Coldcard's $38M (so far) exploit shakes faith in self-custody
4 hours ago
- A Coldcard firmware flaw enabled attackers to steal nearly 600 bitcoin worth about $38 million, one of the biggest failures of Bitcoin self-custody.
- Security experts warn that the hack underscores growing operational risks in self-custody as cyber threats evolve, including software, hardware, and supply-chain risks.
- The incident may accelerate the shift toward regulated custodians and spot Bitcoin ETFs, with some analysts advising investors to hold funds on exchanges or ETFs instead of managing private keys.
- Affected users must generate entirely new wallets and move funds, as updating firmware alone does not fix existing vulnerable seeds.
- The exploit highlights the tension between Bitcoin's self-custody ideal and the rising technical burden on ordinary investors, pushing them toward professional custodians.