Is Bitcoin Safer on an Exchange? What the Coldcard Hack Actually Proved
On July 30, Bitcoin started disappearing from wallets that had never been connected to the internet. By August 4 the running total passed $130 million. Nobody was phished, no malware was installed, and no device was stolen. The wallets were sitting exactly where their owners left them.
Within days the incident had been turned into an argument. If cold storage can fail like this, the reasoning went, maybe leaving your coins on an exchange was the safer choice all along. That argument leans on a specific pair of numbers, and those numbers do not support the weight being put on them.
What actually broke
A hardware wallet protects your Bitcoin with a secret recovery phrase, and that phrase has to be built out of genuine randomness. If the randomness is real, the phrase cannot be guessed by anyone, ever, with any amount of computing power. The entire security model rests on that one assumption.
In March 2021, Coinkite shipped Coldcard firmware version 4.0.0. One line in it routed seed generation away from the device's dedicated hardware random number generator and into a software fallback, seeded with chip data that was not secret. The phrases those devices produced carried roughly 72 bits of randomness instead of the 128 bits a recovery phrase is supposed to have.
That gap sounds modest. It is not. It is the difference between a number nobody can ever guess and a number that a determined attacker can work through. Once researchers understood the flaw, private keys could be rebuilt offline and the coins swept straight off the blockchain.
Being offline was never the thing that failed. The device did its job of staying disconnected. The problem was that the phrase it handed you was weak from the moment it was created. An airgap protects a secret. It cannot protect a secret that was already guessable.
The bug sat there for five years before anyone noticed.
Which devices are affected
A lot of coverage reported that only the Mk3 was at risk. Coinkite's own advisory says otherwise, and if you own one of these it is worth reading the actual list rather than a summary of it.
- Mk2 and Mk3, firmware 4.0.1 through 4.1.9. Fixed in 4.2.0 or later.
- Mk4 and Mk5, anything before 5.6.0. Fixed in 5.6.0 or later.
- Q, anything before 1.5.0Q. Fixed in 1.5.0Q or later.
- Edge builds, before 6.6.0X on Mk4 and Mk5, or before 6.6.0QX on the Q.
- TAPSIGNER, OPENDIME and SATSCARD are not affected.
Two groups came through this untouched. Anyone who added 50 or more of their own private dice rolls during setup, because those rolls put real randomness back into the phrase. And most people running a strong, unique passphrase on top of their recovery phrase.
The detail that matters most, and the one most easily missed, is this. What counts is the firmware version your phrase was created on, not the version running on the device today. The weakness was baked into the phrase at birth. Updating the firmware does not repair a phrase that was already weak. If you are affected, you need a completely new seed and a migration to it. If you cannot remember which firmware you set the wallet up on, the safe assumption is that you are exposed.
The claim that exchanges are statistically safer
Shortly after the hack, an analyst posted two figures from River's 2025 custody report. The founder of Binance read them and concluded that storing coins on an exchange is statistically safer than holding them yourself.
- 1.57 million bitcoin permanently lost in self-custody
- 1.51 million bitcoin lost on exchanges
Two nearly identical numbers. If you stop reading there, self-custody looks no safer than an exchange, and possibly slightly worse. But the same report contains a third number that changes the meaning of the first two entirely.
98% of those losses happened before 2020
River's estimate is that 98% of the 1.57 million lost in self-custody was lost before 2020.
Those are not modern security failures. They are coins from an era when Bitcoin traded for pennies and nobody thought of a wallet file as money. Wiped drives. Discarded laptops. Passwords for accounts that were worth nothing at the time. That number is a story about 2011, and it says almost nothing about whether a hardware wallet you set up recently is safe.
The exchange column does not have that property. Losses there kept accumulating well after 2020. River records more than 100,000 bitcoin lost in 2022 alone at platforms offering yield products, plus roughly $2.6 billion lost to embezzlement at exchanges since 2020. One column largely stopped growing. The other did not.
The second problem: the two piles are not the same size
There is a further issue with setting those totals side by side, and it is the kind of mistake that turns up constantly in crypto arguments.
Most Bitcoin has always been held by people themselves. Self-custody covers far more coins, held across far more years, than anything sitting on an exchange. A much larger pile will lose more coins in absolute terms even if it is meaningfully safer per coin.
Comparing raw totals without accounting for how much was held each way, and for how long, is not a comparison. To make a real claim about which is safer you would need a rate, and neither side has published one.
What the other side gets right
It would be easy to stop here and declare the argument won. That would be dishonest, because the counter-argument contains a point that genuinely cuts against everything above.
Exchange hacks are loud. They make the news, they get investigated, they get counted. Losses in self-custody are quiet and personal, and most of them are never reported to anyone. The self-custody figure is therefore probably an undercount, and nobody can tell you by how much. That is a fair objection and it deserves to be stated plainly.
Two other points also hold up. A handful of collapsed exchanges drag the exchange column down disproportionately, and some exchanges have covered user losses out of their own funds after a hack. It is also worth noting that the actual conclusion offered was that a balanced approach is probably best, which is a good deal closer to the truth than the headline the post turned into.
Both columns are estimates. Both are probably low. That is the honest position.
Every method has exactly one way it dies
The whole debate was about which single basket is safest. The Coldcard failure is the clearest possible evidence that this is the wrong question to be asking.
One line of code, written in 2021, reached every owner of one brand at the same moment. It did not matter how carefully any of them had stored the device, how good their backups were, or how disciplined they had been. They shared a single point of failure and most of them had no idea it existed.
Every storage method has one. They are just different:
- On an exchange. Company failure, insider theft, a freeze or seizure, a hack. It does survive your own mistakes, fire, and a lost device.
- One hardware wallet. A firmware or supply-chain bug, a destroyed backup, theft, or you dying without leaving a plan. It survives an exchange collapsing.
- Two wallets from the same brand. The same firmware bug, hitting both at once. It survives one device breaking.
- Two wallets from different brands. Your own backup mistakes. It survives any single vendor's bug.
- Multisig with keys held separately. Losing track of the setup itself. It survives any one key being lost or stolen.
The last two rows never came up in the argument. They are not a compromise between the two positions. They are the answer to a better question.
What to actually do
None of this requires being technical. It requires refusing to let one thing hold everything.
- Split across at least two independent methods. Two of the same device from the same maker is one point of failure wearing a disguise.
- Add your own randomness when you generate a phrase. The dice-roll users walked away from this week untouched.
- Use a passphrase on top of your recovery phrase, and store it separately from the phrase.
- Test your backup by restoring it before you trust it with real money. An untested backup is a guess.
- Keep backups in separate physical places. Fire, flood and burglary are boring and they take far more coins than exploits do.
- Verify receive addresses on the device screen. Your computer can lie to you. The screen is the entire point of the device.
- Write down who gets access if something happens to you. A large share of that 1.57 million was never stolen. It was simply lost.
- Re-check when firmware updates land. This bug sat quietly for five years.
Spreading things out has a real cost. More backups to track, more setups to remember, more ways to confuse your future self a decade from now. That price is genuine and worth weighing honestly. Losing everything to a single bug is a larger one.
The bottom line
The people who came through this week intact were not the ones who picked the right brand. Plenty of careful, well-informed people owned the affected device. They were the ones who never let a single thing hold all of it.
Education, not financial advice.
Common questions
Is it safer to keep Bitcoin on an exchange or in self-custody?
Neither is universally safer, and the totals being quoted do not settle it. River's 2025 report shows 1.57 million bitcoin lost in self-custody against 1.51 million on exchanges, but 98% of the self-custody losses happened before 2020, while exchange losses continued afterward. Self-custody also covers far more coins over far more years, so its larger raw total comes off a much larger base.
What happened in the Coldcard hack?
Coldcard firmware 4.0.0, shipped in March 2021, routed seed generation to a software random number generator instead of the device's hardware one. Recovery phrases carried around 72 bits of randomness instead of 128, making them reconstructable. Attackers rebuilt private keys offline and swept the coins. Reported losses passed $130 million between July 30 and August 4, 2026.
Which Coldcard devices are affected?
Mk2 and Mk3 on firmware 4.0.1 through 4.1.9, Mk4 and Mk5 before version 5.6.0, and the Q before 1.5.0Q. Edge builds before 6.6.0X and 6.6.0QX are also affected. TAPSIGNER, OPENDIME and SATSCARD are not. What matters is the firmware version your phrase was created on, not the version installed today.
Does updating Coldcard firmware fix the vulnerability?
No. A recovery phrase that was guessable when it was generated stays guessable forever, regardless of later updates. If your phrase was created on affected firmware you need to generate an entirely new seed on patched firmware and migrate your funds to it, keeping the old backup until the move is confirmed.
What is the safest way to store Bitcoin?
Spread it across at least two independent methods rather than trusting any single one. The Coldcard exploit hit every owner of one brand simultaneously, which is the failure mode a single hardware wallet cannot protect against. Adding your own dice rolls when generating a phrase, using a passphrase, testing backups before funding them, and storing backups in separate locations all remove single points of failure.
Keep reading
We break down the market like this every day, free on Instagram and YouTube, and in depth inside the community.
Education, not financial advice. Trading involves real risk.