A software bug in Coldcard hardware wallets has drained nearly 600 Bitcoin, worth roughly $38 million. The exploit, which appears to still be active, is shaking confidence in self-custody and could accelerate the shift toward Bitcoin ETFs.
The $38 million hole
Nearly 600 Bitcoin is a lot. At current prices, that's about $38 million. But the real concern is the "so far" — the exploit may still be running. Coldcard hasn't said how many wallets were hit or how the bug works. Users are in the dark.
Self-custody's weak link
Hardware wallets are supposed to be the safest way to hold your own keys. A software bug that lets an attacker drain funds undermines that promise. If the wallet's own code is the weak point, then even offline storage isn't safe. This incident could push more retail investors toward Bitcoin ETFs, which handle custody on their behalf. The ETF route removes the need to manage private keys — but also removes the sovereignty that self-custody offers.
Waiting for answers
The crypto community is waiting for Coldcard to explain the root cause and whether a patch is coming. Meanwhile, users are left wondering if their funds are safe. The "so far" language suggests the exploit may still be siphoning Bitcoin. Until Coldcard speaks, the full damage is unknown.




