Unchained's Dhruv Bansal: The Coldcard Hack Proves Single-Signature Bitcoin Storage Is the Real Risk

A firmware flaw in Coldcard hardware wallets has become one of the costliest self-custody failures in Bitcoin's history, and it has forced a hard conversation about how everyday holders should actually store their coins. Dhruv Bansal, co-founder and CSO of Unchained, joined Simply Bitcoin to walk through what happened, why his firm's multisig clients came through largely unscathed, and what every self-custodied Bitcoiner should do next.
A WEEKEND THAT CHANGED THE SELF-CUSTODY CONVERSATION
Bansal called July 30 a date that will be remembered for years in Bitcoin circles. The vulnerability traces back to a code regression introduced in March 2021 within Coldcard MK3 devices manufactured by Coinkite. The flaw caused the wallets to generate recovery seeds with approximately 40 bits of entropy instead of the intended 128 bits. That gap let attackers reconstruct private keys without ever touching a victim's device. As of this week, Coldcard's developers have confirmed the exploit has drained as much as $114 million from self-custodied wallets, with the theft still active.
Bansal pushed back on the instinct to treat this as proof that self-custody itself is broken. He argued the actual lesson is narrower: any single device, vendor, or person is a point of failure, and Bitcoin's irreversibility means a single mistake anywhere in that chain can be unrecoverable. He noted that a meaningful share of all Bitcoin ever lost, not stolen, traces back to exactly this kind of single point of failure in the early, self-custody-only days of the network.
WHY MULTISIG CLIENTS CAME OUT AHEAD
Unchained's clients typically hold Bitcoin in a two-of-three multisig quorum, with two keys held by the client and a third held independently by Unchained, generated off any cold card device. Bansal explained that even clients who had used two Coldcards inside that setup were not immediately exposed, because knowing a compromised key alone was not enough for an attacker to locate the funds. Attackers had, in his words, the keys to the vault but not the map to where the coins actually sat, buying his clients time to migrate before ever broadcasting a transaction.
According to Bansal, a large share of Unchained clients holding Coldcards have already moved their funds to new vaults, and the clients who avoided any Coldcard entirely, or who paired one with a different manufacturer's device, were never really at risk. He said the episode reinforced a lesson Unchained had not pushed hard enough before the exploit: clients using multisig should mix hardware from different vendors rather than relying on multiple units from the same manufacturer.
SKIPPING THE MEMPOOL TO DODGE AN RBF ATTACK
The riskiest moment for multisig holders came at the point of recovery. Once a client broadcasts a transaction to move funds off a compromised device, that transaction becomes visible to everyone, including the attacker. For people using multi-signature setups, common among Coldcard users who split control of funds across several devices, broadcasting a transaction publicly reveals the wallet's keys and spending conditions, and an attacker already holding a matching weak private key can spot that transaction, build a competing one with a higher fee, and use Replace-by-Fee to jump the line and steal the funds first.
Unchained's fix was to route recovery transactions around that exposure entirely using Mara's Slipstream service. Because the transaction never touches the public mempool, an attacker never sees the keys or the spending details until the miner has already mined the coins into a confirmed block. Bansal said the feature had not even been on Unchained's roadmap until days before the exploit, but it let hundreds of clients and thousands of coins recover safely once it launched.
YOUR OWN MORTALITY IS A SINGLE POINT OF FAILURE TOO
Bansal's broader point extended past hardware. He said spreading keys across five wallets and five vendors does nothing if a holder dies and no one else can reconstruct the setup. He described building Unchained's own collaborative custody around solving inheritance for his own family, connecting relatives directly into shared vaults so that recovery does not depend on anyone finding a hidden seed phrase or remembering a device PIN.
WHAT TO DO NOW
Bansal's recommendation for anyone still holding significant Bitcoin on a single device, or a multisig setup built entirely on Coldcards, is straightforward: move to a multisig arrangement that spans multiple hardware vendors, and use a collaborative custody provider if setting that up alone feels too complex. He named Unchained, Casa and Anchorwatch as options, and gave a partial endorsement to the open source wallet Liana. He stopped short of recommending Nunchuk for now, citing the company's own disclosure that it had relied on Coldcard devices for entropy in some of its keys, a claim Simply Bitcoin has not independently verified beyond Nunchuk's own statement.
The specific claim that roughly 22,000 Bitcoin has moved from self-custodial wallets onto exchanges since the exploit was raised on the show and is attributed to that on-air discussion rather than confirmed here as a precise figure.
This story comes from the Simply Bitcoin Live show. Watch the full episode.


