Is your client's "cold wallet" actually covered?

A five-year-old coding bug just drained $86m from bitcoin's safest storage

Is your client's "cold wallet" actually covered?

Cyber

By Matthew Sellers

The pitch behind hardware wallets like Coldcard has always been simple: take your bitcoin offline onto a device that never touches the internet, and no hacker can get near it. That pitch took a battering last week - and the fallout says as much about crypto custody insurance as crypto security.

Canadian manufacturer Coinkite disclosed on July 30 that a coding error from a March 2021 firmware update had quietly been generating predictable wallet seeds - the master password behind every coin in the wallet - on some Coldcard devices. Instead of pulling genuine randomness from the device's hardware chip, the flawed firmware leaned on a software process that could be reverse-engineered from outside the device entirely.

How it unfolded

The attack came in fast waves. On July 30, someone drained roughly 594 BTC (about $38 million) from nearly 500 dormant wallets in under half an hour, according to Block's engineering team. By August 1, Galaxy Research put the total at around 1,159 BTC (~$75 million). By Monday August 3, Bloomberg reported the tally had climbed to roughly 1,367 tokens - close to $86 million - from over 4,500 wallets.

The cause: affected firmware skipped the hardware random number generator, falling back on a predictable software substitute partly seeded by non-secret data like the device's serial number. On the worst-hit Mk3 units, that shrank the effective guesswork needed from an industry-standard 128 bits of entropy to around 40 - a different order of magnitude. Mk4, Mk5 and Q devices on older firmware are touched too, Coinkite says, though less severely.

Patched firmware is now out for every affected model; TAPSIGNER, OPENDIME and SATSCARD weren't affected. The catch: updating firmware doesn't fix a seed already generated on a dodgy version - those funds need moving to a brand new wallet, seed and all.

Why insurers should care

For a market still building its appetite for crypto risk, this is an awkward one - not because of the size, but because of where the failure sat. Cold storage is the gold-standard control against theft in specialty underwriting; Lockton's own guidance on the specie and crime markets defines it by the "air-gap" between device and internet. Coldcard owners had that air-gap. Didn't matter - the weakness was baked into the key before it was ever generated, not in how it was later stored.

That distinction matters at claims stage. Cyber insurance is generally built around data breaches, ransomware and business interruption, not private-key theft, which typically sits with crime or specie policies instead. But as Howden sets out, specie cover for digital assets has historically centred on named perils - fire, flood, theft, employee dishonesty - not a latent bug in a manufacturer's own random number generator. Whether this flaw falls neatly inside existing wordings, or drops into a gap between crime, specie and cyber, is what claims teams are about to find out.

Custody and key-management failures, not flashy smart contract exploits, are increasingly the industry's biggest loss driver. TRM Labs found infrastructure and key compromises made up around 15% of crypto hacking incidents in H1 2026 but drove roughly three-quarters of total losses, per Bloomberg's reporting. Blockaid's Ido Ben-Natan has flagged the same trend, noting most 2026 losses started at the key-generation stage rather than in smart contract code - exactly where Coldcard's flaw sat.

The regulatory backdrop

Timing-wise, it's inconvenient. The FCA confirmed crypto firms can start applying for authorisation under the UK's new cryptoasset regime from September 30, 2026, with the full framework binding from 25 October 2027. Insurance Business has previously covered how the UK market has been building capability to serve crypto custodians, and how regulators are tightening expectations on third-party risk generally - a framing that fits wallet-manufacturer firmware just as well as it fits a cloud provider.

For underwriters, "self-custody" and "cold storage" aren't the same as "no residual risk" - they just move the risk somewhere else, here into five-year-old firmware. For brokers, it's a nudge to check which policy, if any, actually responds when the loss comes from a defect built into the client's kit long before they bought it.

What to ask crypto-holding clients now

  • Whose hardware, which firmware? Even "cold storage" clients can be exposed if the seed was generated on flawed firmware.
  • Which policy actually responds? Crime, specie or cyber - confirm which wording triggers. Howden's specie-market framing suggests it isn't always obvious.
  • Was a BIP-39 passphrase used? Independent entropy can meaningfully cut exposure even on affected firmware.
  • Is anyone watching vendor advisories? Ask if there's a process for acting on manufacturer notices, with evidence of when firmware was last updated.
  • How would a claim be evidenced? Keep records of wallet fingerprints, transaction history and firmware version at seed generation.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!