A roughly $116 million hardware wallet exploit has turned self-custody back into the central question for Bitcoin holders, forcing renewed attention on how coins are stored and who ultimately controls the keys.
A roughly $116 million hardware wallet exploit has turned self-custody back into the central question for Bitcoin holders, forcing renewed attention on how coins are stored and who ultimately controls the keys.
A roughly $116 million hardware wallet exploit has turned self-custody back into the central question for Bitcoin holders, forcing renewed attention on how coins are stored and who ultimately controls the keys.
The figure traces to what security researchers described as the largest hardware wallet exploit of 2026, an attack tied to Coldcard devices that drained roughly $116 million, according to a TRM Labs analysis. The amount is denominated in U.S. dollar value at the time of the incident. For related coverage, see Cboe Files to List 3x Leveraged ETFs for Bitcoin, Ether, Gold, Silver, Oil and Natural Gas.
Device maker Coinkite has publicly flagged a seed generation issue affecting the Coldcard Mk3, warning users of the risk in an advisory posted to its blog. That warning speaks to how the funds became exposed rather than any breach of an exchange or custodian.
Self-custody means holding Bitcoin in a wallet whose private keys the owner alone controls, rather than trusting a third party to safeguard them. It is the practical expression of the maxim “not your keys, not your coins.”
The tradeoff is direct: custodial platforms offer convenience and recovery options, while private wallets give the holder full control and remove counterparty risk. The Coldcard case shows that control also shifts the burden of security, including firmware and seed integrity, onto the user.
The incident already appears to be shaping on-chain behavior, with a reported rise in new Bitcoin addresses that followed the Coldcard exploit and related fund transfers. Movement of long-dormant coins, such as Bitcoin from 2010 that recently moved for the first time in 15 years, underscores how closely holders now watch wallet activity.
Bitcoin holders tend to monitor custody risk more closely than generic crypto users because the asset is often held for the long term as a self-sovereign store of value. The broader weekly digest on this shift was covered in Cointelegraph’s Crypto Biz roundup.
Away from self-custody wallets, institutional demand has stayed firm, with U.S. spot Bitcoin ETFs drawing about $854 million over five days as rate-hike expectations faded. That flow suggests the custody scare has not dented headline demand for regulated Bitcoin exposure.
The exploit reads as a device-specific event rather than a signal of a broad self-custody exodus, since the loss is tied to a particular hardware fault and the ETF inflows point the other way. It sits alongside other recent security stress in the ecosystem, including Boltz disabling its Bitcoin Lightning swap services after an exploit.
The concrete signal to watch next is whether new address growth and cold-storage migration continue, or whether the pattern normalizes once affected users complete transfers. Continued institutional appetite is also visible in product filings, such as Cboe’s filing for a first 3x Bitcoin and Ether ETF.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Quick access to the site tools and map-driven utility pages.
Follow the core desks readers use most across Bitcoin, altcoins, mining, events, and sponsored coverage.
© 2026 BitcoinInfoNews.com. All rights reserved.
Independent Bitcoin and crypto coverage with public trust, policy, and newsroom pages available sitewide.