A hardware wallet exploit targeting Coldcard devices has crystallized into one of the most damaging self-custody security incidents in recent Bitcoin history, with Galaxy Research now estimating total losses at approximately $70 million — a figure that is nearly double what was reported in the earliest assessments of the breach. The severity of the revised toll has prompted Binance founder Changpeng Zhao, widely known as CZ, to issue a pointed public warning to the broader Bitcoin-holding community, urging holders not to treat any single wallet solution as an impenetrable fortress.
CZ's message was characteristically blunt. "Nothing is 100%," he stated, encapsulating in three words a truth that the Coldcard exploit has now driven home with painful financial clarity. His counsel was practical rather than philosophical: spread your holdings across multiple wallets rather than concentrating risk in any single device or custody solution. For a community that has long debated the merits of hardware wallets over exchange custody, the warning carries particular weight coming from the founder of the world's largest cryptocurrency exchange by trading volume.
From Bad to Worse: How the Estimates Escalated
The rapid escalation from initial estimates to Galaxy Research's $70 million figure is itself a significant data point. It suggests that the full scope of the Coldcard exploit was not immediately visible — a common characteristic of sophisticated hardware-level attacks, where affected wallets may not all surface simultaneously and victims may take days or weeks to discover that their funds have been compromised. The doubling of the loss estimate is a warning sign for security researchers and ordinary holders alike: when the dust settles on incidents of this nature, the damage is almost always larger than first feared.
Coldcard, manufactured by Coinkite, has long been regarded as one of the gold-standard hardware wallets in the Bitcoin ecosystem, favored precisely because of its reputation for air-gapped security and open-source firmware. That a device of this stature could serve as the vector for a $70 million exploit will force a fundamental reassessment across the self-custody landscape. Hardware wallet manufacturers, security auditors, and the Bitcoin development community will face intensified scrutiny over vulnerability disclosure protocols and the pace at which firmware patches reach end users.
The Self-Custody Paradox
The incident puts renewed pressure on what might be called the self-custody paradox. The Bitcoin community has historically promoted the principle of "not your keys, not your coins," pushing users away from exchange custody toward personal hardware devices. Yet the Coldcard exploit demonstrates that self-custody introduces its own category of risk — one that individual holders are often ill-equipped to manage without diversification strategies of the kind CZ is now publicly advocating.
This is not an argument for abandoning self-custody or returning all assets to centralized exchanges. Rather, it is a reminder that sound portfolio risk management extends beyond asset allocation and into the architecture of custody itself. Just as a sophisticated investor would not hold all their assets in a single institution, prudent Bitcoin holders should consider distributing funds across multiple wallets, potentially combining hardware devices from different manufacturers, multisignature setups, and — depending on individual risk tolerance — partial custodial holdings.
Institutional Implications
For institutional participants and high-net-worth individuals who have been drawn into the Bitcoin ecosystem over the past several years, the Coldcard incident is a case study in operational security failure at scale. Institutional-grade custody solutions typically employ multisignature schemes, geographically distributed key management, and third-party custodial insurance precisely to avoid single points of failure. The $70 million loss figure, while significant in absolute terms, might have been substantially reduced or entirely avoided had affected holders implemented even a basic multi-wallet distribution strategy.
Regulators and compliance officers watching the space will likely cite this incident as further evidence that retail participation in self-custody Bitcoin carries material risk that is difficult to quantify in advance. The absence of a deposit insurance framework analogous to the Federal Deposit Insurance Corporation (FDIC) in traditional banking means that losses from exploits like this one are unrecoverable through any formal mechanism — a regulatory gap that policymakers in the United States and Europe have repeatedly flagged but not yet resolved.
What This Means for Bitcoin Holders
The Coldcard exploit and the revised $70 million loss figure from Galaxy Research represent more than a single security incident. They mark an inflection point in how the Bitcoin community must think about custody risk. CZ's warning — "Nothing is 100%" — should be read not as an invitation to paralysis but as a call to adopt the kind of layered, distributed security posture that professional risk managers employ as a matter of routine. No device, no firmware version, and no custody architecture is categorically immune to exploitation. Hardware wallet manufacturers will need to accelerate security audit cycles, improve vulnerability disclosure pipelines, and engage more transparently with users about the limitations of their products. Until then, diversification across wallets remains the most accessible hedge against the next incident — whenever and wherever it arrives.
Written by the editorial team — independent journalism powered by Codego Press.