This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.

Enjoying NewsLayer?

Get breaking crypto stories the second they drop — join our Telegram channel.

NewsLayer.com

A Hardware Wallet Hack & the Custody Conversation With Clients

Publié il y a un jour 4 min de lecture
A Hardware Wallet Hack & the Custody Conversation With Clients

A Hardware Wallet Hack & the Custody Conversation With Clients ETF Database

More than $100m in bitcoin has been swept because of a five-year-old firmware flaw. Advisors should read it as an operational risk story.

Beginning 30 July, an attacker started sweeping bitcoin from addresses generated by Coldcard, a bitcoin-only hardware wallet made by Canadian firm Coinkite. The first burst took roughly 594 BTC from around 500 wallets in about 25 minutes.1 As of 4 August, Galaxy Research said it had high confidence that 1,596 BTC had been taken from about 7,300 addresses across three confirmed waves and 14 smaller incidents, worth more than $100m. Including a suspected but unconfirmed fourth wave, the total could reach roughly 2,055 BTC, or about $130m. At least 15 independent attackers were exploiting the same flaw, and it remained live.2

No one was phished. No device was stolen. Coinkite’s advisory traces the problem to a firmware change in March 2021 that handed key generation to a predictable software randomizer instead of the chip’s hardware one. That narrowed the range of possible keys far enough for an attacker to reconstruct them offline, without ever seeing the device. Only single-signature wallets are affected. Coinkite has published the affected models and firmware versions.3

The detail that matters for suitability

Fixed firmware shipped on 31 July, but a patch cannot repair a key that has already been generated. Owners must create a new one and move their coins, and a minority of setups built with enough independent private entropy are exempt.3

This did not catch the careless. It caught holders who had read the arguments, bought a respected bitcoin-only device and moved their coins off exchanges. The defect sat undetected for more than five years, and nothing an owner did would have revealed it. That is the part worth carrying into a client meeting: the risk was real, material and undetectable by the end user.

The flow response inverted the FTX pattern. In late 2022 holders pulled coins off exchanges. This time they sent them back. CryptoQuant recorded 39,600 BTC moving in transfers under 1 BTC on 31 July, just short of the 39,900 BTC moved on 16 November 2022, days after FTX filed for bankruptcy. Net exchange inflows hit 11,163 BTC.4

Content continues below advertisement

Custody is a spectrum, not a virtue test

Hold your own keys, or hold a listed product? The question resurfaces with every incident, and the people who built this industry decline to pick a side.

We put it to Adam Back last year. The cryptographer, now Blockstream’s chief executive, is among the handful of researchers whose work is cited in the Bitcoin whitepaper. His answer: “Both. I have done both actually. ETFs offer portfolio integration and borrowing advantages… But self-custody is crucial for maintaining decentralization and immutability.” He had already cautioned that “self custody is not for everyone.”5

David Marcus, the former PayPal president who went on to run Meta’s digital currency effort and now leads Lightspark, argues openly for self-custody and still hedges: “Personally, I think the best way to do it is a combination of custodial services by trusted entities and self-custody.”6

Bloomberg’s Eric Balchunas points at something more prosaic: “Wallets today are still too complex. When it gets easier, I might switch to self-custody. For now, ETFs eliminate that friction.”7

What a wrapper solves, and what it does not

An exchange-traded product does not abolish key risk. It relocates it to a custodian running institutional key generation, multi-signature controls, audit and insurance, and it swaps a silent single point of failure for an accountable counterparty. In return the holder takes on issuer and custodian risk, a management fee and no on-chain optionality. That is a trade, not an upgrade, and it should be presented as one.

Nor does one firmware defect end the argument. Peter Todd, an early Bitcoin developer, put the counter-case directly: “Self custody has a much better track record than third parties.” He noted that QuadrigaCX alone cost users about $200m, roughly double the Coldcard losses known at the time he wrote.8 Willy Woo, who says he holds nothing against regulated products, argues that only self-custody delivers genuinely sovereign property.9

Both positions hold. The narrower question for an advisor is which failure mode a given client can detect, insure and survive. For five years, Coldcard owners could do none of the three.

For more news, information, and strategy, visit the CoinShares Crypto ETF Hub.

Sources

  1. Crypto Economy, “Coldcard Vulnerability Turns ‘Impossible to Guess’ Seeds Into Guessable Ones, Draining 594 BTC”, 31 Jul 2026
  2. Galaxy Research, via The Block, “Bitcoin losses from Coldcard hack could swell to $130 million”, 4 Aug 2026
  3. Coinkite, “Coldcard Security Advisory”, 30 Jul 2026, updated 1 Aug 2026
  4. CryptoQuant and Timechainindex, via CoinDesk, 2 Aug 2026
  5. CoinShares interview, Adam Back, CEO of Blockstream, 23 May 2025
  6. CoinShares interview, David Marcus, CEO and founder of Lightspark, 13 Nov 2025
  7. CoinShares interview, Eric Balchunas, Senior ETF Analyst, Bloomberg, 11 Jul 2025
  8. Peter Todd, post on X, 3 Aug 2026
  9. Willy Woo, post on X, via The Crypto Times, 3 Aug 2026

CoinShares is an issuer of crypto exchange-traded products. Loss figures are estimates published by Galaxy Research and are as at 4 August 2026. The exploit was ongoing at the time of writing and totals have been revised upwards repeatedly. Nothing here is investment advice.

Attribution

Originally reported by ETF Database

Get stories like this, daily.

Daily crypto + regulation intelligence, straight to your inbox. Free.

Articles Liés