- A Coldcard firmware flaw enabled attackers to steal nearly 600 bitcoin worth about $38 million, one of the biggest failures of Bitcoin self-custody.
- Security experts warn that the hack underscores growing operational risks in self-custody as cyber threats evolve, including software, hardware, and supply-chain risks.
- The incident may accelerate the shift toward regulated custodians and spot Bitcoin ETFs, with some analysts advising investors to hold funds on exchanges or ETFs instead of managing private keys.
- Affected users must generate entirely new wallets and move funds, as updating firmware alone does not fix existing vulnerable seeds.