Key facts
- A Coldcard firmware exploit led to the theft of approximately 2,100 BTC.
- In the days following the exploit, 233,000 BTC were moved out of long-term holder wallets.
- Casa CEO Nick Neuman cited the event as evidence of self-custody's resilience.
- The exploit was due to a firmware bug affecting seed generation on certain Coldcard models.
- Neuman suggested that the amount moved to safety was significantly larger than the amount stolen.
Casa CEO Nick Neuman highlighted on-chain data following a recent Coldcard firmware exploit as evidence of Bitcoin's self-custody resilience. In an X post, Neuman cited figures indicating that in the days after the hack, which resulted in the theft of approximately 2,100 BTC, 22,000 BTC moved to exchanges and 233,000 BTC left long-term holder wallets.
Neuman suggested that these movements, which he estimated were between 10 to 100 times the amount stolen, reflected holders reassessing single-key risks and shifting funds to multisig wallets or removing affected Coldcard devices from their setups. He contrasted this scenario with a hypothetical breach of a centralized custodian, where he argued the majority of funds would likely be lost in a single event.
The Coldcard vulnerability stemmed from a March 2021 firmware issue that weakened seed generation on certain models. While confirmed losses are estimated between 1,700 to over 2,000 BTC, potentially reaching $130 million, Neuman emphasized that the distributed nature of self-custody limited the systemic impact. He concluded that self-custody benefits both individual holders and the broader Bitcoin network by distributing risk and maintaining confidence.
