Unchained has printed an evaluation of the Coldcard safety incident, arguing that multisig pockets buildings shielded hundreds of bitcoin whereas singlesig customers had been left instantly uncovered.
On July 30, 2026, Coinkite issued a safety advisory overlaying a vulnerability affecting most Coldcard {hardware} wallets.
How the bug labored
Based on Unchained’s breakdown, the flaw sat within the machine’s random quantity generator, that means the entropy behind key era was far weaker than customers believed.
Unchained wrote:
“The entropy wasn’t almost as unpredictable or random as individuals believed, and the variety of potential seeds and keys that could possibly be produced was a lot smaller than it wanted to be.”
As a result of entropy is the bottom layer, each layer above it inherited the weak spot:
“As a result of entropy is the foundational place to begin, its lack of safety means each different layer constructed on prime of it’s insecure as nicely.”
Singlesig customers hit first
Attackers scanned frequent derivation paths and located keys tied to dwell balances.
Unchained defined:
“As quickly as they discovered a key that was controlling a steadiness, the attacker may then use the important thing to maneuver the bitcoin right into a pockets they alone management, stealing the bitcoin.”
Why multisig held up
In a 2-of-3 setup, a single compromised key isn’t sufficient.
Unchained famous:
“If one key’s stolen (or on this case, compromised by an existential RNG bug), the thief doesn’t have sufficient keys to entry any bitcoin.”
Even wallets constructed fully from Coldcard keys retained some safety, since attackers would wish to appropriately pair three key units in opposition to an deal with.
The agency concluded:
“It’s clear at this level that multisig gave many customers extra fault-tolerance and time to reply.”
Unchained additionally rolled out direct-to-miner transaction submission to cut back RBF assault threat whereas spends sat unconfirmed in public mempools.