← WCN Reports
World Crypto Network · Report · Self-Audit

Our Coldcard Coverage vs. the 2026 Hack

We taught people to set up a Coldcard in 2019. In July 2026 a Coldcard firmware flaw drained ~594 BTC. So the fair question: did we promote the bad version, was it mainly Max, and how exposed are we? Here is the honest answer, checked against the tape and the primary advisories.

2026-08-01 WCN · MB · TBG searched 14 Coldcard episodes Built from the transcripts
// Bottom line

WCN promoted the Coldcard Mk2 — one of the affected hardware families — across a 2019 teaching series. But the vulnerability was introduced in firmware 4.0.0 on 1 March 2021, roughly 20 months after our last Coldcard episode. We never demonstrated or endorsed the vulnerable firmware; the version we actually showed on camera was v2.1.1. Because the exploit only affects seeds generated on the buggy firmware, a viewer who set up their Coldcard from our 2019 videos and kept that seed is not in the affected set. Our own episodes even stressed the device's true hardware RNG — the exact thing the later firmware silently disabled. Involvement: real promotional exposure, minimal culpability.

01What actually happened in 2026

Between 01:31 and 01:56 UTC on 31 July 2026, an attacker swept roughly 594 BTC (~$38 million) out of about 500 single-signature Coldcard wallets in a 25-minute run. Nothing touched the physical devices. The root cause, traced by Coinkite and Block's engineering team to a commit dated 1 March 2021 (shipped in firmware 4.0.0 / 4.0.1), was a build flag that made the wallet skip its own true hardware random-number generator and fall back to a weak software generator seeded from non-secret chip data. That cut the real entropy of a "random" seed from 128 bits to as little as ~40–72 bits — enough for an attacker to simply enumerate and guess the seeds. Coinkite's advisory scopes the severe case to Mk3 seeds made on v4.0.1 through v4.1.9; an updated advisory notes Mk4, Q and Mk5 seeds made before the fix carry a milder (~72-bit) version of the same weakness. Fixed firmware shipped immediately. Updating does not repair an already-weak seed — affected users must migrate.

CORRECTION WORTH KNOWING — Several outlets reported "$70M / ~1,000+ BTC." The figure carried by CoinDesk, Coinkite and Block is 594 BTC / ~$38M across ~500 wallets. The "1,324" number in circulation is a count of transaction outputs moved, not coins.

02The three questions

Did we promote the bad version?
No — not the vulnerable firmware

We promoted the Coldcard Mk2 device, which is part of the affected hardware family. But the flaw lived in firmware 4.0.0+ (March 2021). Our coverage ran April–July 2019 and the specific version we walked through on air was Cold Card v2.1.1 — almost two years before the bug existed. The exploit depends on the firmware running at the moment a seed is created, not on the model or the purchase date, so a seed generated while following our 2019 tutorials is not affected. In a real irony, our backup episode spent its runtime explaining that the seed comes from "the device's true random number generator" — the very component the 2021 firmware quietly bypassed.

Was it mainly Max?
Yes — Max Hillebrand's series

The hands-on run was Max Hillebrand's "Understanding Bitcoin" teaching series on WCN. Of the fourteen Coldcard episodes, the twelve step-by-step tutorials from April to July 2019 were Max's — every one carried his "donate a couple sats to Max" tag. The only non-Max items are a re-shared Breaking Bitcoin conference interview with Coldcard's creator and a couple of hardware round-ups. And to be complete across all three shows: The Bitcoin Group mentioned Coldcard zero times in 483 transcripts, and Mad Bitcoins never centered it either. Coldcard on our network is, essentially, Max on WCN.

How many views and comments?   How bad is our involvement?
Low / indirect exposure

On the numbers: honestly, per-episode public view and comment counts are not stored in our archive for these fourteen videos — the master index keeps titles, dates, channels and YouTube IDs but not live stats, and the 2019 educational micro-series was never captured by the podcast view-tracker. The videos are still live on WCN's YouTube (linked below) if you want current counts; as a class they were niche, short how-tos, not flagship episodes.

On involvement: low. We gave the brand real airtime and taught people to buy and set up the device, so there is genuine promotional exposure. But (1) the flaw postdates our coverage by ~20 months; (2) we never showed the vulnerable firmware; (3) seeds made on the firmware we demonstrated are safe; and (4) the mitigations Coinkite now recommends — verify firmware signatures, use a BIP-39 passphrase, add your own dice-roll entropy — are things our episodes actively taught. The one fair caveat: our tutorials helped grow the Coldcard user base, and some unknown subset of those viewers later re-generated seeds during the 2021–2026 vulnerable window. That is indirect, and unquantifiable from our side, but it is the honest asterisk.

03The timeline, side by side

2018-11 → 2019-02
WCN first names the Coldcard (Max) — offline, Bitcoin-only hardware.
2019-04 → 2019-07
Max's 12-part hands-on series: Mk2 unbagging, PINs & duress, encrypted SD backup, Electrum/Wasabi air-gap — firmware v2.1.1.
2019-07-16
Final Coldcard episode: Rodolfo Novak interview (Breaking Bitcoin, Amsterdam).
2021-03-01
THE BUG IS BORN — firmware 4.0.0 commit skips the true RNG. ~20 months after our last episode.
2026-07-31
~594 BTC (~$38M) swept from ~500 wallets in 25 minutes. Seeds made on 4.0.x were guessable.
Thirteen years earlier, Mad Bitcoins had already called this exact class of bug: "The random number generator on Android ain't so random." Mad Bitcoins · 2013-08-12

We have a long record of covering weak-randomness failures — Mad Bitcoins reported the 2013 Android/Java SecureRandom bug in real time. The 2026 Coldcard exploit is the same family of failure, and it is worth noting our house has warned about it since 2013. See the companion report, WCN & Hardware Wallets.

04The fourteen episodes

DateEpisodeHostYouTube
2018-11-21Hardware Wallet ~ Bitcoin to the MaxMaxbvCJZhE8q8I
2019-02-23The Most Useful Bitcoin-Only HardwareWCNSyIh-UqxEyQ
2019-04-27Unbagging the ColdCard Mark2 ~ GiveawayMax5FwOOTYH7Uw
2019-04-29Setting up ColdCard Mark2 Wallet BackupMaxw6MvnUu2GBo
2019-04-30Secure Upgrade Firmware of ColdCard Mark 2MaxJCZzugnfQPs
2019-05-01Coldcard PIN Design and OperationMaxiuiOqqZ8eeU
2019-05-06How to Set Up the Different PINsMaxhk1Lq2Rp2KM
2019-05-09How to Use ColdCard with ElectrumMax9A0cS2wwMI0
2019-05-10The Design of the Encrypted SD BackupMaxEgIL1e8ttpQ
2019-05-12How Do You Encrypt Your SD BackupMax2E-nLwe_pcc
2019-05-13How to Wipe the Seed & Restore SD BackupMaxWVIPLJCMGUQ
2019-07-07Securely Upgrade Wasabi v1.1.6 & Cold Card v2.1.1MaxmTrClVA_o5A
2019-07-10Wasabi + Cold Card ~ Air-Gapped Private StorageMaxaU8ysH9JH9M
2019-07-16The Latest of Cold Card ~ Rodolfo Novakre-shareu8HqxDBftDs
METHOD — Coverage facts are from the WCN / LLM-Wiki transcript archive (WCN, Mad Bitcoins and The Bitcoin Group all searched). Hack facts are from Coinkite's advisory, Block's engineering write-up and CoinDesk. Per-episode view/comment counts are not present in the archive and are not asserted here.
// Sources
  1. Coinkite advisory — Coldcard Mk3 seed-generation warning · blog.coinkite.com/coldcard-mk3-seed-generation-warning/
  2. Block engineering — Predictable RNG fallback in Coldcard firmware · engineering.block.xyz
  3. CoinDesk — "Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep" · 2026-07-31
  4. WCN Coldcard episodes (14) — linked in the table above, 1n2.org / LLM-Wiki archive
  5. Mad Bitcoins — "Random Android Bitcoin Wallet Bug" · 2013-08-12