The Coldcard Bitcoin hardware wallet hack has ballooned into a $114 million disaster, shaking confidence in self-custody. The breach, which targeted users of the popular cold-storage device, marks one of the largest security failures in the crypto space this year. It also highlights a new front in the war on digital assets: AI-powered attacks.
How the hack unfolded
The attack exploited vulnerabilities in Coldcard's firmware, allowing attackers to siphon funds from wallets that were supposed to be offline. While details remain scarce, the scale of the losses — $114 million and counting — suggests a sophisticated, possibly state-backed operation. Coldcard has not yet released a full post-mortem, but the incident has already rattled the self-custody community.
AI as a threat vector
Security researchers point to artificial intelligence as a key enabler of the hack. AI-driven tools can analyze patterns, find weaknesses, and automate exploits at a speed and scale humans can't match. This isn't a theoretical risk — it's happening now. The Coldcard breach is a stark reminder that even hardware wallets, long considered the gold standard for security, are not immune.
Self-custody under fire
The hack comes at a time when the ethos of self-custody — "not your keys, not your coins" — is being tested. Exchanges and custodians have their own problems, but this incident shows that holding your own crypto isn't risk-free either. Users are now questioning whether hardware wallets are truly safe, especially as attackers deploy more sophisticated tools. The $114 million figure may rise as more victims come forward.
Coldcard has not yet released a full technical breakdown of the hack. The crypto community is waiting for a patch or a statement on how to secure funds. The next few weeks will be critical as Coldcard faces pressure to explain exactly how the attack worked — and whether it could happen again. The question hanging over the industry: can self-custody survive the AI era?




