Coldcard Exploit: Self-Custody Just Lost Its Argument
The irony is architectural: the exploit does not just cost individuals $38 million.
Coldcard Exploit: Self-Custody Just Lost Its Argument
A software vulnerability in Coldcard, one of the most widely trusted hardware wallets in Bitcoin's self-custody ecosystem, has now drained nearly 600 bitcoin — approximately $38 million and rising — from users who believed their holdings were beyond institutional reach, according to CoinDesk.
The breach does not involve an exchange hack or a phishing attack. It originates inside the device itself, which is precisely why it matters. Coldcard built its entire market position on the proposition that holding your own keys is safer than trusting a custodian. That proposition is now the central exhibit in a very uncomfortable argument.
What follows from here is predictable and worth naming plainly. Retail investors who moved to self-custody after the FTX collapse — the exact population Coldcard was designed to serve — are now being pushed back toward Bitcoin ETFs, where BlackRock and Fidelity hold the keys and regulators set the rules. The irony is architectural: the exploit does not just cost individuals $38 million. It costs the self-custody movement the one thing it could never afford to lose, which is proof of concept.
No criminal arrest has been confirmed. No patch timeline has been publicly committed to. The affected wallets remain exposed while the investigation continues.
For any Maltese investor holding hardware wallets: verify your device firmware version immediately against Coldcard's official security advisory, transfer holdings to a clean address if your version falls within the affected range, and do not wait for a second announcement to act.