Hackers drained nearly $70 million in bitcoin from Coldcard cold wallets in a 41-minute breach on July 29, exploiting a seed-generation vulnerability originating in 2021. The attack highlights critical risks in cryptocurrency self-custody as total losses across targeted wallets climb past the previously mentioned seventy million, with additional funds stolen in recent days.
Cold storage devices are built to function as digital vaults. Disconnected entirely from the internet, these hardware tools shield private keys from remote exploitation, making them the preferred security standard for individuals, businesses, and governments managing digital assets.
That design assumption collapsed on July 29, when an architectural flaw in Coldcard devices was exploited to empty thousands of wallets in less than an hour. The breach bypassed malware, phishing, and physical device access entirely, striking directly at the cryptographic foundation of hardware autocustody.
How a 2021 Seed Generation Flaw Enabled the Attack
When users initialize a cold wallet, the device generates a master key known as a seed phrase, consisting of a randomized sequence of 12 to 24 words. From this root code, mathematical algorithms derive every private key required to authorize transactions on the blockchain.

The root cause of the breach dates back to 2021. According to analysis from CheckSig, certain devices generated seed phrases using a routine that was far more predictable and contained a smaller combination pool than intended. Attackers deployed standard desktop computers to cycle through the predictable combinations until they matched active wallets.
Ferdinando Ametrano, CEO of CheckSig, stated via Elpais that these keys originate from a seed.
Once the seed combinations were cracked, the intruders drained the associated addresses without needing interaction from the owners. Data compiled by Galaxy Research shows that the initial 41-minute wave netted roughly $70 million (60.8 million euros) in bitcoin, while subsequent attacks over the following days pushed total losses higher across compromised wallets.
Inside a High-Value Target’s Account
Canadian investor Jonathan Goodman discovered the breach after Coinkite warned customers about the security incident. Even though his hardware device remained locked safely inside a bank safety deposit box, his funds were not spared.

Jonathan Goodman, investor, noted via Elpais that he saw lines of red transactions, meaning fund withdrawals.
Goodman lost $1.6 million in bitcoin during a seven-minute window. Blockchain intelligence firm Chainalysis noted that the hackers deliberately targeted high-value portfolios, executing transactions so rapidly that $30 million was siphoned within the first 10 minutes of the operation.
Jonathan Goodman, investor, explained via Elpais that between 21:36 and 21:43 on July 29, his three wallets were completely emptied.
Investigators point out that this methodical prioritization indicates the attackers mapped and studied their targets long before executing the seed extraction.
The Limits and Risks of Cryptocurrency Autocustody
The Coldcard incident has reignited industry debate over the practical realities of managing digital wealth independently. While autocustody eliminates third-party counterparty risk—such as exchange insolvency—it places the entirety of operational and technical risk onto the individual user.
Anthony J. Pompliano, CEO of ProCap Financial, noted that while sovereign control over assets remains a fundamental right, the technical hurdles involved mean self-custody is not suitable for every market participant.
Anthony J. Pompliano, CEO of ProCap Financial, affirmed via Elpais that he believes in the right of every individual to exercise sovereignty over their assets.
Echoing that assessment, Ari Redbord, global head of policy at TRM Labs, observed that autocustody shifts systemic danger rather than erasing it.
What Security Experts and Users Must Watch Next
Keep reading
