A Shaken Industry
Bitcoiners at large are experiencing deep feelings of betrayal, guilt, and grief, and it has changed our industry forever.
G’day Folks,
As a Bitcoiner, I can’t recall an event that has shaken the industry in quite the same way as the Coldcard exploit that is still unfolding this week.
PSA: If you have any Bitcoin secured by a Coldcard hardware wallet, you may be at risk of losing your funds. Please read and action this post immediately.
Please also watch this WBD podcast with Rob Hamilton (who is a saint).
Over the last few days, I have tried to help as many people as I could step through the technical and even emotional journey of urgently migrating their cold storage. I have also unfortunately heard of some heartbreaking stories of folks who have lost funds. To those friends amongst us, I am truly sorry. We all are.
I know I have personally felt everything from fear, to sadness, to anger, and even a degree of guilt and embarrassment as the mess unfurled over the weekend.
I also know a great many of us in the Bitcoin space feel the same way.
There is an overwhelming sense of collective betrayal and grief that this shocking event leaves in its wake.
Today’s post is my attempt to reason through all of these emotions, with an objective to understand them better, and to bounce back quicker.
I’ll also try to reflect on some of the constructive outcomes and lessons that may arise from this event. The history of engineering is littered with catastrophic events, but our response to those events is precisely why much of the engineered world is so safe today.
Disclaimer: This article is general in nature and is for informational and entertainment purposes only, and it shall not be relied upon for any investment or financial decisions.
Full Video Version
An Emotional Roller-coaster
The only Bitcoin-related event where I was left with an equivalently large pit in my stomach was when FTX collapsed in Nov-2022. I was not an active customer of FTX, and I avoided this Coldcard exploit for a variety of factors.
Nevertheless, I can deeply empathise with the fear, and realisation that my life savings may have just been stolen out from under me.
What makes this particular exploit so gut-wrenching is that it has hit people who did everything right. They used a hardware wallet, kept their seed offline, didn’t leave their funds on exchanges, and stacked spot Bitcoin into cold storage.
They followed the not your keys, not your coins mantra, only to fall victim to an even deeper betrayal.
This has been how many of us have stacked a decent chunk of our life savings for several years. I had many moments of pause this weekend where I imagined all the years of hard work it took to earn those coins getting ripped away from me.
I feel betrayed.
I feel grief.
I even feel guilty.
I have experienced many powerful negative feelings over the last 48 hours, and I want to unpack a few of them in the hopes that it resonates with readers to contextualise similar feelings.
Betrayal
I have been an active user of Coldcard hardware for many years, including over the course of this weekend. It has been an integral part of my wallet setup for many years, and I would easily classify myself as a Coldcard power user.
What I liked the most about the device was the tools it provided, from dice rolls at seed generation, to passphrases, and the derivation of child seeds.
Whenever I provided a wedding gift of Bitcoin, I would use these tools since I knew the recipients were quite likely to lose the seed. I would be their Uncle Check just in case.
When a friend or family member asked me which hardware wallet to use, I always defaulted to Ledger first for the simplicity, but then to a Coldcard if they were semi-technical and were starting to go deeper down the Bitcoin rabbit hole.
Fortunately, those who ended up with a Coldcard on my direct advice also utilised the passphrase feature I suggested. We safely migrated their funds away as a result.
I’ve even been a soft proponent of Coinkite products, and many subscribers will recall me saying things like this routinely in videos:
Eventually, these coins find a coldcard owned by a HODLer…
The price is dead on $X according to my blockclock
If this [unlikely event] happens, I’ll eat my coldcard
For this, I am deeply sorry.
I too trusted this device with my own, and my friends’ savings.
For many years, my Coldcard based custody setup has been a comforting anchor in the back of my mind. A tool that I trusted to look after a large chunk of my historical proof-of-work. The chain attached to that anchor has now snapped, and it is very uncomfortable.
I feel betrayed by something I trusted very deeply.
Everyone who has been directly or indirectly affected by this event is right to feel betrayed. That betrayal can absolutely be directed at Coinkite, but also towards the person who recommended the product, and even at the Bitcoin industry itself for not catching it sooner.
Betrayal is a very strong feeling, and it leaves us in a relatively vulnerable and uncertain state.
I am very proud to watch the tireless efforts of many raising awareness, providing support, and helping people navigate this stressful situation.
Once again, if you need help, please contact me, and I promise to do my very best to assist you (technically, emotionally or otherwise).
Guilt
There are many reasons people will be experiencing feelings of guilt across the industry, including myself.
In my case, I feel guilty over having been both a soft and hard proponent of the Coldcard for several years. I’ve both recommended it to a handful of friends, but also spoken about it positively and (usually) in passing on podcasts and my reports.
It’s important to recognise that there is a lot of nuance underlying this feeling. I come from a class of Bitcoiners who grew up in 2018-19, and I first learned about the Coldcard listening to Marty and Matt riffing on the Rabbit Hole Recap podcast.
The Coldcard seed generation back in 2019 was, in fact, cryptographically sound (this bug was introduced in March 2021).
At the time, I followed the advice to roll dice for additional entropy, and to use passphrases, but even if I hadn’t, my seed was ultimately generated in a sufficiently random way.
Further to this, the first Mk1 version of the Coldcard was released in Dec 2017 and had more Lindy effect in Bitcoin than I do. It has been around longer than I have, and in my specific circumstance it did what it was supposed to do.
That the firm was set to introduce a catastrophic bug in March 2021 is something nobody could have anticipated. Coinkite was a prolific sponsor of Bitcoin podcasts, and many people are currently dragging the hosts through the mud of shame this week as a result.
There is no defence for Coinkite’s actions.
I do feel very bad for the podcast hosts who were sponsored by them.
There is a degree of responsibility that comes with accepting sponsorships, and taking them was a business decision we at Checkonchain specifically rejected from day one. Podcast hosts who were sponsored by Coinkite must necessarily carry some degree of responsibility for that decision. With that said, I also feel that they, like I, could never have audited the code or anticipated this vulnerability.
Coldcard had a Lindy effect that pre-dated many of us. In the world of cryptography, that implies a level of resilience, which is often viewed as a stress test in its own right.
Coldcards were trusted because when we grew up, it used to be trustworthy.
Old-timers like me adopted the device when it actually did what it was supposed to do. Our basis of knowledge (and thus recommendation) was formed on an entirely different product than the one shipped with faulty firmware after March 2021.
Sponsored podcast hosts will be feeling a tremendous amount of guilt at this stage.
I also think we should recognise that many of us would have made the very same mistake if we were put into their shoes.
Reflection and responsibility must be taken. However, I’d suggest we please keep some of these historical and human elements in mind when judging the situation.
This is also the first time in my Bitcoin journey when I truly felt like a grizzled Bitcoin veteran. I’ve seen countless exchange hacks, crypto rug-pulls, lender bankruptcies, outright frauds, and wallet drains in my time. I have fortunately avoided almost all of them (I’ve lost a few coins here and there, but nothing substantial).
I still feel deeply saddened hearing the stories of people who have lost funds in this exploit. I cannot imagine how heartbreaking it must be to see years of hard work and savings lost this way.
The hard part is that this mess will be net a deflationary event for the number of Bitcoin holders, especially in self-custody:
Folks who lost funds will struggle to trust Bitcoin in the future, and it’s a very tall order to start rebuilding your stack after something like this.
People who recommended Coldcards will feel guilt and shame. I suspect many will be so jaded by this that they may back away from the industry entirely, and certainly won’t be recommending self-custody as readily.
Self-custody has taken a major step back because even people who did everything right became victims. I can’t imagine the damage if this had occurred in a larger hardware wallet like Ledger or Trezor, it could very well have been end-times bad.
Even the people who have avoided this specific failure scenario realise that it could have been them, and that a major injustice has occurred. Hindsight shows that surviving multiple years in Bitcoin has not been easy.
The best we can do at this stage is actively make people aware of the exploit, and do our very best to help them migrate funds as quickly as possible. After that, we must reflect, learn the hard lessons, and start the process of rebuilding the trust which has been lost.
Grief
In my opinion, this is the most important emotional state that is rippling across the Bitcoin industry.
Collectively, we are currently experiencing a traumatic event.
I’d wager everyone reading this has gone through a very stressful couple of days, checking their wallet balance, fearful that they might be next. Having to make any changes to our cold storage setup is an ordeal in itself, let alone under urgent emergency circumstances.
Every single one of us can sympathise with folks who have lost their savings, and have perhaps imagined that state of mind for themselves too.
We’re feeling a collective sense of sadness and grief for the loss of others.
The result is that many people have stood up and offered their hand in help. Bitcoiners have rushed to the scene to help triage the situation with awareness campaigns, profiling the risks, and actively stepping people through fund migrations.
This event has even crossed existing social schisms, where folks who disliked each other just days ago are rallying to solve the immediate problem.
By way of example, I had a call with Danny Knowles this morning, and he mentioned that he put out this tweet elevating Rob Hamilton, PortlandHODL and Wicked Smart Bitcoin for their tireless efforts. All three are notable opponents of BIP110, and yet Danny said countless folks with ‘BIP110’ in their X handle are liking and retweeting it.
Even folks who vehemently disagreed on key issues three days ago realise the gravity of this situation, and are all hands on deck.
By the end of this horrible saga, I suspect we will all look around and realise there isn’t much worth bickering over in comparison to risks like this one.
It’s a little bit like Bitcoin’s ‘fourth turning’, where the already exhausted bear market sentiment takes a final crushing blow with a major break of trust. Afterwards, we don’t have the energy or desire to keep fighting, and instead want to focus on a more positive outlook.
SBF broke the back of trust in 2022.
Coinkite has followed suit in 2026.
The crisis phase of the fourth turning is eventually followed by the more stable ‘white picket fence’ era of the first turning.
Without a doubt, this event is a negative setback on many levels.
However, forest fires also make way for fresh grass to grow.
Lasting Lessons
One of my friends that I helped migrate at-risk funds works in the aviation industry, and he offered a sobering lens for this event.
The airline disasters of the past are the reason flying is so safe today.
Engineering is replete with similar examples. The disasters themselves are a tragedy for everyone involved. In the years that follow, the industry learns lessons and adapts so that similar failures do not happen again.
There are several areas where I believe we have an opportunity to create lasting constructive changes from this particular event:
Thorough review of industry security: Naturally, the first lesson will be hardening the security of the entire industry. Frontier AI models have a role in both the attackers’ and the defenders’ toolkits, and this will only accelerate into the future.
Self-custody stress test: Everyone who is aware of this exploit has double-checked their self-custody setup, and many will update or change how they hold their Bitcoin entirely. Robust multi-signature and multi-party custody will become the default self-custody recommendation. Others will migrate towards custody providers and ETFs, and for many people, this is in fact the better solution for them.
Quantum resistance: In many ways, this Coldcard incident is a microcosm of what a genuine Q-day threat would look like. We are lucky that Coldcard was a small boutique piece of hardware that most in the wider crypto industry have never heard of. I believe even folks who are quantum sceptical will admit that long-term reliance on a single ECC signature scheme isn’t going to last hundreds of years. None of us wants to do this on a network-wide scale, and advancing quantum-resistant cryptography likely has fewer barriers now.
A general ‘unsticking’ of Bitcoin development: Many have commented on the stagnation of Bitcoin development in recent years.
The Great Consensus Cleanup (BIP-54): This soft fork proposal is for a set of four well-known and documented bugs that exist in Bitcoin’s consensus code. Given the role that frontier AI models had in this exploit, our tolerance for retaining known security holes must be tightened, and this is one of many proposals that likely has an easier path to reaching rough consensus.
Renewed appreciation of covenants: Covenants are a technology that enables greater control over Bitcoin spending paths. A coin could have a spending restriction enforced such that it can only be spent to a destination address as a first hop (a middle ground held by the owner), or all spends are delayed by N blocks unless an override key is presented. In these instances, an attacker with the victim’s seed could not sweep an entire wallet, and the owner would have fail-safes in place to buy them time.
This list is far from comprehensive, but I think it illustrates a few areas where the Bitcoin industry will strengthen in the years ahead.
The darkest days we collectively experience are often the source of the hardest and most impactful lessons we learn.
Today, we are going through and reeling from this event, and there is still much triage work left to be done.
Tomorrow, we collectively start the hard work of ensuring something like this never ever happens again.
Concluding Thoughts
Bitcoin has taught all of us many powerful lessons.
Not only about how the world and financial markets operate, but about ourselves.
A wise man once said, ‘HODLing Bitcoin is very simple, but it sure isn’t easy’.
I know that we all feel that today.
For everyone who has been directly affected by this exploit, please know that we all feel tremendously heavy hearts for you, and we are sorry this has happened.
You’re not alone, and I think you’d struggle to find someone reading this who isn’t willing to help you at a moment’s notice.
From us at Checkonchain, our inbox is wide open, and we will make every effort possible to help however we can.
After we work through the triage phase of this mess, we move on to the rebuilding and restructuring of an industry that has been through failures of a similar magnitude many times before.
Bootstrapping a monetary network like Bitcoin has always had all odds stacked against it. Yet time after time, the people supporting it build back stronger and even more resilient.
Watching the industry band together, despite our differences, has been an incredible thing to watch play out.
We all have a role to play, and many hands make for lighter work.
I myself am also here to help anyone who needs it.
I’m proud of us, even in a very dark hour.
Thanks for reading,
James




I have an issue with calling it a “hack” or an “exploit”. It was a catastrophic defect that their devices had from March 2021 onwards.
Incompetence on the highest level possible for a hww maker, and with hubris too.