binary to decimal with a hardware calculator (not a phone), cross-reference printed BIP39 word lists, and use an air-gapped tool like SeedSigner solely for checksum calculation. That practice, baked into local Bitcoin culture, made the Coldcard RNG flaw largely irrelevant for Korean users.
Analyst Koji Higashi attributed the resilience to structural strengths in community self-custody practices rather than individual skill. "It's not that Korean users are smarter," he said. "The community built systems that assume the hardware might be compromised."
English-speaking communities hit harder
English-speaking users fared worse, in part because many relied on influencers for setup advice — some of whom had sponsorships or ties to Coldcard maker Coinkite. The core lesson, according to post-mortem discussions, is that Bitcoin's 'not trust, verify' principle should apply to information sources, not just code. Trusting a single influencer or vendor recommendation without independent verification proved costly.
What comes next
Coldcard has destroyed its remaining vulnerable inventory, but the question of whether a fourth wave of victims exists remains open. For now, the incident stands as a stark reminder that self-custody isn't just about holding your own keys — it's about how you generate them in the first place.




