Misleading
The Coldcard incident proves hardware wallets have been physically hacked and that all cold storage is now unsafe.
Claim by · Viral self-custody threads and reply accounts on X
A real software flaw affecting Coldcard users led to substantial bitcoin losses, but reporting describes a software-level exploit rather than a physical break of the devices, and it does not establish that all cold storage is unsafe.
Analysis
Two separate strands are being merged in these posts. The first is documented: reporting describes a software bug affecting the popular Coldcard hardware wallet, with roughly 600 BTC — about $38 million at the time of the first report — stolen, and follow-up reporting putting cumulative losses higher as more wallets were drained. The second strand is the inference, and it is where the claim breaks down. Follow-up coverage explicitly frames the attack as one that never touched the physical devices, which is the opposite of the "devices were physically hacked" framing circulating online. A supply-chain or software-level defect in one vendor's firmware or companion tooling is a different failure mode from an attacker extracting keys from silicon in hand. It also does not generalise: hardware wallets from other vendors, multisig arrangements, and air-gapped signing setups were not shown to be affected by this defect. Readers should treat the incident as a strong argument for firmware diligence, multisig, and vendor risk spreading — not as evidence that self-custody as a category has failed. The Crypto News Hub takes no position on whether readers should self-custody or use ETFs, and points have no bearing on that choice.
What we know
A software-level exploit affecting Coldcard users resulted in the theft of hundreds of bitcoin, with reported losses rising from about $38 million to roughly $70 million as more cases surfaced. Reporting states the attack did not require physical access to the devices.
What we don’t know
The full final loss total, the complete technical chain of the exploit, how many users remain exposed, and whether any funds will be recovered are all unresolved. Whether other vendors share any related weakness has not been established.
Evidence
Reviewed 8/1/2026. This fact-check follows The Crypto News Hub methodology: transparent sourcing, named editors, and public corrections history.