Coldcard Exploit Exposes Limits of Self-Custody
The recent Coldcard exploit has drained over $83 million from thousands of Bitcoin wallets, highlighting the limitations of self-custody.
The incident has sparked conversations about how users approach self-custody, with security researcher Jameson Lopp arguing that it doesn't invalidate the principle but rather exposes its limits.
Lopp noted that verification of complex software and hardware is not feasible for most people, saying 'it's a good mantra... But you have to understand that verification of complex software and hardware is simply not feasible for 99.9% of the population.'
The Coldcard vulnerability was introduced in its seed-generation process in 2021, reducing entropy used in randomizing wallet seeds and allowing attackers to brute-force affected wallets remotely.