Navigating an Emergency: Coldcard Vulnerability Incident Report
On July 31, 2026, Coinkite disclosed a serious vulnerability in Coldcard firmware: seeds generated on Coldcard devices since early 2021 may have been created with far less randomness than intended, leaving some keys weak enough that, in the worst cases, an attacker could reconstruct them. Coldcard is one of the most widely used hardware signers in Bitcoin, including among Nunchuk users, so we treated this as a full emergency from the moment it was confirmed.
We immediately assembled an emergency response team. Our number one priority was the safety of our clients’ funds.
We moved as fast as we could. Within minutes of confirming that the Mk4, Mk5, and Q models were also affected, not just the Mk3, we identified that the most immediately vulnerable funds were coins sitting at addresses that had already been spent from. Spending from an address publishes its public keys on-chain, and for a wallet with an affected Coldcard key, those exposed keys are exactly what an attacker would match against a database of cracked seeds to locate and target funds. We sent an advisory to our subscribers and to the public, urging them to move affected funds to fresh, never-used addresses. Within 48 hours, 99% of our clients’ potentially vulnerable funds had been moved to safe addresses.
We also identified that multisig quorums built entirely from Coldcard keys were the next most vulnerable, since an attacker could bruteforce the wallet descriptor and be able to see all addresses in the wallet, and with enough cracked keys, they could sweep the wallet. We reached out to these clients individually, explained the situation, and helped them migrate. Today, 97% of those funds have been moved to safety.
We enabled Slipstream integration across all platforms (Android, iOS, and desktop), so that subscribers with a Coldcard in their assisted wallet receive automatic protection against RBF-sniping when they migrate. This protects transactions in flight, including for funds that have not yet been migrated.
We pivoted completely away from Coldcard in our own infrastructure and regenerated our platform key at full 256 bits of entropy, independent of any hardware vendor.
We accelerated our existing conversations with additional hardware vendors to keep expanding the list of devices we support for our inheritance protocols.
As a result of this effort, to date no Nunchuk subscriber has lost any bitcoin to the Coldcard vulnerability, and the large majority of the most vulnerable funds have been migrated to safety.
What we learned
Every incident teaches you something. We want to share what this one taught us, in the hope that it helps strengthen the broader Bitcoin ecosystem.
The importance of not reusing addresses. Reusing addresses has always been discouraged for privacy, but this incident showed it’s also a first line of defense during a security breach, particularly for multisig. As long as even one key in your quorum remains uncracked, an attacker can’t reconstruct or locate your unspent addresses, because they’d need that key’s public key, which never appears on-chain until you spend. Address hygiene that many people treat as a privacy nicety turned out to be exactly what kept a large share of funds out of reach.
Key Replacement proved its worth. Our Key Replacement feature handles the hard parts of migration: choosing which keys to replace and which parts of your setup to keep, preparing the migration transactions so you’re not hand-entering destination addresses (error-prone at the best of times, more so under stress), and supporting coin control and randomized broadcast to preserve privacy. As far as we know, no other Bitcoin wallet offers this level of control through the migration process. We built it two years ago, before anyone asked for it, and during this incident we refined it further so it’s easy to follow from start to finish.
Over-communication in a crisis. We delivered urgent messages across three channels to the most affected users: email, push notifications, and in-app home-screen alerts. Going forward, we’re fine-tuning this alert system to be even faster and more responsive. The sooner we can notify users of a security issue, the more time they have to act before it becomes a loss.
This matters especially for a long-term savings solution like ours. Many of our users keep their cold storage genuinely cold, logging in only occasionally. A lot of them aren’t on social media and don’t follow Bitcoin news day to day. For them, a reliable alert reaching them directly can be the difference between acting in time and not hearing about a problem at all.
Why Nunchuk is different
During this emergency, many new clients joined us. We want to welcome them, and take the opportunity to explain to them and to prospective clients what makes Nunchuk different from other Bitcoin services and collaborative-custody providers.
Our service rests on four pillars:
- KYC-free
- No single point of failure
- Open standards
- Bitcoin-focused
We committed to these pillars because of a unique experience that shaped us: our part in the Freedom Convoy incident of February 2022. When the Canadian government moved against the protesting truckers and their supporters, we were served a Mareva injunction demanding that we disclose information about our users and freeze their funds. Many Bitcoin services voiced support for self-custody in principle but watched from a distance, unwilling to take on the protesters as users for fear of the government’s response.
That was the moment our vision of what Nunchuk should be became clear. The question we now ask of ourselves is simple: if an entity is powerful enough to compel us to disclose information about our users and freeze their funds — could we even do it? Can we and our clients withstand a state-level attack? And crucially, it’s not enough to be willing to say no. Our architecture has to make it so that we cannot comply in the first place.
That’s why we’re KYC-free. Your privacy is paramount. Anyone targeting you learns nothing about you even if they compromise Nunchuk, because we don’t hold that information. The one exception is that subscribers provide an email at signup (an anonymous address like Proton works fine), because we need a way to reach you during exactly the kind of security incident we just lived through. Last weekend made the case that this trade-off was the right one.
That’s why we insist on no single point of failure. In practice this means multi-vendor multisig as the foundation, and it also means ensuring our clients hold no hot keys. In collaborative custody, the provider already holds one key. If the client’s other keys included a hot key running in an app the same provider maintains, a forced or malicious software update could seize a majority of keys (in a 2-of-N setup) and sweep or freeze funds. A hot key would make life easier for us and our users, but it would fail the standard we set for ourselves in 2022. So we made the harder choice and disabled it entirely.
This design philosophy is, in many ways, what protected our clients and us during this incident. Despite a catastrophic flaw in one of the most widely used hardware signers, and despite weakened entropy in some keys, no client lost bitcoin (including those who used the Mk3, the most severely affected model). We have room for improvement, but the architecture proved highly resilient under real stress.
That’s why we build on open standards. In the worst case, you can always migrate your Nunchuk setup to other software that follows the same Bitcoin standards, such as Sparrow. The exit door stays permanently open, even if Nunchuk were to disappear tomorrow.
That’s why we’re Bitcoin-focused. Bitcoin is what we build for, and what we build on, including its Layer 2 system. The wider “blockchain” industry, with many centralizing points of failure, whether explicit or implicit, has proven throughout the years that it cracks under real pressure. We chose depth over breadth, and quality over quantity.
These are the reasons Nunchuk stands apart from other services in Bitcoin.
Closing
If February 2022 forged our DNA, August 2026 strengthened our resolve and our architecture. We came through both better than we entered them, and we learned more about who we are.
To the users who had to make an emergency migration: we’re sorry you had to go through that. And to all of our users and supporters who stood with us through this incident: thank you. We’ll keep moving forward with our vision intact and our conviction stronger than ever — forged, and refined, in a crisis.
