If you held funds in a Coldcard hardware wallet and have seen them disappear over the past few weeks, this is not a case of phishing or user error. Coinkite, the device’s manufacturer, has publicly acknowledged that certain firmware versions generated cryptographic seeds with insufficient randomness, allowing third parties to reconstruct private keys and drain wallets without any security mistake on the user’s part. Confirmed losses already exceed 1,300 BTC — around $90 million — spread across thousands of affected addresses.
This changes the legal picture entirely: this is not theft caused by the owner’s negligence, but — allegedly — the consequence of a defect in a device that was marketed specifically to provide security.
Do you have a claim?
If your wallet was generated using an affected firmware version and you lost funds, you may have several avenues open to you, depending on your circumstances:
1. Defective product. The device was marketed as a tool to safely custody digital assets. If the defect existed at the time of sale and was the direct cause of the loss, you may be entitled to claim damages arising from that defect.
2. Breach of contract. Purchasing a hardware wallet carries an implicit expectation of a reasonable level of security in key generation and custody. A manufacturer’s failure in that essential function may amount to a breach of contract.
3. Tort / negligence liability. Even without a direct contractual relationship, a negligence claim may be available if it can be shown that the defect was avoidable through adequate technical controls.
4. The full value of the bitcoin lost — not just the price of the device. If the device’s sole purpose was to custody your bitcoin, the recoverable damages could extend to the full value of the stolen funds, plus interest and other proven losses.
5. Additional damages. Depending on your case, you may also be able to claim blockchain investigation costs, asset recovery expenses, loss of profit, or lost investment opportunity.
6. Joint action with other victims. Given the scale of the incident, collective claims are likely to emerge. Coordinating with other affected users can strengthen each claimant’s position and reduce costs.
Why this case is different from other crypto thefts
Most crypto litigation to date has centered on exchanges, fraud, or scams. Here the question is different: whether the manufacturer of a device whose sole function was to protect your private keys should be held liable when that function fails due to its own defect. This is largely uncharted legal territory, which is exactly why specialised advice from the outset — and careful documentation of your loss — matters.
What to do now
- Do not enter your seed phrase into any third-party website or tool claiming to “check” whether you are affected.
- If you still hold funds on a Coldcard running older firmware, follow Coinkite’s official instructions to migrate to a newly generated seed before doing anything else.
- Gather all available evidence: affected addresses, balance screenshots, transaction IDs, and a timeline of events.
- Contact us to have your specific case assessed.
Ferrer-Bonsoms & Sanjurjo is a law firm specialised in FinTech, Blockchain and crypto-assets law, and a founding member of the Blockchain Arbitration Society. We are actively analysing the Coldcard case from its origin and can help you assess whether your situation gives rise to a claim.
