Seventy million dollars. Gone from a Coldcard—the exact device Bitcoin's most paranoid users called the gold standard of self-custody hardware. Galaxy Research's initial loss estimate was rough. The revised number nearly doubled. That upward revision alone tells you everything about how badly the market misjudged what actually happened.
CZ saw the truth coming. Or at least, he said the thing nobody wanted to repeat out loud: "Nothing is 100%." The man who built Binance, who spent the better part of the last cycle grinding through the American regulatory meat grinder, who knows more about where crypto assets actually die than almost any human on the planet, said what should have been obvious a decade ago.
Bitcoin's coldest, most trusted storage just produced a seventy-million-dollar fire.
The immediate reaction from the self-custody crowd was predictable: blame the user. Blame the signing environment. Blame anything but the device. But the numbers don't lie. The exploit happened. The money moved. And if you built your entire security model on a single assumption, you need to learn exactly when that assumption breaks—before it breaks, not after.
I've been here before. Not with Coldcard, but with code everyone trusted.
Coldcard's reputation was earned, not marketed. Coinkite built a device that treats paranoia as a design philosophy. Air-gapped signing via microSD. Open-source firmware that security researchers can actually read and audit. A secure element engineered to resist side-channel extraction. Duress PINs, BIP39 passphrases, and a general attitude that says "we assume you're being targeted, so we built accordingly." For the "I don't trust anything with a network connection" demographic, Coldcard was the end of the search.
This is the wallet you're told to buy when you say "I'm moving serious Bitcoin off the exchange." It's the device you choose after reading the comparative horror stories across the hardware wallet landscape. Coldcard wasn't for casuals. It was the choice for users who wanted to eliminate every single point of failure they could identify.
And it still got cracked.
Here's what we don't know: the technical root cause. The original reporting never disclosed the specific vulnerability, and independent researchers are still piecing together the attack path. Was it a supply chain compromise, with devices tampered with before delivery? A firmware bug that opened a signing-time exploit? A side-channel attack against the secure element? Or a compromised signing environment, where the computer feeding transactions to the wallet was already owned?
Without the details, we're auditing a vault while the door is still open.
Here's what we do know: Galaxy Research estimated the losses at roughly $70 million. And that figure was significantly higher than the first estimates, which means the incident is still expanding. This wasn't a dust attack or a lone user losing a backup. This was a targeted, large-scale exploitation of the most trusted consumer security device in the Bitcoin ecosystem.
When the paranoid hyper-cypherpunk security hardware fails, the entire industry needs to update its threat model. Including the people who mocked the less paranoid. Including the people who built their entire personal security doctrine around a single plastic-and-metal device.
The right frame here is trust chains, because that's what actually broke.
A hardware wallet is not a single device. It's a stack of assumptions, each one load-bearing. The silicon foundry that manufactured the secure element has to be honest. The factory that flashed the firmware has to be uncompromised. The integrity check that verifies the device hasn't been altered before first use has to be sound. The signing routine that derives keys from your seed phrase has to be correct. The PIN and passphrase you enter have to be observed by no one. The USB or microSD path that carries the transaction payload has to be clean. The computer on the other end that constructed that transaction has to be uncompromised.
Break any single link, and the phrase "cold storage" becomes warm storage with extra steps.
We don't know which link snapped in this case. But the framing matters far more than the specific exploit vector, because the market had priced Coldcard as an unbreakable vault. In reality, it was a vault with an excellent lock—and the attacker found a way to compromise the process surrounding the lock, rather than the lock itself.
That distinction is the entire lesson.
In 2020, I spent three weeks as a part-time security advisor stress-testing an AMM protocol's bonding curve against flash loan attacks. I found a reentrancy vulnerability in the liquidity withdrawal function that would have allowed an attacker to drain a meaningful chunk of the pool. The bug didn't come from broken math. It came from an assumption about execution semantics—the code assumed state changes happened atomically, so it checked a balance and performed a withdrawal without accounting for the possibility that the withdrawal itself could trigger another execution before the first one finalized.
The exploit I found wasn't a hack of the math. It was a hack of the trust model.
This Coldcard incident is the same shape. The Bitcoin ecosystem assumed that a hardware wallet was a trusted execution environment in the strongest possible sense. Every interaction—seed generation, address derivation, transaction signing—was assumed to happen in a way that couldn't be observed or influenced by an attacker.
That assumption was always too strong. This event just proved it in public.
What makes it worse is the cultural laziness that accompanied the hardware wallet boom. Bitcoin's security narrative was built on the principle of "don't trust, verify." But the industry sold hardware wallets as a "set it and forget it" solution. Buy the device. Write down the seed. Bury it in a safe. Never think about it again. The verification rituals—confirming the address on the device screen matches the address on your computer, comparing the device fingerprint at first initialization, running a small test transaction before moving serious funds—were treated as optional paranoia for the deeply suspicious.
This is precisely the mistake I watched compound in 2017. During the ICO mania, I launched a white-label token called ZurichChain with a persuasive narrative about decentralized sovereignty. I had a cryptography background and zero product experience, and that didn't matter at all—we raised $4.2 million in 48 hours because investors didn't want to verify. They wanted to believe. The market rewarded narrative velocity and punished verification as a form of hesitancy. The people who asked hard questions were mocked for missing the boat.
That's how seventy million dollars disappears from a Coldcard. Somewhere in the chain, a verification step was skipped. Or a verification mechanism was compromised. Either way, the outcome is the same: single-point trust, in a system that was designed to eliminate single-point trust.
CZ's public warning to spread funds across multiple wallets is not just a safety tip. It's an institutional acknowledgment that self-custody is not a binary state—you don't either trust yourself or trust an exchange. You design an architecture with layers of redundancy, and you assume that any individual layer will eventually fail.
This is the same shift I documented in my report "The Illusion of Seamless Interoperability," written after leading a hackathon where we built cross-chain bridges in 72 hours and watched them fail in predictable ways. The bridges didn't break because cryptography failed. They failed because trust was concentrated in a single messaging layer, and the entire ecosystem treated that layer as infallible.
Bitcoin self-custody has the same disease. The market treated the hardware wallet as an infallible layer. The Coldcard exploit just proved—with seventy million dollars of evidence—that no layer is infallible.
Now let's talk about the number itself, because the multiplier matters more than the headline.
Seventy million is material but not systemic. Bitcoin's daily trading volume dwarfs that figure by orders of magnitude. The price impact of a single wallet compromise is likely to be muted. The market has absorbed worse.

But the fact that Galaxy Research's initial estimate nearly doubled is the real signal. When a security incident keeps growing after the first disclosure, you should assume the attacker's access was broader than initially understood. You should assume there may be more victims who haven't yet come forward. You should assume the attack infrastructure is still active.
That's not FUD. That's base-rate reasoning from incident response. In every major exploit I've traced—whether it was a bridge hack, a smart contract drain, or the collapse of a lending protocol—the first numbers were always the wrong numbers. The pattern is consistent: initial underestimate, painful correction, slow reveal of systemic implications.
The other side of this is narrative. A security event like this doesn't exist in isolation. CZ's visibility gives the warning reach into mainstream crypto discourse. A former Binance CEO issuing a public statement that "nothing is 100%" is the kind of soundbite that gets repeated in conference panels and Twitter threads for weeks. That, in turn, affects user behavior.
Some users will panic and move funds to exchanges. That's the wrong move, but it's a predictable one. We watched the same dynamic in 2022, when the bear market gutted my speculative gains and the same crowd that mocked centralized custody retreated to centralized custody the moment self-custody looked fragile. They didn't analyze the risk trade-off. They just ran toward the nearest authority figure.
News flash: FTX was an authority figure. Mt. Gox was an authority figure. Celsius was an authority figure. The history of this industry is a graveyard of trusted custodians who turned out to be trusted thieves or trusted incompetents. The solution to a hardware exploit is not to hand your keys to the platform that might be tomorrow's bankruptcy filing.
The correct response is architectural. Use multiple hardware wallets from different manufacturers. Use multisig with geographically distributed keys and independent signers. Verify every address on every device before every transaction. Run test transactions before moving serious amounts. Use a passphrase that exists only in your memory. Maintain offline backups that are themselves encrypted and distributed. Design your security posture on the assumption that every layer can fail, and then build redundancy on top of that assumption.
This is what professionals mean when they say "defense in depth." It's not a buzzword. It's a survival strategy. The people who practiced it were not the victims of this attack. The victims were the people who bought one device, trusted it completely, and never looked again.
One more technical point, and it matters. The vulnerability class here—trusting a single hardware device to protect assets without independent verification—has a direct parallel in smart contract security. The most sophisticated DeFi hacks of the past cycle didn't break cryptographic primitives. They exploited composition. They attacked the way systems interacted, not the way individual components worked.
Same with this. A secure element in a Coldcard might be mathematically impossible to extract keys from directly. But if the signing process can be coerced, or the transaction payload can be swapped, or the display can be tricked, or the firmware can be replaced—the secure element becomes an ornament in a broken system.
This is why the crypto community's reflexive "blame the user" response is both cruel and wrong. It's cruel because we don't know the specifics yet. It's wrong because even if the user made a mistake, the mistake occurred within a system that was marketed as mistake-proof. When a bank vault gets robbed, you don't blame the depositor for trusting the vault. You investigate the vault manufacturer, the security guards, and the alarm system. The same logic applies here.
There's also a regulatory dimension. If this exploit traces back to a supply chain issue or a firmware flaw at the manufacturer level, the consumer protection question enters the picture. The "hardware wallet equals unhackable" marketing language that has pervaded the industry becomes a liability when it turns out to be false. Regulators are already circling self-custody, and incidents like this give them rhetorical ammunition.
The autonomy argument for self-custody remains strong: it removes the counterparty risk inherent in exchanges, it aligns with the ethos of Bitcoin, and it puts users in control of their own assets. But every security incident chips away at that argument's public credibility. The industry needs to respond not by defending a single brand, but by building tools and practices that make the architecture genuinely resilient.
Multisig is the clear winner. Bitcoin's multisig technology is mature, audited, and battle-tested. A 2-of-3 setup, with keys held on different devices, in different locations, controlled by different entities, converts a single-device exploit from a catastrophic loss into a nuisance event. The attacker would need to compromise multiple devices, in multiple places, with different security postures, simultaneously or sequentially. That's an entirely different threat model.
And the industry is moving in that direction. But not fast enough. The market still sells "one device, one wallet, one seed phrase" as the default. The Coldcard exploit is an expensive reminder that the default is no longer acceptable.
Here's the contrarian take, and it will annoy both camps.
This exploit is the best thing that could have happened to Bitcoin self-custody in this market cycle. The "set and forget" culture was always a bubble. The people who bought a hardware wallet and stopped thinking were walking around with a false sense of security that was going to get them eventually. The Coldcard exploit pops that bubble early, before the cultural rot spreads further, and it forces an honest conversation about what security actually means.
The maximalist camp—the "hardware wallets are the only legitimate way to hold Bitcoin" crowd—also has a problem. They treat self-custody as a religious identity instead of an engineering discipline. They blame the victim, defend the brand, and demand technical details that excuse the device. But the brand deserves scrutiny, not devotion. And the device deserves a full audit, not a defense narrative.
The harder truth: CZ's advice is self-interested. Every security scare reshuffles trust toward custodians, and Binance is a custodian. "Spread your funds across multiple wallets" sounds like pure public service, but the first wallet most retail users flee to is a trusted exchange. That doesn't make CZ wrong. It makes him convergent with his incentives. Verify the advice like you would verify a transaction: independently, skeptically, before you act on it.
The next era of Bitcoin security won't be won by a magical device. It will be won by architecture: multisig as default, independent verification as ritual, and security postures built on the honest assumption that every single layer can fail.
We didn't build this industry to hand our sovereignty to a single point of failure. The seventy-million-dollar question is whether we remember that before the next exploit—or after.