Coldcard, one of Bitcoin's most widely used hardware wallets, released a new firmware update this week after an extended review prompted by a flaw linked to $114 million in stolen bitcoin. The timing lands against a striking backdrop: Bitcoin is trading at $76,969, up roughly 24% since Monday, its best weekly performance since 2023, according to CoinDesk.
The Firmware Fix—and Its Limits
Three weeks of internal review preceded the release. According to CoinDesk, that review—assisted by AI tools—turned up additional bugs unrelated to the original vulnerability. That's notable in itself. Extended scrutiny found problems that would otherwise have gone undetected.
But Coldcard was direct about one critical point: installing the update does not make a wallet safe if that wallet was already compromised. If an attacker accessed a seed phrase or private key before the patch, the update changes nothing. Users who suspect exposure need to move funds to a freshly generated wallet—not just update the firmware.
Bitcoin Magazine went further, examining what the incident reveals about software licensing. The piece argued that Coldcard's source-available license—which restricts commercial reuse—limits the pool of independent reviewers compared to fully open-source alternatives. Fewer eyes reviewing code means vendors carry more of the security burden themselves. That tradeoff is worth understanding for anyone choosing a custody solution.
Why Custody Questions Matter More Right Now
The security story arrives as more capital is moving into Bitcoin, not less. Spot Bitcoin ETFs drew $608 million on August 20 alone, pushing August's total to a 2026 high of $2.07 billion, according to Cointelegraph. Strategy's bitcoin holdings climbed back above their average purchase price, sitting on roughly $1.4 billion in profit as of Friday, per CoinDesk.
STS Digital CEO Maxime Seiler described current conditions to The Block as an "institutional summer" even if token prices have lagged. Institutional participation means larger pools of bitcoin held in custody—which raises the stakes of any custody vulnerability across the board.
What the Coldcard Case Actually Teaches
A few practical takeaways stand out:
- Patch promptly, but understand what patching does and doesn't do. Firmware updates fix forward-looking vulnerabilities; they cannot reverse a past compromise.
- Check your wallet's license model. Open-source code invites broader peer review. Source-available code does not—and that affects how quickly bugs surface.
- AI-assisted auditing is becoming standard. Coldcard's use of AI in its review caught additional issues. This is increasingly common in software security and will likely expand.
- When in doubt, generate a new wallet. Moving funds to a fresh seed is the only reliable recovery path after suspected exposure.
The broader rally—short liquidations exceeding $4 billion over two days, Bitcoin reclaiming its 200-day moving average for the first time since November—creates urgency around safe custody. More people holding more bitcoin means the cost of a custody failure, individual or collective, only grows.
How charities and nonprofits store donated bitcoin deserves the same scrutiny any individual donor applies to their own holdings—sound custody practices protect the people those donations are meant to reach.