Casa CEO Nick Neuman: 233,000 BTC Moved to Safety After Coldcard Exploit Highlights Self-Custody Resilience
Key Takeaways
- •Approximately 2,100 BTC was stolen in the Coldcard exploit, which exploited a seed generation vulnerability originating from a March 2021 firmware update affecting certain hardware wallet models.
- •On-chain data revealed that 233,000 BTC left long-term holder wallets following the incident, representing 10 to 100 times the amount stolen, as users migrated funds to safer setups.
- •Some of the observed Bitcoin movement reflected holders transitioning from single-key hardware wallets to multisig configurations, while existing multisig users removed Coldcard devices from their setups.
- •Neuman contrasted the self-custody outcome with a hypothetical centralized custodian breach, where a single hack could result in catastrophic losses comparable to the 2014 Mt. Gox collapse of 850,000 BTC.
- •The Coldcard incident has reignited industry-wide discussions about hardware wallet security standards, firmware auditing practices, and the relative advantages of multisig and covenant-based vault designs.

Casa CEO Nick Neuman has pointed to on-chain data following the recent Coldcard firmware exploit as compelling evidence that self-custody strengthens Bitcoin's resilience as an asset class.
In an X post on August 9, Neuman cited figures showing that in the days after the Coldcard hack — in which approximately 2,100 BTC was stolen — 22,000 BTC moved to exchanges and 233,000 BTC left long-term holder wallets in on-chain transactions, according to data from Checkonchain.
"The onchain metrics around the Coldcard incident reinforce how important self-custody is to the resilience of Bitcoin as an asset class," Neuman wrote.
Galaxy Research has tracked confirmed losses from the Coldcard entropy flaw as low as 1,700 BTC, with estimates ranging above 2,000 BTC. The stolen coins have been traced across multiple attack waves beginning July 30, with higher loss estimates approaching $130 million.
The vulnerability originated from a March 2021 firmware issue that weakened seed generation on certain Coldcard hardware wallet models produced by manufacturer Coinkite. Coldcard devices are widely used among self-custody practitioners for their air-gapped design, making the seed generation flaw particularly significant for users who had relied on the wallet's security model.
Neuman noted that conversations with Casa's own customers indicated that part of the 233,000 BTC movement reflected holders migrating from non-Coldcard single-key setups — such as Ledger or Trezor devices — into multisig wallets after reassessing single-key risk. Other observed flows involved existing multisig users removing Coldcard devices from their key configurations.
"So somewhere between ~10x–100x the amount of bitcoin stolen was moved to safety as people sounded the alarm," he wrote. "This is a giant flashing neon sign showcasing the resilience that self-custody adds to the network."
Neuman contrasted the outcome with a hypothetical breach at a centralized custodian. In such a scenario, he argued, the figures would likely be reversed: a limited amount of funds might escape while the vast majority would be lost in a single catastrophic event. With self-custody, attackers were forced to target individual wallets one at a time, constraining the scale of any single exploit and affording holders a window to react. The argument echoes long-standing concerns in the Bitcoin community dating back to major exchange failures such as Mt. Gox in 2014, where approximately 850,000 BTC was lost in a single custodial collapse.
"If all that BTC was held at a custodian and the custodian was hacked instead, those numbers would have been flipped," Neuman stated. "As it was, the thieves had to crack one wallet at a time (and are still going), earning a little BTC each wallet, instead of cracking one wallet and getting a massive payday."
He concluded that self-custody benefits not only individual holders but the broader Bitcoin network by distributing risk and preserving confidence among participants.
Casa, founded in 2018, provides multi-signature vault solutions designed for higher-value holders and institutions seeking practical self-custody.
The Coldcard incident has sparked renewed industry-wide discussion about single-signature hardware wallets, key generation practices, and the relative merits of multisig configurations alongside emerging covenant-based vault designs. The episode is also drawing attention to supply-chain security and firmware audit practices across hardware wallet manufacturers, an area that has received limited independent scrutiny compared to open-source software wallets. On-chain data cited by Neuman suggests that, regardless of the technical shortcomings of specific devices, the ability of holders to move funds independently ultimately limited the systemic impact of the exploit.
This article first appeared on Bitcoin Magazine and was written by Juan Galt.