Unlike the FTX collapse, the $89 million Coldcard exploit has investors sending bitcoin back to exchanges

A security vulnerability in Coldcard hardware wallets has led to the theft of approximately $90 million in Bitcoin, prompting users to move their assets back to centralized exchanges. The exploit stems from a firmware bug that weakened the randomness of seed phrase generation.
Why it matters
The incident challenges the narrative of self-custody safety in the crypto industry and highlights the risks associated with hardware wallet vulnerabilities.
Now they are doing the opposite by moving coins to exchanges, as the ongoing multi‑million‑dollar Coldcard hardware‑wallet incident, which began Friday, has raised fresh questions about the safety of self‑custody.
"Daily exchange deposits of Bitcoin transfers < 10 BTC spiked yesterday [Friday] to 7.3K BTC, the highest since February 6. Could be related to the coldcard hack, as people move their holdings looking for safety," Julio Moreno, head of research at blockchain analytics firm CryptoQuant, said.
Coldcard, the Bitcoin‑only hardware wallet made by Canadian firm Coinkite, is facing one of its biggest security incidents after a firmware bug quietly weakened how some devices generate seed phrases.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in