What the Coldcard Incident Reveals About Crypto Custody Trade-offs

August 24, 2026
Newton Team
August 24, 2026
What the Coldcard Incident Reveals About Crypto Custody Trade-offs

Hardware wallets are designed to keep private keys offline, reducing exposure to certain online threats. But keeping keys offline doesn't eliminate custody risk. It changes where that risk lives, and who is responsible for managing it.

A recently disclosed vulnerability affecting Coldcard hardware wallets has brought that distinction into focus.

Beginning July 30, 2026, attackers drained Bitcoin from wallets whose seeds were generated on affected Coldcard firmware. TRM Labs, citing Galaxy Research's tracking, reported on August 5 that roughly 1,816 BTC, worth approximately US$116 million at the time of its analysis, had been taken from more than 5,200 addresses. Galaxy Research separately tracked losses near US$130 million as of August 4. Because tracing remains ongoing and the value of Bitcoin changes, estimates have varied.

The incident is significant not just because of the amount involved, but because of where the vulnerability occurred: during seed generation.

What happened with Coldcard?

When many crypto wallets, including Coldcard, are created, they can generate a seed phrase that can ultimately be used to derive the private keys controlling the assets in that wallet. The security of that process depends heavily on randomness, or "entropy," making the resulting seed extremely difficult for someone else to reproduce.

On July 30, Coldcard manufacturer Coinkite disclosed that a firmware issue had reduced that randomness for seeds generated on certain devices and firmware versions. The issue originated in software changes introduced in March 2021.

Under Coinkite’s current attack assumptions, affected Mk2 and Mk3 devices could generate seeds with roughly 40 bits of effective entropy rather than the intended 128 bits. Mk4, Mk5 and Q devices contained additional entropy, but Coinkite estimates an effective search space of approximately 72 bits.

That reduction matters.

Researchers tracking the thefts say attackers could generate possible seeds offline, derive their corresponding Bitcoin addresses and compare them against addresses visible on the public blockchain. Physical access to the hardware wallet itself was not required.

In other words, keeping the wallet offline did not eliminate the risk, because the vulnerability was introduced when the seed was generated.

Coinkite has since released fixed firmware for affected models. However, installing an update does not repair a seed that was previously generated using affected firmware. Its advisory instructs affected users to create a new seed after updating and migrate their funds, subject to specific exceptions for users who added sufficient independent dice-generated entropy when creating their original seed.

Are hardware wallets still safe after the Coldcard exploit?

Short answer: Yes, but security requires careful management.

The Coldcard incident doesn't negate the benefits of hardware wallets or self-custody. Hardware wallets can reduce several important risks by allowing users to keep their private keys offline and retain direct control over their crypto.

But self-custody doesn't eliminate custody risk. It transfers responsibility for managing it.

Someone using a hardware wallet may be responsible for choosing the device, verifying its software, generating and protecting a seed phrase, securing backups, managing passphrases, installing appropriate updates and ensuring that recovery information remains both accessible and protected.

Usually, that level of control is one of the main reasons someone chooses self-custody in the first place.

It also means that failures involving a device, its software, key generation, backups or the user's own security practices can have consequences that may be difficult or impossible to reverse.

The Coldcard incident is an unusual example, but it highlights a broader point: the method used to hold crypto changes the risks involved; it doesn't make risk disappear.

Self-custody and custodial platforms manage different risks.

Custody Factor Self-Custody Custodial Platform
Private Keys Controlled by the user Managed by the platform and custodians
Key Risks Seed loss, device/software issues, user error Custodian, platform, technology and operational risk
Recovery Depends on wallet access or backup Account recovery processes may be available
Storage Hardware device + offline backup Cold and hot wallet infrastructure

The distinction is easier to understand when you look at who controls the private keys.

With self-custody, the individual controls the keys. There is no custodial platform standing between the holder and the blockchain, but the individual assumes responsibility for protecting those keys and maintaining the infrastructure needed to access them.

With a custodial platform, the platform or its custody providers hold crypto assets on the client's behalf. The client does not personally manage the underlying private keys.

That shifts some of the responsibilities associated with managing private keys away from the individual, but introduces a different set of risks, including risks related to the platform, its custodians, its technology and its operational controls.

Neither model is risk-free. They represent different approaches to where custody responsibility sits.

How custody works at Newton.

We use a custodial model to hold crypto on behalf of our clients. Newton Crypto Ltd. is a dealer member of the Canadian Investment Regulatory Organization (CIRO), and our current Risk Disclosure sets out how we hold client crypto assets.

As a regulated dealer, we follow asset segregation requirements: we hold client crypto assets separately from our own operational assets and from the assets of our custody providers.

How we hold assets:

  • Cold storage: We hold at least 80% of client crypto assets offline in cold storage with third-party custodians (primarily Coinbase Custody Trust Company and BitGo Bank & Trust). Because these assets are kept offline, they are less exposed to certain online threats, but they are not as readily available for day-to-day transactions.
  • Hot wallets: We hold up to 20% of client crypto assets in internet-connected hot wallets so funds are available to support activities such as deposits and withdrawals. These wallets use Fireblocks, which provides institutional-grade digital-asset wallet infrastructure and security controls for managing and authorizing transactions. As our Risk Disclosure notes, assets held in hot wallets face higher exposure to hacks and theft than assets held in cold storage.
  • Fiat cash: Fiat currency is held separately from Newton’s own assets with a qualified Canadian cash custodian. In the event of insolvency, eligible CAD and USD cash balances may qualify for CIPF protection, subject to CIPF’s eligibility requirements and coverage limits.

Custody also carries risk. Our Risk Disclosure identifies the potential for loss if a custodian becomes bankrupt or insolvent, if its technology systems break down, or through fraud, misconduct, negligence or error by a custodian or its personnel. CIPF protection is designed to help return eligible client property that is missing in the event of a member firm’s insolvency; crypto assets are not eligible for that protection and are not protected by CDIC.

So, where should you hold your crypto?

There isn't one custody model that is appropriate for everyone.

For some crypto holders, directly controlling private keys and accepting the responsibilities that come with self-custody may be important. Others may prefer a custodial platform where key management and custody infrastructure are handled on their behalf.

Understanding that distinction is more useful than treating the choice as a simple question of which method offers more protection.

The Coldcard incident is a reminder that custody has multiple layers. A private key can be kept offline, but the process used to create it still matters. A custodial platform can remove the need for an individual to manage that key directly, but doing so introduces reliance on the platform, its custodians and their systems.

The real question isn't whether custody carries risk. It's which risks and responsibilities you choose to take on yourself, and which you choose to place with a custodian.

To learn more about how Newton holds client crypto assets and the risks associated with that model, review Newton's Risk Disclosure.

‍

Manage crypto without managing private keys yourself.

Newton uses a custodial model to hold crypto on behalf of our clients.
No items found.

FAQs

Does updating Coldcard firmware fix an existing seed phrase?

How does Newton store client crypto assets?

Are crypto assets held on Newton covered by CIPF?

This article is for informational purposes only and does not constitute tax, investment, financial, or legal advice. Cryptocurrencies and blockchain-based assets are highly speculative, subject to significant risks including price volatility, regulatory uncertainty, and potential total loss of investment. Crypto assets are not insured by the Canada Deposit Insurance Corporation (CDIC). Cryptocurrencies and stablecoins may be considered securities or derivatives under Canadian law, subject to CSA and CIRO oversight. Consult a qualified financial or legal professional before making investment decisions. No securities regulatory authority has expressed an opinion about any of the crypto assets made available on the Newton’s platform, including any opinion that a crypto asset is not a security and/or derivative. This blog may contain links to other websites for informational purposes or for your convenience. We do not control the linked websites or the content provided through such websites, and we have not reviewed, in their entirety, such websites. Your use of linked websites is subject to the privacy policies and terms of use established by the specific linked website, and we disclaim all liability for such use. The fact that we offer such links does not indicate any approval or endorsement by us of any linked website or any material contained on any linked website, and we disclaim any such approval or endorsements.
Newton Team
Follow Newton on LinkedIn
Follow Newton on YouTube
Follow Newton on LinkedIn
Follow Newton on Twitter
BACK TO BLOG