ADVERT
World4 min(s) read
Published 10:29 13 Aug 2026 GMT
A man who stored his Bitcoin on a device specifically designed to make it unhackable has had all of it stolen after a software bug gave criminals a way in.
Jonathan Goodman owned 18.25 Bitcoin, worth $1.6 million Canadian.
He had been buying since the end of 2020. He kept his seed phrases on a Coldcard hardware wallet made by Canadian company Coinkite and locked it inside a safe-deposit box.
He thought he had done everything right.
On July 31, he sat down at a library computer to check his account and discovered that all three of his wallets had been emptied two days earlier, between 9:36pm and 9:43pm on July 29.
Seven minutes to lose everything he had spent four years building.
Coldcard devices store seed phrases offline - that is the whole point.
The seed phrase is the key to a crypto wallet, and if nobody can reach it digitally, nobody can steal what is inside.
Except Coinkite announced last month that a software bug in their firmware had allowed hackers to reconstruct seed phrases remotely, without ever needing physical access to the device.
The bug affected an unknown number of Coldcard units. Over $100 million in Bitcoin has been stolen as a result.
Goodman never shared his phrase with anyone. His device never left the safety deposit box. None of that mattered.
"My incorrect assumption was that the only way to get my seed phrase would have been to gain access to my Coldcard device," he told LADbible.
He was scrolling Facebook at the library when he saw a friend post about the hack.
His first thought was that it probably didn't affect him. He saw stories about hacks online every day.
Then he remembered his Bitcoin was on a Coldcard.
He opened the Wasabi software he uses to view his wallets.
It took a couple of minutes to load because he rarely opens it.
The moment it did, he saw red lines for withdrawals across all three accounts.
"It took a minute or two to load because I don't open it often," he said.
"The moment it loaded I knew I was screwed because I saw red lines for withdrawals."
Then he had to go home and tell his wife.
"I have some really bad news," he told her.
"What?"
"All of our Bitcoin was stolen."
"What the [expletive]. How could that even happen?"
He explained as best he could.
As far as he had known, everything was '100 percent secure and stored offline in a safety deposit box'.
A friend who was deep in the crypto space had recommended Coldcard as an extra layer of protection. Until last month, experts had praised it as one of the safest ways to store sensitive information.
Coinkite has told customers to move their funds to new wallets immediately if their seed was generated using the affected firmware.
"We understand there is real anger at this moment," the company said in a statement.
"Users have suffered real losses, and for those impacted, no public statement is enough."
They added: "We also believe this vulnerability is a warning for every company building Bitcoin hardware and software, not only us."
The company has advised that users whose seed phrases were generated without at least 50 independent dice rolls and without a strong BIP-39 passphrase should consider their wallets compromised.
Goodman has gone to the police.
He says they have been 'great' and told him that arresting the people responsible is a priority. Whether any of the money can actually be recovered is a different question entirely.
He says he is done with crypto.
No more Bitcoin. No more of any of it.
That's understandable when you consider he did everything he was told to do, stored his keys on a device built specifically to be secure, locked the thing in a safe-deposit box, never showed it to a soul, and still lost the lot because of a bug in someone else's code.