A Coldcard wallet exploit has drained bitcoin from users who held assets in self-custody, raising fresh questions about the operational risks of hardware wallets. CoinDesk reported that researchers linked the incident to a firmware flaw and said at least 1,816 BTC, worth about $114 million, had been taken from more than 5,200 addresses since July 30.
The incident matters because self-custody is often treated as a core bitcoin principle, but it still depends on the security of the devices and software used to create and manage private keys. Analysts cited by CoinDesk said the breach could lead some holders to reconsider whether they want to manage those risks directly.
Cantor said the exploit may have a positive read-through for publicly traded crypto companies tied to institutional adoption. The firm said affected or concerned users could move toward managed custody providers and exchanges, naming companies including Robinhood, Coinbase, BitGo, Bullish, eToro and Gemini as potential beneficiaries if customer flows increase.
FRNT Financial made a similar point, saying the exploit exposed the tradeoff between control and operational complexity in self-custody. The firm said many users affected by the breach had followed common best practices, a detail that could make the event more unsettling for the broader bitcoin community.
FRNT compared the episode with the 2023 “Milk Sad” exploit, where flawed key generation led to roughly $900,000 in digital asset theft. Rather than predicting the end of self-custody, the firm said the likely long-term outcome is adaptation: wallet providers may harden their products, while some investors may prefer regulated bitcoin exposure through spot ETFs.