All Crypto Blogs

Coldcard's $38 million (so far) exploit shakes faith in self-custody, may push investors to ETFs

coindesk.com · Jul 31, 2026 at 17:07

Coldcard's $38 million (so far) exploit shakes faith in self-custody, may push investors to ETFs
coindesk.com Jul 31, 2026

Long among Bitcoin's biggest selling points has been that investors don't need to trust banks and exchanges to safeguard their money.

That promise suffered one of its biggest blows — maybe ever — after a flaw in popular hardware wallet maker Coinkite's Coldcard allowed attackers to recreate wallet recovery phrases and steal bitcoin from what users believed were securely self-custodied wallets.

The flaw has since been patched but the fallout continues. Affected users must generate entirely new wallets and move their funds because updating the firmware alone doesn't eliminate the risk.

"If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further," wrote Coinkite CEO NVK in an open letter a short time ago. He added that while the fix protects new seeds going forward, it does not fix seeds already generated on vulnerable firmware.

The exploit exposes a growing tension as bitcoin enters the financial mainstream: self-custody remains one of the cryptocurrency's defining features, but the technical burden of securing private keys may increasingly push ordinary investors toward professional custodians, exchanges and regulated investment products instead.

Some prominent bitcoin advocates say the incident is among the most damaging failures of self-custody the industry has experienced.

"This is the worst hit in bitcoin history to the most knowledgeable and 'properly secured' bitcoiners," said Bitcoin commentator Guy Swann. "This isn't an exchange getting hacked because of hot keys. This is thousands of individuals having their personal private keys recreated out from underneath them."

For years, bitcoin advocates have argued that holding private keys removes the counterparty risk of centralized exchanges, a lesson reinforced by failures such as FTX. Analysts now argue that users have simply exchanged one set of risks for another.

"The self-custodial hardware space is a disaster at this point and creates more bad rep for the industry than anything else," said Lorenzo Valente, director of digital asset research at ARK Invest.

"In practice, consumers have traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk, and the possibility of losing everything through one mistake," he said. "Frankly, you are better off today holding funds across several publicly-traded exchanges or ETFs."

The Coldcard flaw illustrates that challenge. Researchers found that certain firmware versions generated wallet seeds using far less randomness than intended, making them susceptible to brute-force attacks.

"You just can't ask people to roll dice to be secure with your self custody," Casa CEO Nick Neuman said, referring to guidance that users supplement wallet-generated randomness with physical dice rolls. "It's a non-starter for 99% of people."

Source

This article is syndicated for educational reading. For the latest updates, visit the original publisher.

Read on coindesk.com

Recently Used