Coldcard Exploit Reverses Self-Custody Trend, Draining $118 Million
A major vulnerability in Coldcard hardware wallets has led to four coordinated attack waves draining an estimated $118 million from affected users, reversing the trend of self-custody adoption sparked by the FTX collapse.
The exploit stems from a firmware build error present since March 2021 that reduced seed entropy from 128 bits to approximately 40 bits on Mk3 devices and 72 bits on Mk4/Mk5/Q models, making private keys guessable through brute force. Every Coldcard owner who generated a seed on affected firmware must create a new seed on patched hardware and migrate their funds.
The net transfer of bitcoin from self-custody wallets to exchange addresses has been positive every day since July 31, according to on-chain flow data, with Galaxy Research tracking 5,294 affected addresses. The users moving bitcoin to exchanges are not panicking retail investors but rather technically sophisticated holders who chose Coldcard for its security features.
The narrative shift frames self-custody as a risk rather than a solution, benefiting companies that hold bitcoin through institutional custody like Strategy and Coinbase Custody.