We taught people to set up a Coldcard in 2019. In July 2026 a Coldcard firmware flaw drained ~594 BTC. So the fair question: did we promote the bad version, was it mainly Max, and how exposed are we? Here is the honest answer, checked against the tape and the primary advisories.
WCN promoted the Coldcard Mk2 — one of the affected hardware families — across a 2019 teaching series. But the vulnerability was introduced in firmware 4.0.0 on 1 March 2021, roughly 20 months after our last Coldcard episode. We never demonstrated or endorsed the vulnerable firmware; the version we actually showed on camera was v2.1.1. Because the exploit only affects seeds generated on the buggy firmware, a viewer who set up their Coldcard from our 2019 videos and kept that seed is not in the affected set. Our own episodes even stressed the device's true hardware RNG — the exact thing the later firmware silently disabled. Involvement: real promotional exposure, minimal culpability.
Between 01:31 and 01:56 UTC on 31 July 2026, an attacker swept roughly 594 BTC (~$38 million) out of about 500 single-signature Coldcard wallets in a 25-minute run. Nothing touched the physical devices. The root cause, traced by Coinkite and Block's engineering team to a commit dated 1 March 2021 (shipped in firmware 4.0.0 / 4.0.1), was a build flag that made the wallet skip its own true hardware random-number generator and fall back to a weak software generator seeded from non-secret chip data. That cut the real entropy of a "random" seed from 128 bits to as little as ~40–72 bits — enough for an attacker to simply enumerate and guess the seeds. Coinkite's advisory scopes the severe case to Mk3 seeds made on v4.0.1 through v4.1.9; an updated advisory notes Mk4, Q and Mk5 seeds made before the fix carry a milder (~72-bit) version of the same weakness. Fixed firmware shipped immediately. Updating does not repair an already-weak seed — affected users must migrate.
We promoted the Coldcard Mk2 device, which is part of the affected hardware family. But the flaw lived in firmware 4.0.0+ (March 2021). Our coverage ran April–July 2019 and the specific version we walked through on air was Cold Card v2.1.1 — almost two years before the bug existed. The exploit depends on the firmware running at the moment a seed is created, not on the model or the purchase date, so a seed generated while following our 2019 tutorials is not affected. In a real irony, our backup episode spent its runtime explaining that the seed comes from "the device's true random number generator" — the very component the 2021 firmware quietly bypassed.
The hands-on run was Max Hillebrand's "Understanding Bitcoin" teaching series on WCN. Of the fourteen Coldcard episodes, the twelve step-by-step tutorials from April to July 2019 were Max's — every one carried his "donate a couple sats to Max" tag. The only non-Max items are a re-shared Breaking Bitcoin conference interview with Coldcard's creator and a couple of hardware round-ups. And to be complete across all three shows: The Bitcoin Group mentioned Coldcard zero times in 483 transcripts, and Mad Bitcoins never centered it either. Coldcard on our network is, essentially, Max on WCN.
On the numbers: honestly, per-episode public view and comment counts are not stored in our archive for these fourteen videos — the master index keeps titles, dates, channels and YouTube IDs but not live stats, and the 2019 educational micro-series was never captured by the podcast view-tracker. The videos are still live on WCN's YouTube (linked below) if you want current counts; as a class they were niche, short how-tos, not flagship episodes.
On involvement: low. We gave the brand real airtime and taught people to buy and set up the device, so there is genuine promotional exposure. But (1) the flaw postdates our coverage by ~20 months; (2) we never showed the vulnerable firmware; (3) seeds made on the firmware we demonstrated are safe; and (4) the mitigations Coinkite now recommends — verify firmware signatures, use a BIP-39 passphrase, add your own dice-roll entropy — are things our episodes actively taught. The one fair caveat: our tutorials helped grow the Coldcard user base, and some unknown subset of those viewers later re-generated seeds during the 2021–2026 vulnerable window. That is indirect, and unquantifiable from our side, but it is the honest asterisk.
We have a long record of covering weak-randomness failures — Mad Bitcoins reported the 2013
Android/Java SecureRandom bug in real time. The 2026 Coldcard exploit is the same
family of failure, and it is worth noting our house has warned about it since 2013. See the
companion report, WCN & Hardware Wallets.
| Date | Episode | Host | YouTube |
|---|---|---|---|
| 2018-11-21 | Hardware Wallet ~ Bitcoin to the Max | Max | bvCJZhE8q8I |
| 2019-02-23 | The Most Useful Bitcoin-Only Hardware | WCN | SyIh-UqxEyQ |
| 2019-04-27 | Unbagging the ColdCard Mark2 ~ Giveaway | Max | 5FwOOTYH7Uw |
| 2019-04-29 | Setting up ColdCard Mark2 Wallet Backup | Max | w6MvnUu2GBo |
| 2019-04-30 | Secure Upgrade Firmware of ColdCard Mark 2 | Max | JCZzugnfQPs |
| 2019-05-01 | Coldcard PIN Design and Operation | Max | iuiOqqZ8eeU |
| 2019-05-06 | How to Set Up the Different PINs | Max | hk1Lq2Rp2KM |
| 2019-05-09 | How to Use ColdCard with Electrum | Max | 9A0cS2wwMI0 |
| 2019-05-10 | The Design of the Encrypted SD Backup | Max | EgIL1e8ttpQ |
| 2019-05-12 | How Do You Encrypt Your SD Backup | Max | 2E-nLwe_pcc |
| 2019-05-13 | How to Wipe the Seed & Restore SD Backup | Max | WVIPLJCMGUQ |
| 2019-07-07 | Securely Upgrade Wasabi v1.1.6 & Cold Card v2.1.1 | Max | mTrClVA_o5A |
| 2019-07-10 | Wasabi + Cold Card ~ Air-Gapped Private Storage | Max | aU8ysH9JH9M |
| 2019-07-16 | The Latest of Cold Card ~ Rodolfo Novak | re-share | u8HqxDBftDs |