Coldcard Exploit Exposes Self-Custody Weakness as DeFi Losses Soar
A recent exploit of the Coldcard hardware wallet has sent shockwaves through the Bitcoin community, causing an estimated $100 million in losses and raising concerns about the security of self-custody.
The flaw, which was caused by a 2021 firmware update that compromised seed generation, allowed attackers to drain funds from wallets without ever touching a physical device. The exploit, which began in July 2026, has affected over 7,300 addresses and may total up to $130 million if a suspected fourth wave is confirmed.
The incident highlights the growing security challenges facing the cryptocurrency ecosystem, particularly in decentralized finance (DeFi) and hardware wallets. DeFi exploits have resulted in staggering losses this year, with over $1 billion lost in the first half of 2026 due to operational failures, compromised keys, social engineering, and bridge vulnerabilities.
The use of artificial intelligence (AI) has also accelerated these threats, allowing attackers to process large amounts of data quickly and identify potential weaknesses. This has created an asymmetric advantage for attackers, who can now exploit vulnerabilities more efficiently than defenders.