NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com

A Hardware Wallet Hack & the Custody Conversation With Clients

发布于 3 小时前 4 分钟阅读
A Hardware Wallet Hack & the Custody Conversation With Clients

A Hardware Wallet Hack & the Custody Conversation With Clients ETF Database

More than $100m in bitcoin has been swept because of a five-year-old firmware flaw. Advisors should read it as an operational risk story.

Beginning 30 July, an attacker started sweeping bitcoin from addresses generated by Coldcard, a bitcoin-only hardware wallet made by Canadian firm Coinkite. The first burst took roughly 594 BTC from around 500 wallets in about 25 minutes.1 As of 4 August, Galaxy Research said it had high confidence that 1,596 BTC had been taken from about 7,300 addresses across three confirmed waves and 14 smaller incidents, worth more than $100m. Including a suspected but unconfirmed fourth wave, the total could reach roughly 2,055 BTC, or about $130m. At least 15 independent attackers were exploiting the same flaw, and it remained live.2

No one was phished. No device was stolen. Coinkite’s advisory traces the problem to a firmware change in March 2021 that handed key generation to a predictable software randomizer instead of the chip’s hardware one. That narrowed the range of possible keys far enough for an attacker to reconstruct them offline, without ever seeing the device. Only single-signature wallets are affected. Coinkite has published the affected models and firmware versions.3

The detail that matters for suitability

Fixed firmware shipped on 31 July, but a patch cannot repair a key that has already been generated. Owners must create a new one and move their coins, and a minority of setups built with enough independent private entropy are exempt.3

This did not catch the careless. It caught holders who had read the arguments, bought a respected bitcoin-only device and moved their coins off exchanges. The defect sat undetected for more than five years, and nothing an owner did would have revealed it. That is the part worth carrying into a client meeting: the risk was real, material and undetectable by the end user.

The flow response inverted the FTX pattern. In late 2022 holders pulled coins off exchanges. This time they sent them back. CryptoQuant recorded 39,600 BTC moving in transfers under 1 BTC on 31 July, just short of the 39,900 BTC moved on 16 November 2022, days after FTX filed for bankruptcy. Net exchange inflows hit 11,163 BTC.4

Content continues below advertisement

Custody is a spectrum, not a virtue test

Hold your own keys, or hold a listed product? The question resurfaces with every incident, and the people who built this industry decline to pick a side.

We put it to Adam Back last year. The cryptographer, now Blockstream’s chief executive, is among the handful of researchers whose work is cited in the Bitcoin whitepaper. His answer: “Both. I have done both actually. ETFs offer portfolio integration and borrowing advantages… But self-custody is crucial for maintaining decentralization and immutability.” He had already cautioned that “self custody is not for everyone.”5

David Marcus, the former PayPal president who went on to run Meta’s digital currency effort and now leads Lightspark, argues openly for self-custody and still hedges: “Personally, I think the best way to do it is a combination of custodial services by trusted entities and self-custody.”6

Bloomberg’s Eric Balchunas points at something more prosaic: “Wallets today are still too complex. When it gets easier, I might switch to self-custody. For now, ETFs eliminate that friction.”7

What a wrapper solves, and what it does not

An exchange-traded product does not abolish key risk. It relocates it to a custodian running institutional key generation, multi-signature controls, audit and insurance, and it swaps a silent single point of failure for an accountable counterparty. In return the holder takes on issuer and custodian risk, a management fee and no on-chain optionality. That is a trade, not an upgrade, and it should be presented as one.

Nor does one firmware defect end the argument. Peter Todd, an early Bitcoin developer, put the counter-case directly: “Self custody has a much better track record than third parties.” He noted that QuadrigaCX alone cost users about $200m, roughly double the Coldcard losses known at the time he wrote.8 Willy Woo, who says he holds nothing against regulated products, argues that only self-custody delivers genuinely sovereign property.9

Both positions hold. The narrower question for an advisor is which failure mode a given client can detect, insure and survive. For five years, Coldcard owners could do none of the three.

For more news, information, and strategy, visit the CoinShares Crypto ETF Hub.

Sources

  1. Crypto Economy, “Coldcard Vulnerability Turns ‘Impossible to Guess’ Seeds Into Guessable Ones, Draining 594 BTC”, 31 Jul 2026
  2. Galaxy Research, via The Block, “Bitcoin losses from Coldcard hack could swell to $130 million”, 4 Aug 2026
  3. Coinkite, “Coldcard Security Advisory”, 30 Jul 2026, updated 1 Aug 2026
  4. CryptoQuant and Timechainindex, via CoinDesk, 2 Aug 2026
  5. CoinShares interview, Adam Back, CEO of Blockstream, 23 May 2025
  6. CoinShares interview, David Marcus, CEO and founder of Lightspark, 13 Nov 2025
  7. CoinShares interview, Eric Balchunas, Senior ETF Analyst, Bloomberg, 11 Jul 2025
  8. Peter Todd, post on X, 3 Aug 2026
  9. Willy Woo, post on X, via The Crypto Times, 3 Aug 2026

CoinShares is an issuer of crypto exchange-traded products. Loss figures are estimates published by Galaxy Research and are as at 4 August 2026. The exploit was ongoing at the time of writing and totals have been revised upwards repeatedly. Nothing here is investment advice.

Attribution

Originally reported by ETF Database

Get stories like this, daily.

Daily crypto + regulation intelligence, straight to your inbox. Free.

相关报道