A Message From Our Sponsor … 🚀


GET IT RIGHT 🎯


Self-custody Is Still Right. But the Argument Just Got Harder.

A hardware wallet is supposed to be the safest place to keep Bitcoin. The device never connects to the internet. The private keys never leave it. The whole point is that an attacker would need to physically hold it to steal anything. This week, 15 different hackers proved that wrong without touching a single device.

The attacker never touched a device.
The Coldcard hack didn't break the case for holding your own Bitcoin. It exposed a risk that hardware wallet marketing has never been honest about.

Here is what actually happened. On March 1, 2021, a single line of code changed inside Coldcard's firmware. The wallet's seed generation — the process that creates the recovery phrase controlling your Bitcoin — was supposed to draw randomness from a hardware random number generator producing 128 bits of entropy. A number so large that guessing it is computationally impossible. Instead, a firmware error silently routed that process to a software-based generator producing roughly 40 bits of effective entropy. The difference between 128 bits and 40 bits is not marginal. It is the difference between uncrackable and reproducible.

For five years nobody noticed. Then somebody did.

What the attackers actually did

The elegance of the exploit is what makes it genuinely alarming. The attacker never touched a Coldcard device. Never intercepted a transaction. Never phished a password. They simply replicated the flawed seed generation process on their own computers — running through the limited search space until they found wallet addresses that matched real holdings. Four waves of attacks across five days. At least 15 separate actors once the vulnerability became public. Approximately $130 million drained from more than 5,200 addresses. The first wave took 41 minutes to sweep 1,196 wallets. The device sitting in your drawer, air-gapped and offline, was already compromised before you plugged it in.

Coinkite has confirmed the flaw, halted shipments of affected devices, and strongly advised users who generated wallet seeds on Coldcard firmware from March 2021 onward to move funds immediately using high transaction fees to prioritize their rescue transaction ahead of any attacker. If you have a Coldcard wallet, that guidance applies to you now. Not after this article.

The honest risk conversation hardware wallets never had

Self-custody is the right principle. That hasn't changed. What the Coldcard hack exposed is the risk gradient that hardware wallet marketing has historically obscured — and that the self-custody community has been reluctant to discuss clearly.

Keeping Bitcoin on an exchange eliminates counterparty risk from hardware failure, firmware bugs, supply-chain compromise, and phishing. It introduces counterparty risk from exchange insolvency, regulatory action, and custodial failure. Neither option is risk-free. The relevant question — the one the Coldcard hack forces into the open — is which risk profile matches your holdings, your technical sophistication, and your ability to execute emergency migrations under pressure.

For most retail holders with moderate positions, a combination of regulated custodians and ETF exposure provides meaningful security without the firmware vulnerability surface that self-custody introduces. For technically sophisticated holders with large positions and the operational discipline to manage multisig setups, self-custody remains the superior long-term framework. The mistake is treating either option as categorically safe — because nothing in this space is.

The Coldcard hack is not an argument against self-custody. It is an argument for honest risk accounting. The community that prides itself on doing its own research owes itself a clearer-eyed look at what holding your own keys actually requires.

While Everyone Was Watching the Hack, Solana Was Quietly Making History 🏦

The week's most underreported story had nothing to do with stolen Bitcoin. Solana's tokenized asset transfer volume hit $8.68 billion over a 30-day period — more than double the prior month — and the network now represents approximately 95 to 97% of all on-chain tokenized equity trading activity across every blockchain.

SpaceX shares alone generated $770 million in tokenized volume on Solana in June. The Alpenglow consensus upgrade — targeting transaction finality from 12.8 seconds down to 150 milliseconds — rolls out August through October. The network's fundamental story has never been stronger. Its token is still trading 70% off its January high. That gap between what Solana is doing and what SOL is priced at is the most interesting setup in crypto right now that nobody seems to be talking about.

41 Minutes

That's how long it took the first wave of Coldcard attackers to drain 1,196 Bitcoin wallets on July 30 — sweeping approximately $70 million before most holders even knew the vulnerability existed. The speed is the point. Because the seed generation flaw was deterministic and reproducible, attackers could pre-compute target addresses offline and execute the sweeps in coordinated bursts.

By the time the second and third waves hit, the total had climbed to $89 million. By August 4, with at least 15 separate attackers in the field, it crossed $130 million. The Coldcard hack is not just the largest hardware wallet breach in Bitcoin's history. It is a demonstration of how quickly a five-year-old silent flaw can become a coordinated mass theft once knowledge of it becomes public.

Three Things Worth Writing Down

  1. If you have a Coldcard wallet — act now: Move funds immediately to a freshly generated wallet using different hardware or a reputable exchange. Use high transaction fees to prioritize your rescue transaction. Updating firmware alone does not fix an existing compromised seed — the vulnerability exists in the seed itself, not the device's current software state. Coinkite's open letter confirms this.

  1. The multisig answer: The Coldcard exploit would not have worked against a properly configured multisig setup requiring multiple independent signing devices. If your Bitcoin holdings are significant enough to warrant self-custody, they are significant enough to warrant multisig. The incremental complexity is the point — it eliminates single points of failure exactly like the one Coldcard just exposed.

  2. Bitcoin ETF inflows surged as the hack spread: On August 4 — the same day hack losses crossed $130 million — US spot Bitcoin ETFs recorded $170 million in net inflows, with BlackRock's IBIT alone taking in $111 million. That is not a coincidence. Spooked self-custody holders moving to regulated custodians and ETF wrappers is the most direct real-world demonstration of the custody trade-off playing out in the market in real time.

Mark It.

  • If you have a Coldcard wallet — read this first:
    Block's engineering team published the most technically precise analysis of the firmware flaw available. It explains exactly which devices are affected, which firmware versions are vulnerable, and the steps to safely migrate funds. Essential reading before you do anything else: block.xyz/engineering → search "Coldcard firmware analysis."

  • The self-custody security framework worth bookmarking:
    Unchained Capital's multisig guide is the clearest plain-English explanation of collaborative custody and multisig architecture for Bitcoin holders who want self-custody without single points of failure. Free, thorough, and more relevant this week than it has ever been: unchained.com/bitcoin-security

COIN SPOTLIGHT 👛 

Bitcoin (BTC) The Custody Paradox

$170 million into ETFs on the same day $130 million was stolen from hardware wallets.

That parallel is not ironic. It is the Bitcoin custody debate resolving itself in real time through capital flows.

Bitcoin is trading at $64,271 — holding above its 200-week moving average, 63% correlated with the S&P 500, and consolidating in a range that has contained every major sell-off since June. The price action is not the story this week. The custody story is.

Two things are simultaneously true right now

Self-custody holders just suffered the largest hardware wallet breach in Bitcoin's history — $130 million across five days, 15 attackers, 5,200 addresses, a five-year-old firmware flaw that the community trusted and never verified. Meanwhile institutional custody just had one of its strongest inflow weeks of the year. BlackRock's IBIT pulled $111 million in a single session. Total spot ETF assets are climbing back toward $80 billion. The same week self-custody burned, institutional custody accelerated.

Neither of these data points proves the other wrong. Self-custody remains the philosophically correct answer for Bitcoin holders who want true sovereignty over their holdings — no counterparty, no custodian, no regulatory risk. The Coldcard hack does not change that principle. It changes the execution requirements. Properly implemented multisig self-custody using hardware from multiple independent manufacturers is more secure than any single hardware wallet and more secure than any exchange. The problem is that most self-custody holders are not running multisig. They are running a single device they trust — which is exactly the trust model the Coldcard hack exploited.

The honest Bitcoin setup heading into August

Support at $62,500 has held through legislative disappointment, a hawkish Fed hold, a $130 million security crisis, and 32,000 BTC moving onto exchanges in a single day. The fact that Bitcoin absorbed all of that and is sitting at $64,271 with positive ETF inflows is either a sign of extraordinary structural resilience or a sign that the market has not yet fully processed the macro headwinds building for September. Jackson Hole is coming. The Fed's September rate decision — currently priced at 57% odds of a hike — is coming. The CLARITY Act's September window is coming.

Bitcoin is holding. The question is whether it is building a base or borrowing time.

 Until next time ….

— Solid Right


GARAGE LOGIC

FINAL SPIN 🎬

A Message From Our Sponsor … 🚀