A fresh hardware-wallet exploit has reignited criticism of crypto's security culture, with prominent analyst Benjamin Cowen arguing that scam memecoins and repeated custody failures continue to erode trust in the asset class even as institutional adoption grows.
The comments follow the disclosure of a firmware vulnerability in Coldcard hardware wallets that allowed attackers to drain approximately 594 BTC, worth roughly $50 million at current prices, from around 500 wallets. Many of the compromised addresses had sat untouched for years before being rapidly emptied, and the stolen funds were consolidated into a single address, a pattern that points to coordinated theft rather than scattered opportunistic hacks.
How the Coldcard Exploit Worked
According to details circulating after the disclosure, the vulnerability traced back to Coldcard's seed generation process. Affected firmware versions reportedly relied on predictable inputs rather than genuine hardware entropy when creating wallet seeds, giving attackers a path to reconstruct private keys and empty wallets that owners had assumed were secure through self-custody.
The scale of the breach struck a nerve precisely because Coldcard wallets are marketed as an air-gapped, security-first option for Bitcoin holders who want to keep funds off exchanges. That the exploit hit long-dormant wallets, some untouched for years, only sharpened the sense that even careful, security-conscious users were not immune.
Related: Celah Firmware Coldcard Kuras $89 Juta Bitcoin dari 4.500 Lebih Wallet
An Analyst Who Rarely Comments Speaks Up
Cowen, known for typically steering clear of day-to-day news commentary, broke from that pattern to address the fallout directly.
I don't comment on the news very often, but it's devastating to see so many people lose so much Bitcoin while doing what they thought was the right thing.
His broader point extends beyond this single incident: he argues the crypto industry remains dominated by scam memecoins and recurring security failures that collectively undercut its credibility with newcomers. In his view, no amount of technological progress fully offsets the reputational damage done every time a widely trusted security product turns out to have a critical flaw.
Why This Keeps Happening
The Coldcard incident adds to a long list of custody failures that have shaped public perception of crypto as a high-risk asset class, regardless of how far the underlying technology has matured. For a segment of the market, cold storage hardware has always represented the gold standard of self-custody, precisely the opposite of the leverage-driven memecoin speculation Cowen also singled out for criticism.
Cowen's conclusion is blunt: until the industry meaningfully reduces both the volume of scam-driven speculation and the frequency of security breakdowns in tools users are told to trust, mainstream perception of crypto as too risky for everyday use is unlikely to change.