APX Lending has 0 exposure to the Coldcard exploit
Our borrowers also have 24/7 visibility into their collateral, both on-chain and through the APX platform. No guess work, no questions, full and absolute transparency.

The Coldcard vulnerability does not affect collateral held with APX Lending.
The exploit involved seeds generated using vulnerable Coldcard firmware. APX Lending does not use Coldcard devices or single-signature self-custody wallets to secure borrower collateral.
APX Lending borrower collateral is held in segregated, cold-storage, multi-signature wallets with BitGo covered by up to $250M in insurance.
As a CSA-regulated entity, we have in place the most robust policies, procedures and security protocols and since launching in 2023 we have had 0 collateral losses to date.
Our borrowers also have 24/7 visibility into their collateral, both on-chain and through the APX platform. No guess work, no questions, full and absolute transparency.
What caused the Coldcard exploit?
The Coldcard exploit was not a failure of cold storage generally. It was caused by a firmware error affecting how Coldcard cold wallets generated wallet seeds.
A firmware integration error introduced in March 2021 routed seed generation through a deterministic software random-number generator instead of the device’s hardware random-number generator. The software fallback relied on non-secret chip and timing information, substantially reducing the randomness of the resulting seeds and making it possible to guess offline.
By the morning of August 3, losses were estimated to be about 1,816 BTC, worth roughly $114 million, from more than 5,200 addresses. Because the attack remains under investigation, these numbers may continue to change.
Coinkite has released patched firmware for the affected models. However, installing the update does not repair a seed that was previously generated using vulnerable firmware. Affected users must generate a new seed using patched firmware and migrate their funds.
This incident is a reminder that custody architecture matters. Before taking out a Bitcoin-backed loan, borrowers should understand:
Have questions about how your assets are held with APX? Reach out to our team today at support@apxlending.com
This article is for informational and educational purposes only and does not constitute legal, financial, investment, or tax advice. APX Lending does not provide investment or tax recommendations. Borrowers should consult qualified professionals and conduct their own due diligence before entering into any crypto-backed lending arrangement.
The Coldcard vulnerability does not affect collateral held with APX Lending.
The exploit involved seeds generated using vulnerable Coldcard firmware. APX Lending does not use Coldcard devices or single-signature self-custody wallets to secure borrower collateral.
APX Lending borrower collateral is held in segregated, cold-storage, multi-signature wallets with BitGo covered by up to $250M in insurance.
As a CSA-regulated entity, we have in place the most robust policies, procedures and security protocols and since launching in 2023 we have had 0 collateral losses to date.
Our borrowers also have 24/7 visibility into their collateral, both on-chain and through the APX platform. No guess work, no questions, full and absolute transparency.
What caused the Coldcard exploit?
The Coldcard exploit was not a failure of cold storage generally. It was caused by a firmware error affecting how Coldcard cold wallets generated wallet seeds.
A firmware integration error introduced in March 2021 routed seed generation through a deterministic software random-number generator instead of the device’s hardware random-number generator. The software fallback relied on non-secret chip and timing information, substantially reducing the randomness of the resulting seeds and making it possible to guess offline.
By the morning of August 3, losses were estimated to be about 1,816 BTC, worth roughly $114 million, from more than 5,200 addresses. Because the attack remains under investigation, these numbers may continue to change.
Coinkite has released patched firmware for the affected models. However, installing the update does not repair a seed that was previously generated using vulnerable firmware. Affected users must generate a new seed using patched firmware and migrate their funds.
This incident is a reminder that custody architecture matters. Before taking out a Bitcoin-backed loan, borrowers should understand:
Have questions about how your assets are held with APX? Reach out to our team today at support@apxlending.com
This article is for informational and educational purposes only and does not constitute legal, financial, investment, or tax advice. APX Lending does not provide investment or tax recommendations. Borrowers should consult qualified professionals and conduct their own due diligence before entering into any crypto-backed lending arrangement.