The $70 Million Coldcard 'Exploit' That Has No CVE, No Source, and No Victim
CryptoAnsem
There’s a particular kind of panic that only exists in the information vacuum between a tweet and a block explorer. It starts with a screenshot, mutates into a headline, and acquires a dollar amount before anyone has bothered to ask the manufacturer if it’s true. Over the past 36 hours, the crypto world has been rotating around a claim that Coldcard—the Bitcoin-only hardware wallet favored by the most paranoid self-custody crowd—was exploited for $70 million. The word "exploit" is doing a lot of heavy lifting. No CVE has been published. No affected firmware version has been named. No attack vector has been described. No transaction hash has been shared. And Coinkite, the maker of Coldcard, has been conspicuously silent. The only authoritative voice attached to the story is Changpeng Zhao, who responded to a social media post with the kind of phrase that sounds wise until you realize it’s also a disclaimer: "Nothing is 100%."
I’ve spent the last decade dissecting security narratives—from 2017 whitepapers that promised decentralization and delivered delegated proof-of-stake, to 2021 Art Blocks provenance mechanics, to the validity-proof vs. fraud-proof rabbit hole that consumed my 2022 bear market. What this story triggers is my structural skepticism reflex. Because if you strip away the panic, the headline, and the name of a beloved hardware wallet manufacturer, you’re left with a rumor that has all the evidence of a phishing email but no attachment. And the more I look at it, the more I believe the real attack isn’t on Coldcard at all. It’s on the information environment that allows unverified claims to move markets.
Let me put this in context. Coldcard is not a niche product sold at a mall kiosk. It’s a Bitcoin-only device built by Coinkite, a company that has cultivated a reputation for radical transparency: open-source firmware, air-gapped signing, optional secure element, tamper-evident seals, and a boot process you can verify with your own eyes. The entire value proposition is that you, the user, can verify the authenticity of every piece of silicon and every line of code. If you believe that physical isolation plus algorithmic verification equals safety, then Coldcard is the apex of that belief system. So when I see a report that Coldcard has been exploited, I don’t just ask whether the report is true. I ask: what would have to be true for this to be real? A remote attacker would need to bypass the secure element, or compromise the firmware build pipeline, or intercept and modify a physical device in transit. All three are possible, but all three would require an attacker with more resources than a typical scammer. And all three would leave behind forensic evidence that a competent security incident response team would find within hours, not days.
Here’s where my previous work becomes relevant. In 2022, I spent several weeks verifying code snippets for a Layer 2 foundation, trying to distinguish between validity proofs and fraud proofs. The lesson that stuck with me wasn’t mathematical. It was methodological: in a cryptographic system, the burden of proof lies with the person making the positive claim. If someone tells you that a proof is broken, you ask for the proof of the proof. If someone tells you that a hardware wallet is compromised, you ask for the minimum set of facts that would make the claim credible. That set includes a CVE number, a commit diff, a firmware version, a reproducible build, and a vendor statement. None of those facts have appeared in this story. Instead, we have a dollar figure—$70 million—which is both precise and unverifiable. And I’ve seen this pattern before: when a news item is allergic to technical specifics but comfortable with exact dollar amounts, the real source is usually a support ticket, not a security bulletin. It’s a story about a user who lost money, not a story about a device that lost its integrity.
Let’s talk about what a real $70 million hardware wallet exploit would look like. The first 24 hours would see Coinkite publishing an advisory. There would be a coordinated disclosure on the Bitcoin-security mailing list. There would be a Galaxy Digital or Chainalysis post tracing the stolen funds. There would be at least one independent security researcher confirming the issue with a proof of concept. Instead, we have the inverse information hierarchy: an exchange executive commenting before the vendor. CZ’s response is not a technical assessment. It’s a vacuous assurance designed to be correct in every possible future. "Nothing is 100%" is true for everything from cold wallets to cold fusion. But in this context, it serves a more strategic function: it shifts the framing from "Coldcard is broken" to "all storage methods have risk," which implicitly makes the case for centralized exchange custody. That framing aligns with the commercial interests of Binance, but it also nicely neutralizes panic by making the story about universal fragility rather than a specific product failure.
The contrarian take, however, isn’t that Coldcard is safe. It’s that the panic itself is the attack. I’m not a hardware wallet maximalist. I’ve seen users sign malformed transactions with multi-sig setups, and I’ve seen institutions lose more money through governance attacks than through private key theft. Over the years, I’ve reached a conclusion that many crypto natives find heretical: a well-regulated, audited exchange with insured custody can be a better security posture for some people than a self-custody setup that requires military-grade operational discipline. But that conclusion cuts both ways. The danger of an unverified panic story is that it doesn’t just make people question their hardware wallet. It makes them move funds right now, using the tools that appear highest in their search results. That’s how phishing works. The attacker creates urgency, then follows up with a fake solution. The headline "$70 Million Coldcard Exploit Stirs Panic" is the urgency. The fake recovery tool that appears in the next browser tab is the payload. If there is a real theft happening in this story, it’s not from the Coldcard device. It’s from the wallets of users who reacted before verifying.
History rhymes, but the code doesn’t. In 2016, Bitfinex was hacked for 120,000 bitcoin, and the market reaction was severe because there was a verified on-chain trail. In 2021, Ledger’s customer database was leaked, and the impact was real but it was a phishing vector, not a device compromise. In 2023, multiple rumors of Ledger and Trezor exploits were floated, and nearly all were debunked. What separates those events from this one is the presence of a verifiable artifact. Bitfinex had a blockchain address. Ledger had a leaked file. The 2023 rumors had... well, they had a similar shape to this Coldcard story. They disappeared after 48 hours because no one could produce a single piece of evidence. And yet, each time, the panic itself did damage: users rushed to transfer funds, paid absurd transaction fees, sometimes moved coins to an address they didn’t fully control. The lesson is that the confirmation delay is the attack surface. The gap between rumor and verification is where the bad actors operate.
Let me be specific about what I’d need to see before I treat this claim as anything more than noise. First, an official Coinkite statement—either a denial or an advisory. Silence from Coinkite for more than 48 hours is already a strong signal, because this company lives and dies on transparency. Second, a firmware release note or a published security audit. If the exploit is in a specific signing routine, there should be a patch. Third, a block explorer record showing the alleged $70 million moving from a Coldcard-derived address. Fourth, an independent researcher or security lab reproducing the attack. None of these have emerged. In the absence of all four, the rational stance is to assume the claim is unverified, and to advise anyone asking me whether their cold wallet is safe to keep holding. Better to sit on your hands than to feed your seed phrase into a scam interface.
There is another layer to this story that I find deeply interesting. The information poverty of the original report is not a bug; it’s a feature of the modern crypto news cycle. A headline with a precise dollar amount and a named victim product performs better in engagement metrics than a nuanced story about supply chain complexity and user error. The authors of such headlines don’t care whether the exploit is real. They care that the term "Coldcard" gets associated with "vulnerability" and "panic" in the same sentence. The marketers at Ledger and Trezor might even secretly appreciate the confusion, since it could drive users toward their own devices. But the actual effect on industry trust is negative for everyone. Every false alarm makes future legitimate warnings harder to believe. When a real exploit does happen—and at some point, it will—the public will have been trained by a hundred fake panics to ignore it. That’s the boy who cried wolf, but with asynchronous neural computation.
In my consulting work, I’ve advised multiple projects on how to handle security incidents. The first thing I tell them is to control the narrative by releasing all verifiable facts within 24 hours, even if those facts are incomplete. Coinkite’s silence is therefore more concerning than a quick denial would be. It suggests that either the company is investigating something real, or it has decided the rumor is beneath its attention. The former is unlikely given Coldcard’s history—the device is not bug-free, but its vulnerabilities have been minor and publicly disclosed. The latter is more likely, but it’s a PR mistake. In an information vacuum, the market creates its own truth. And the truth that is forming right now—across X, Telegram, and a dozen crypto news aggregators—is that a staple of the self-custody community might have been broken. That narrative is taking root, and it will be extremely hard to uproot, even with a comprehensive denial.
So what should a rational actor do? Do not liquidate your cold wallet because of a screenshot. Do not buy puts on Bitcoin based on a story that has no source. Do not move funds to an exchange because you suddenly feel that physical security is impossible. Instead, do the boring, empirical thing: wait. Wait 72 hours. Check the Coinkite Twitter feed and their signed GitHub updates. Search for a CVE database entry. Look for a statement from a reputable security firm. If none appears, then the story is almost certainly FUD. And if you’re the type of person who honestly believes that no tool is 100% secure, then the correct response is not to abandon hardware wallets but to build a multi-sig scheme with devices from different manufacturers and geographically separated keys. That’s a much better investment of your panic than sending BTC to a new address that might belong to an attacker.
The bottom line is that this story is not a technical story. It’s a story about the difference between information and knowledge. The crypto ecosystem prides itself on being decentralized, permissionless, and transparent. But the attention economy operates on exactly the opposite principles: centralized, gated, and opaque. The $70 million Coldcard exploit will either be confirmed in the next few days or it will fade into the long tail of false alarms that make 2026’s security landscape harder to navigate. I’ve seen this cycle enough times to know that the best play is to do nothing until the evidence arrives. Because in this industry, the only thing that’s 100% is that nothing is 100%—and pretending otherwise is how people lose money. Better to treat every unverified claim as a phishing attempt until proven otherwise. That’s not cynicism. That’s risk management.