Coldcard's $38 million (so far) exploit shakes faith in self-custody, may push investors to ETFs

A significant security flaw in Coldcard hardware wallets has allowed attackers to recreate recovery phrases, leading to $38 million in losses. The incident has sparked a debate about the risks of self-custody versus the safety of regulated financial products like Bitcoin ETFs.
Why it matters
This exploit undermines the core 'self-custody' value proposition of Bitcoin and may accelerate the shift of retail investors toward institutional custodians and regulated financial vehicles.
Long among Bitcoin's biggest selling points has been that investors don't need to trust banks and exchanges to safeguard their money.
That promise suffered one of its biggest blows — maybe ever — after a flaw in popular hardware wallet maker Coinkite's Coldcard allowed attackers to recreate wallet recovery phrases and steal bitcoin from what users believed were securely self-custodied wallets.
The flaw has since been patched but the fallout continues. Affected users must generate entirely new wallets and move their funds because updating the firmware alone doesn't eliminate the risk.
"If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further," wrote Coinkite CEO NVK in an open letter a short time ago. He added that while the fix protects new seeds going forward, it does not fix seeds already generated on vulnerable firmware.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in