Coldcard's recovery phrase generator had a bug that made phrases predictable under certain conditions. Attackers could derive private keys without ever accessing the device. Even air-gapped hardware wallets are vulnerable to software-level exploits.
If hardware wallets—marketed as the safest place for Bitcoin—can be compromised via software bugs, who bears the risk? Users can't patch devices mid-theft. This incident is reigniting the self-custody vs. regulated custody debate.
Bitcoin and Ethereum spot ETFs now hold $50B+. These provide institutional custody (Fidelity, BNY Mellon), insurance, and no private key risk. The Coldcard exploit may accelerate retail flows from self-custody to regulated ETF solutions.
Check if your recovery phrase was generated with a vulnerable firmware version. Coldcard released patches. Worst case: consider moving Bitcoin to a non-custodial exchange (Kraken, Coinbase) or spot ETFs if you want institutional custody without self-custody risk.
Read More →