Last week’s ongoing Coldcard exploit has already drained more than 1,300 bitcoin, worth roughly $83 million, from thousands of addresses across multiple waves, making it one of the biggest self-custody failures in Bitcoin history.
The incident has sparked broader conversations about how users should approach self-custody.
Shifting trust
For Bitcoin security researcher and Casa co-founder Jameson Lopp, the exploit doesn’t invalidate self-custody, but it does expose the limits of one of Bitcoin’s oldest principles: “Don’t trust, verify.”
Speaking on The Block’s The Starting Block podcast, Lopp said:
“It’s a good mantra … But you have to understand that verification of complex software and hardware is simply not feasible for 99.9% of the population.”
The Coldcard vulnerability was introduced in its seed-generation process in 2021, reducing the entropy used in randomizing wallet seeds and allowing attackers to brute-force affected wallets remotely.
Galaxy Digital head of research Alex Thorn noted researchers have identified up to a potential fourth wave of thefts since the flaw became public.
Responsibility of self-custody
Lopp argued users inevitably end up trusting hardware vendors, developers, and researchers to validate systems they cannot audit themselves.
“The entire point … is to not trust any one thing. Not trust any one hardware vendor, not trust any one piece of software.”
AI and wallet security
Lopp believes AI likely accelerated discovery of the vulnerability, reshaping the security landscape for both attackers and defenders.
That echoed CoinKite CEO Rodolfo Novak, who took responsibility for the firmware bug and called it “a sober reality of the new AI paradigm.”