Doing Our Duty at The Bitcoin Way

In this article:
By the evening of Thursday, July 30th, the Coldcard story was moving faster than the facts.
Rumors were spreading across X. People were piling into Spaces, comparing transactions, firmware versions, and the community was in panic. Bitcoin had already started disappearing from wallets that had sat untouched for years, but nobody yet had a clean picture of why. Nobody knew how many people were exposed, which devices were vulnerable, or where the problem stopped. Every new post seemed to answer one question and create three more.

If you were using a Coldcard, the uncertainty was brutal. You could look at a wallet that had been perfectly fine that morning and suddenly wonder whether the seed protecting your bitcoin had been compromised years earlier without anyone knowing. Should you move immediately? Was moving itself dangerous? Was this an Mk3 problem, or were Mk4s and Qs exposed too? And while everyone tried to work it out in public, the attacker wasn’t waiting.
At around 11pm, we held an emergency call. We didn’t have perfect information either. What we did know was that some of you we had helped set up over the previous several years could be affected, including people we hadn’t needed to speak to since 2023. Waiting until every technical detail was settled might have made the situation easier to explain, but it could also have meant waiting while somebody else discovered the answer by emptying more wallets.

So we made the call to act. We would contact everyone potentially affected, assume the blast radius could be wider than we currently understood, and help you move your funds where necessary. The next six days were all hands on deck. Sales calls stopped. Normal projects were shelved. Founders, technicians, sales staff and marketers were pulled into the response as thousands of messages arrived and hundreds of you needed individual help. Phones kept ringing, Signal kept lighting up, and new information meant the situation kept evolving. There wasn’t much sleep involved, and there certainly wasn’t much business as usual.
The scramble of those six days is only half the story. The other half began long before anyone knew there was a vulnerability, with a decision that ensured none of our clients lost any funds.
The Decision We Made Years Earlier
Every setup we had built included a passphrase alongside the seed generated by the hardware wallet. It added another secret that didn’t come from Coldcard’s compromised seed-generation process, which meant the security of your wallet wasn’t resting entirely on the randomness produced inside one device.
For years, that probably seemed like a fairly unremarkable precaution. Some of you may even remember us insisting on it when an easier setup would have been perfectly tempting. Security has an irritating habit of making redundancy look excessive right up until the component you were worried about actually fails. Coldcard provided the demonstration.

Once researchers began tracing the thefts back to weak seed generation, the distinction became very real. An attacker who could reproduce or brute-force an affected seed still needed the independent passphrase to reach the wallet we had helped you create. That gave everyone using our setups an additional barrier while the rest of the industry was still trying to understand exactly what had happened.
It wasn’t a magic shield, and we didn’t treat it as one. Passphrases vary in strength, the full blast radius was still unclear, and there was no sensible reason to leave your bitcoin sitting on a seed we now had reason to distrust. We therefore advised potentially affected users to move funds and began helping you do exactly that.

So far, we have zero reports of anyone we helped set up losing funds in the incident. We’re enormously grateful for that. At the same time, we are deeply saddened that many people who trusted their Coldcard exclusively, lost their funds. It would be unfair to label this as “user error” on their part and move on. These people put their faith in a brand that was exalted as best in class by the whole industry, and were diligent about securing their wealth. They were badly let down by both the manufacturer and those who suggested that a Coldcard alone provides enough security.
The lesson to be learned from this incident is that relying on a single component is a gamble, and with the right approach, is a risk that can be avoided.
Then Everyone Stopped Doing Their Normal Job
The decision we made years earlier gave us something valuable when the vulnerability surfaced: time, and another layer of protection. What it didn’t give us was certainty. We still had hundreds of people to reach, an evolving threat to understand, and no reason to assume the attacker was finished.
Our sales calendar was closed and the team stopped taking new sales calls. People who would normally spend their day speaking to prospective customers were instead answering messages, helping organise emergency calls and, where they were trained to do so, assisting with withdrawals. Marketing shifted into communications. Projects were put on hold. All three founders joined the response, including helping people move funds themselves. The tech team, unsurprisingly, had rather more on its plate than usual.

Some of you had worked with us recently. Others had set up their Bitcoin with us years earlier and barely needed to speak to us since. Suddenly we were trying to reconnect with more than a thousand people, work out who was potentially exposed, establish who had already moved, who was safe, who needed a call and who was understandably staring at a Coldcard wondering what on earth they were supposed to do next.
The volume built quickly. In the first six days alone, the team handled more than 15,000 emails, 20,000 direct messages and 1,000 one-to-one calls, alongside four webinars across multiple time zones. That amounted to roughly 1,500 hours of technical support from a team of sixteen. As the response continued, we estimated those numbers had grown to around 20,000 emails, 30,000 messages and 1,200 individual calls.

Statistics flatten what those days actually looked like. Behind every call was somebody waiting to know whether years of savings were safe. Behind every unanswered message was another person wondering whether they should move immediately or touch nothing. Information was still developing, hardware wasn’t always available at short notice, and the safest next step depended on the setup in front of us.
Some of the messages coming back put that experience into words better than we could. One of you told us that when the news broke, you felt “relatively calm knowing an update from BTC Way would be in my inbox asap”. Another had already moved their bitcoin, created a fresh wallet using dice-generated entropy, and verified the transfer through their own node, later telling us that the training we had done together had given them the confidence to act for themselves. Those were two very different kinds of reassurance. One came from knowing somebody was there. The other came from knowing what to do yourself. We wanted you to have both.


So the job became simple, even if executing it wasn’t: keep talking to you, keep working through the list, and keep going until we knew where everyone stood. Within six days, more than 98% of those potentially affected had either confirmed they were unaffected, moved their funds, taken action themselves, made contact with us, or had a session scheduled.
Then came our next challenge. Almost 600 setups still needed to be rebuilt.
When Support Stops Being Optional
Rebuilding almost 600 setups is a substantial amount of work, and there was an obvious commercial route available to us. Demand for security help had exploded overnight. People were frightened, hardware was being replaced, and hundreds of hours of specialist time were suddenly required.
We could have treated that as new business. We didn’t. Emergency withdrawal calls were opened at no cost, and if we had previously helped you build a setup that now needed upgrading, we committed to helping rebuild it without charging you for the work. At the same time, we had closed our sales calendar and redirected people who would normally be bringing new revenue into the company towards supporting existing customers instead.

That decision wasn’t particularly complicated. You had trusted us to help you secure your Bitcoin. Many of you chose Coldcard as part of those setups. The vulnerability wasn’t something we created, and our additional safeguards had done what we hoped they would, but pointing at those facts and sending you an invoice for the clean-up would have been a fairly miserable interpretation of responsibility. So we absorbed it.
The calls, withdrawals and rebuilds have been carried out at our expense. We also expanded the technical team to deal with the volume, because getting through the immediate emergency was only the first half of the job. Hundreds of you still needed to move from temporary arrangements into new setups.

The point of that support, however, isn’t to make you more dependent on us. One message sent to Ahmed, one of our founders and self-custody educators, captured the opposite rather nicely: “You taught me how to fish so that I can be self-sufficient”. That is what good support should leave behind. When the stakes demand it, we want to be there. Afterwards, we want you to understand your setup better, know what you are doing and need us less than you did before.

That principle cuts both ways. We talk a lot about responsibility in Bitcoin because self-custody demands it from the person holding the keys. The same standard has to run in both directions. If we expect you to take responsibility for your Bitcoin, we should be prepared to take responsibility for the advice we give you.
Beyond Our Own Clients
There was another part of the response that had nothing to do with rebuilding our own setups. As researchers dug into the Coldcard failure, the wider Bitcoin ecosystem was being put under the microscope too. Vulnerabilities were being surfaced in other Bitcoin-related services, including projects such as BTCPay Server and Boltz. The obvious lesson was that finding weaknesses before attackers do is valuable well beyond the people directly affected by one incident.
That work is often done by independent security researchers and small teams whose incentives are slightly less glamorous than the size of the problems they are trying to prevent. So we donated roughly 0.13 BTC, worth around $8,500 at the time, to the Bitcoin Red Team to support further vulnerability research across the ecosystem.

We didn’t do that because we suddenly expect every Bitcoin company or open-source project to be flawless. The opposite would be a strange conclusion to draw from this incident. Software has bugs, hardware has bugs, and people make mistakes. The useful question is how quickly those weaknesses are found, disclosed and fixed before somebody with a very different incentive finds them first. Coldcard had already shown the cost of getting that sequence wrong.
Supporting researchers looking for the next weakness seemed like a more useful response than simply rebuilding our own setups, closing the incident and moving on. The people protecting Bitcoin aren’t only the companies whose logos you recognise. They’re also the developers, auditors and researchers trying to break things in silence before criminals get the chance. If this episode taught us anything, it’s that we want more of those people looking.

The Standard Has Changed
Getting through the immediate response was never going to be the end of the job.
The safeguards already built into your setup gave us protection when one component failed, but the incident still exposed a dependency worth removing. For years, we, like most of the industry, trusted hardware wallets to generate the randomness behind a new seed correctly. Coldcard showed the cost of allowing such an important part of the setup to depend entirely on software doing exactly what everyone assumes it is doing.
So the lesson we are carrying forward is straightforward: reduce the number of things that have to go perfectly. That means looking again at how seeds are created, how much any setup depends on one device or manufacturer, and where additional independent checks can make a failure less consequential. Our webinar outlined external entropy and hardware-independent seed generation as part of that direction, alongside rebuild options designed to reduce reliance on a single component. The precise setup still has to fit the person using it. Complexity added for its own sake can create just as many problems as it solves.

The rebuilds are part of that work. Moving bitcoin during the emergency dealt with the immediate risk. Almost 600 of you then needed help moving from temporary arrangements into something designed for the years ahead. That is a very different job from telling everyone to buy the newest hardware wallet and hoping it behaves itself this time.
Self-custody will always involve responsibility. There is no magic device that makes that disappear. If the last few weeks have demonstrated anything, it is that the quality of your setup depends on understanding where its weak points are and making sure one failure cannot quietly compromise everything around it.

Good support should help you do that without taking control away from you. You should finish with a setup you understand better, can recover yourself, and can adapt when circumstances change. If this incident has made you question your own setup, use that instinct productively. Ask where your seed came from, what happens if a device or manufacturer fails, whether you have actually tested recovery, and whether you know what you would do if something went wrong tomorrow.
If you are not confident in those answers, we can help you work through them. Book a free 30-minute introductory call with one of our advisers and we can review where your current setup depends too heavily on one component, what is already working well and what may be worth strengthening.