
An unfortunate code flaw within Coinkite's Coldcard hardware wallet allowed an attacker to steal 38 million worth of BTC or more from the device. According to reports from AMBCrypto, the flaw downgraded Coinkite's system from a 128-bit to a guessable 40-bit system, which could easily be cracked using brute force. Since Coldcard shares part of the hardware design involving the True Random Number Generator (TRNG) with other providers, investors were initially worried that other wallets could also be at risk.
Ledger clarified that it uses a 256-bit mathematical complexity system (entropy), which makes seed phrases difficult to crack, maintaining that their Bitcoin hardware wallets were "not affected" by Coldcard's flaw. As reported by AMBCrypto, Trezor also assured its users that they should not be alarmed about the Coldcard incident, stating that the recent issue is limited to Coinkite's custom firmware and how some of their devices generated randomness. Trezor emphasized that it does not share that code with other providers.
Despite the assurances from major hardware wallet providers, the Coldcard exploit sparked broader fear about safety on hardware wallets and self-custody. According to TaprootWizards' Udi Wertheimer, self-custody is now "worryingly unrealistic," warning that AI models with cybersecurity attack capabilities will intensify the hacks. As reported by AMBCrypto, Bitcoin's sentiment dropped to a four-month low, with the cryptocurrency price dropping sharply by nearly 3%, tagging a 2-week low of $62.4K before slightly recovering above $63K.
The weak sentiment also impacted Bitcoin ETF demand, with products recording a daily net outflow of $265 million on Friday. As reported by AMBCrypto, others projected that the overwhelming effort to handle self-custody amid ongoing risks would force investors to opt for U.S. Spot ETFs. However, the spot BTC ETFs demand was also impacted by the weak sentiment on Friday.