News

Public · Published

Coldcard crisis hits $130 million – proving 'not your keys' is meaningless if you trust a single device to generate them

Block's Bitcoin Engineering and Security team and independent Bitcoin Core developers identified a firmware defect in Coinkite's Coldcard hardware wallet that caused a batch of wallets to lose about $130 million before any seed phrase was entered.

Published:

Updated:

What happened

Block’s Bitcoin Engineering and Security team and independent Bitcoin Core developers identified a firmware defect in Coinkite’s Coldcard hardware wallet that caused a batch of wallets to lose about $130 million before any seed phrase was entered.

Confirmed

Global impact / market context

The incident shows that even self‑custody solutions can be vulnerable if the device that creates the private keys is compromised, challenging the belief that keeping “your keys” alone guarantees safety.

Analyst inference

Investors have been attracted to hardware wallets as the safest way to store Bitcoin, but this breach may prompt a reassessment of risk across the broader crypto‑security market and could shift demand toward multi‑device or open‑source solutions.

Analyst inference

What to watch

  1. Whether Coinkite releases a firmware patch and how quickly users can update their devices, which will affect confidence in existing Coldcard holdings. Proposed
  2. Regulatory scrutiny of hardware wallet manufacturers, potentially leading to new compliance requirements for device security testing. Proposed
  3. Adoption of alternative self‑custody approaches, such as multi‑signature wallets or air‑gapped setups, as users seek to reduce reliance on a single device. Analyst inference

Affected assets

  • BTC — Bitcoin

Evidence