René Pickhardt, a Bitcoin researcher and prominent Lightning Network developer based in Germany, says he deliberately kept his personal Bitcoin holdings small for years — not because he doubted the asset's upside, but because he never trusted himself to keep it safe.
Despite its potential upside, I never bought much Bitcoin because security & key management always freaked me out.
Pickhardt added that he had been “too ashamed” to admit the concern publicly until now. His confession landed just as that fear was being validated at scale: Coinkite, maker of the Coldcard hardware wallet, disclosed that a build-time bug had silently swapped its dedicated hardware random-number generator for a predictable software fallback seeded from each device's own serial number and internal timer — values an attacker could reconstruct without ever touching the wallet.
A Five-Year-Old Bug With a Nine-Figure Price Tag
The flaw traced back to March 2021, and by the time it surfaced, attackers had already moved. Starting July 30, 2026, thieves drained roughly 1,816 BTC — about $116 million — from more than 5,200 addresses across four separate waves, the most aggressive of which emptied 1,196 addresses in just 41 minutes. Other trackers have put the toll even higher: TRM Labs and TechCrunch reported combined losses topping $130 million across at least twelve distinct threat actors by August 4, while Galaxy Research's more conservative count put confirmed losses at $88.6 million across 4,585 addresses. The spread reflects how hard it's been to fully map the exploit's reach, not disagreement that it's one of the largest hardware-wallet incidents on record.
Related: Coldcard's Five-Year RNG Flaw Linked to $116M Bitcoin Theft
The Tradeoff Pickhardt Was Actually Weighing
Pickhardt's stated worries — private key storage risk, software vulnerabilities, and the possibility that some future technological advance could compromise a seed he generated years earlier — read less like caution now than an accurate description of exactly what happened to Coldcard users. Blockstream CEO Adam Back framed the underlying tension bluntly: “with great bearer cash power comes great responsibility to not lose your keys.” For a developer who has spent his career building payment infrastructure on top of Bitcoin, the irony of sitting out its price appreciation over a risk that turned out to be real isn't lost on him.
What It Means for Everyone Else
Coinkite has since patched the firmware and is urging anyone who generated a seed on an affected device between March 2021 and the fix to treat it as compromised and migrate to a freshly generated wallet. For self-custody advocates, the episode cuts against a core selling point — that holding your own keys removes counterparty risk — by showing that the device meant to secure those keys can quietly fail at the one job it has, for years, without anyone noticing.