Jonathan Goodman kept his 18.25 BTC on a Coldcard that had never touched the internet, locked in a safety deposit box. Between 9:36 pm and 9:43 pm on July 29, every wallet he had was emptied — about $1.6 million Canadian dollars, gone in seven minutes.

"Perhaps the hardest part about this is that I did everything right," the Canadian entrepreneur wrote on X in a post that has drawn 7.6 million views. "I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes. None of it mattered."

Goodman's account is one of dozens filling X and the Bitcoin subreddit since the Coldcard exploit surfaced on July 30, and they share a refrain: the victims followed the self-custody playbook. They bought a hardware wallet from a respected manufacturer, generated seeds offline, stamped backups into steel, and never typed a seed phrase into a connected device.

A firmware bug that made Coldcard-generated seeds guessable rendered all of it moot — attackers have swept roughly 1,816 BTC, worth some $114 million, from more than 5,200 addresses across four waves of coordinated sweeps.

Goodman said he learned of the hack days after the fact, at his cottage, and checked his balances expecting nothing. "Right away I saw lines of red transaction–withdrawals–and I knew," he wrote. He is filing a police report and a report with the Ontario Securities Commission, but doesn't expect to recover anything.