Coldcard Hack Exposes Self-Custody Security Myth
A major security crisis has shaken the crypto industry, highlighting the vulnerability of self-custody wallets.
On July 30, hackers drained $110 million from thousands of Bitcoin addresses using a previously unknown flaw in Coldcard's firmware. The exploit was buried in the v4.0.1 update released in March 2021 and allowed hackers to brute-force private keys generated during that time period.
The attack was highly automated, with the hacker emptying 1,196 victim addresses in just 41 minutes and transferring over $70 million before Coldcard issued an emergency security warning 30 hours later. The attacks continued for multiple rounds, with the hacker using the Replace-by-Fee (RBF) mechanism to prioritize transactions.
The community responded quickly, using AI-powered code auditing tools to pinpoint the vulnerability in just 8 minutes. The incident has sparked a discussion about the security of self-custody wallets and the need for diversification and multi-signature coordination.