Coldcard Hack Exposes Vulnerabilities in Self-Custody Security
The recent Coldcard wallet hack has left many wondering about the safety of storing Bitcoin. According to Galaxy Research via Alex Thorn, over $130 million worth of BTC was stolen from wallets that were supposed to be secure cold-storage addresses. The hack occurred on July 30 and lasted for just 41 minutes, with 1,083 BTC disappearing during this time.
Investigation revealed that the attackers used an automated tool to work through a list of wallets, exploiting weaknesses in some Coldcard devices' seed phrase generation. This vulnerability allowed the attackers to guess possible seeds more easily, making it a realistic task for powerful computers. The key point is that the self-custody users did not make a mistake, their setup was vulnerable.
The hack highlights the trade-off between self-custody and professional custody. Self-custody gives users full control but also puts the responsibility on them to manage every security aspect, including seed phrase generation, backups, hardware, software, recovery plans, and transactions. On the other hand, professional custody takes care of these tasks, providing multiple layers of security checks and people involved in handling the Bitcoin.
Ledn is a company that offers an indirect way to get professional, institutional-grade custody by storing Bitcoin in cold storage with BitGo. This setup provides more checks, people involved, and layers between one mistake and the Bitcoin moving. While this may not eliminate risks entirely, it does shift the responsibility from individual users to a team of professionals.