Unlike the FTX collapse, the $89 million Coldcard exploit has investors sending bitcoin back to exchanges
Key Points:
- A major security incident involving Coldcard, a Bitcoin-only hardware wallet, has led to thefts estimated between 1,000 and 1,300 BTC (approximately $70–$90 million) due to a firmware bug weakening seed phrase generation since March 2021.
- The flaw caused some Coldcard devices to use a predictable software random number generator instead of hardware RNG, allowing attackers to reconstruct seed phrases and steal funds without physical access to the wallets.
- In response, many investors moved their Bitcoin from self-custody wallets back to centralized exchanges, with daily small Bitcoin deposits (<10 BTC) to exchanges spiking to 7,300 BTC on July 31, the highest since February 2024.
- This shift contrasts with the post-FTX collapse trend, where investors withdrew coins from exchanges to self-custody; now, concerns over hardware wallet security have reversed that behavior, increasing exchange-held Bitcoin from 2.703 million to 2.715 million BTC.
- The incident has sparked renewed debate about the safety of self-custody solutions, with prominent figures like Binance founder CZ reconsidering hardware wallet security amid ongoing thefts.