Newsroom

Peter Todd Warns Single-Signature Bitcoin Wallets Exposed After Coldcard Vulnerability Linked to $38 Million Theft

31 July, 2026   /   News   /  AI   /  466 reads   /   Tags:  hardware, todd, coldcard, seed, flaws

Peter Todd Warns Single-Signature Bitcoin Wallets Exposed After Coldcard Vulnerability Linked to $38 Million Theft

Bitcoin developer Peter Todd raises alarm over Coldcard hardware wallet flaws after researchers tied them to the transfer of 594.48 BTC worth about $38.3 million, urging users to abandon affected single-signature setups

Bitcoin developer Peter Todd has issued a stark warning that no Bitcoin held in single-signature wallets can be considered fully safe following the exposure of critical flaws in Coldcard hardware wallets. The comments come after security researchers connected the vulnerabilities to an automated attack that moved 594.48 BTC, valued at approximately $38.3 million, into a single destination wallet.

The flaws, identified by Block Security, have been present in Coldcard firmware since March 2021 and affect multiple models, including the Mk2, Mk3, Mk4, Q and Mk5. Todd, a long-time Bitcoin contributor previously named as a candidate for the identity of Satoshi Nakamoto in an HBO documentary, described the episode as confirmation of his ongoing doubts about commercial hardware wallets.

I've always been skeptical of hardware wallets. You pay a lot of money for a device running code that few people will ever look at, on hardware that could be backdoored with a supply chain attack.
Peter Todd

How the Seed Generation Failures Worked

Wallet security rests on the quality of randomness used when creating recovery seed phrases. In older Coldcard devices, a software error disabled the built-in hardware random number generator. As a result, the devices produced seeds through a predictable software process rather than genuine hardware entropy.

Newer models suffered a different problem: they truncated critical portions of entropy during seed generation. This sharply reduced the number of possible recovery phrase combinations, making the wallets susceptible to brute-force attacks that could succeed with ordinary computing power in a short time.

Block Security reported that the attack exploited these weaknesses across a large set of addresses. The researchers stressed that the problem originates at the moment of seed creation. Simply exporting an existing recovery phrase to a different device does not eliminate the underlying weakness.

Implications for Multisignature Setups and User Response

The findings also undercut the assumption that multisignature wallets automatically provide protection. If every signing key in a multisig arrangement was generated on a vulnerable Coldcard device, an attacker can still compromise the setup by targeting the individual seeds one after another.

Security researchers and Todd advised affected users to generate entirely new seed phrases on hardware that is not subject to these flaws and then move funds to fresh addresses. Exporting the old recovery words is insufficient. The sole exception involves users who added a BIP-39 passphrase when the original wallet was created; that extra layer substantially raises the difficulty of a successful brute-force attempt.

Todd called for the industry to adopt end-to-end deterministic testing of physical hardware so that developers can verify the true source of entropy rather than assume the chips function correctly. He demonstrated one alternative approach by generating a seed manually with a deck of cards and pointed back to an earlier proposal for a simple button-based random number generator.

Broader Concerns Over Hardware Wallet Trust

The episode has intensified longstanding questions about the degree of independent scrutiny applied to commercial hardware wallet codebases and the supply-chain risks inherent in relying on specialized devices. Todd argued that users are effectively placing significant trust in software and hardware that receive far less external review than the broader Bitcoin protocol itself.

Block Security’s analysis indicates the vulnerabilities span nearly the full range of recent Coldcard models. Users who continue to rely on single-signature configurations generated on those devices remain exposed until they complete a full migration to new, independently generated seeds on unaffected equipment.

The combined disclosures from the security researchers and Todd’s public comments have focused attention on the foundational process of seed generation and the practical limits of current hardware wallet designs in protecting Bitcoin holdings.

Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.