A firmware vulnerability in Coinkite's Coldcard hardware wallet has been exploited to steal roughly 600 bitcoin, worth approximately $38 million, with the total continuing to climb as researchers trace additional affected wallets. The flaw allowed certain firmware versions to generate seed phrases using insufficient randomness, leaving them susceptible to brute-force attacks.
Coinkite CEO NVK issued urgent guidance to users in the wake of the disclosure, writing that anyone who generated a seed on a Coldcard should move their funds immediately using the company's updated best practices. He clarified that the firmware patch only protects newly generated seeds — wallets created before the fix remain vulnerable even after updating.
A Blow to “Properly Secured” Bitcoiners
The incident has rattled a segment of the Bitcoin community that considered itself insulated from exactly this kind of loss. Bitcoin commentator Guy Swann called it “the worst hit in bitcoin history to the most knowledgeable and ‘properly secured’ bitcoiners,” noting that victims had their personal private keys effectively recreated by an external party rather than lost through phishing or exchange failure.
Casa CEO Nick Neuman pushed back on some of the recommended mitigations, arguing that requiring users to supplement device-generated randomness with physical dice rolls is unrealistic for mainstream adoption. Taproot developer Udi Wertheimer echoed the concern, saying the idea of bitcoin “resting easy in some secret location while you enjoy life not worrying about it is currently unrealistic,” and suggesting holders either monitor their setups constantly or defer to professional security teams.
Related: Bulan Terburuk Bitcoin? Sejarah Isyaratkan Agustus yang Berat
Custody Risk Versus Counterparty Risk
The exploit has reopened a long-running debate over whether self-custody is worth the operational burden it places on individual holders. ARK Invest director Lorenzo Valente argued that self-custody advocates have understated the trade-off, saying consumers “have traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk, and the possibility of losing everything through one mistake.”
Blockaid research cited in the report found that most crypto losses in the first half of 2026 stemmed from compromised keys and operational failures rather than smart-contract bugs. Blockaid co-founder Ido Ben-Natan said the episode is a reminder that “a hardware wallet's security ultimately comes down to the firmware and systems users interact with but never see.”
Could This Push More Money Into ETFs?
Amicus co-founder David Lawrence predicted the exploit will accelerate adoption of regulated products such as BlackRock's iShares Bitcoin Trust (IBIT), suggesting that “I'm safer to just buy IBIT” will increasingly resonate with newer investors weighing the risks of holding keys themselves. He framed the episode as a potential setback for the broader vision of widespread personal cold storage.