Crypto Self-Custody Faces Reckoning After $130M Coldcard Hack
The cryptocurrency space experienced a rollercoaster of events in August 2026, particularly for users who invested in hardware wallets. A bug in the Coldcard device allowed attackers to steal up to $130 million worth of Bitcoin directly from users, making it the largest hardware wallet exploit to date.
This was followed by similar attacks on Trezor and SafePal, two other major hardware wallet providers. While no funds were compromised in these attacks, personal data and physical addresses were leaked, leaving customers vulnerable to targeted attacks and phishing scams.
The recent events have raised concerns about the security of self-custody, a practice that involves storing cryptocurrency privately. However, experts argue that the flaws were limited to specific brands and products, rather than the concept of self-custody itself.
To mitigate risks, users are advised to adopt backup redundancy, multisignature wallets, and other security measures to protect their assets. In particular, it's essential to understand how keys are created, where backups live, and what happens when a device fails.