Satoshi Candidate Peter Todd Warns No Bitcoin Is Safe on Singlesig After $38 Million Coldcard Drain

Fri, 31/07/2026 - 10:10
Bitcoin dev Peter Todd slams hardware wallet security after an entropy bug in Coldcard devices allowed hackers to brute-force and drain 594 BTC.
Advertisement
Satoshi Candidate Peter Todd Warns No Bitcoin Is Safe on Singlesig After $38 Million Coldcard Drain
Cover image via depositphotos.com

Disclaimer: The opinions expressed by our writers are their own and do not represent the views of U.Today. The financial and market information provided on U.Today is intended for informational purposes only. U.Today is not liable for any financial losses incurred while trading cryptocurrencies. Conduct your own research by contacting financial experts before making any investment decisions. We believe that all content is accurate as of the date of publication, but certain offers mentioned may no longer be available.

Google

The hardware crypto wallet market has been hit by a severe crisis of confidence as a technical flaw in Coldcard devices allowed hackers to completely drain more than 500 Bitcoin addresses. In a single automated attack, the perpetrators transferred 594.48 BTC, worth about $38.3 million, to one wallet.

Advertisement

The discussion was quickly joined by well-known Bitcoin developer Peter Todd, whom an HBO documentary previously identified as Bitcoin creator Satoshi Nakamoto. For Todd, the incident became yet another confirmation of his long-standing skepticism toward commercial crypto gadgets.

You Might Also Like
HOT Stories
Can XRP Overcome Pressure? Zcash (ZEC) Might Bounce to $500, Did Hyperliquid (HYPE) Lose Its Importance? Crypto Market Review Crypto Is for Crooks, Dem Senator Says

Wallet security depends entirely on randomness during seed phrase generation. However, as it turned out, this mechanism had not been functioning properly in Coldcard firmware since March 2021. According to Block Security, nearly all models are vulnerable: Mk2, Mk3, Mk4, Q and Mk5.

Advertisement

In older devices, an error in the codebase disabled the built-in hardware generator, causing the wallet to create keys through a predictable software algorithm. In newer models, critical portions of the data were truncated. 

As a result, the number of possible secret phrase combinations fell to a minimum, allowing hackers to brute-force them on a computer within minutes.

Todd's position: The codebase lacks enough eyes

"I've always been skeptical of hardware wallets. You pay a lot of money for a device running code that few people will ever look at, on hardware that could be backdoored with a supply chain attack," Peter Todd said on X.

Advertisement

According to the developer, this incident is a perfect example of the fatal lack of independent scrutiny and auditing of the project's codebase.

The industry now needs to move toward end-to-end deterministic testing of real hardware, which would make it possible to know exactly where the entropy comes from. As an alternative to blindly trusting chips, Todd demonstrated a physical generation method using a deck of cards and recalled his earlier proposal for a button-based RNG.

You Might Also Like

The new data from Block Security also undermines hopes that multisig setups remain safe. If all multisignature keys were generated on vulnerable Coldcard devices, hackers can compromise them one by one. The flaw is introduced at the moment the seed phrase is created, and simply exporting the words to another device does not fix it.

The only way to protect Bitcoin now is to fully evacuate the assets. Experts are urging users to immediately generate a new seed phrase on third-party hardware and physically transfer all funds to new addresses.

Only users who added an additional BIP-39 passphrase during the initial setup remain protected, as it creates another barrier against brute-force attacks.

Advertisement
Advertisement
Advertisement
Advertisement
Subscribe to daily newsletter

Recommended articles

Our social media
There's a lot to see there, too
Advertisement