The most significant story in Bitcoin right now is not the price. It is a security flaw that, according to CoinDesk, remains live and actively exploitable in specific Coldcard hardware wallet models and firmware versions. Coldcard itself has urged users to move their funds immediately. The breach has now confirmed three waves of attacks, with Galaxy Research reporting via The Block that losses have surpassed $100 million and could swell to $130 million once a suspected fourth wave is accounted for. Roughly 90% of the stolen bitcoin has not moved yet, which complicates recovery efforts and suggests the attacker may be waiting before attempting to sell.
What makes this moment worth studying is not just the dollar figure. It is the nature of the breach. Cold storage — hardware wallets kept offline — has long been presented as the gold standard for securing bitcoin. The Coldcard incident challenges that assumption in a concrete, practical way. As Decrypt explains in its coverage of air-gapped wallets, keeping private keys offline reduces exposure significantly, but it does not eliminate risk entirely. Firmware vulnerabilities, supply chain exposure, and user behavior all remain vectors. The exploit appears to have affected users across a range of technical skill levels, not just beginners.
Despite all of this, bitcoin is trading near $63,879, up roughly 1.9% over 24 hours according to CoinDesk. The market has, by most measures, absorbed the shock. Sentiment readings still show "extreme fear," but prices have not broken down. That divergence between sentiment and price action is notable.
Why the Calm?
Several forces are providing a floor. Japan reportedly spent as much as $36.6 billion buying yen in a coordinated action with the US, according to CoinDesk's live markets coverage — macro currency intervention of that scale tends to ripple into risk asset behavior. Separately, hopes around a potential Iran deal have steadied equity markets, which often move in loose correlation with bitcoin during periods of uncertainty.
There is also the Strategy dynamic. The company sold $104 million in bitcoin last week, according to Decrypt, a move that added short-term sell pressure but did not destabilize the market. Strategy CEO Michael Saylor told Bitcoin Magazine the company expects to work through what he called a bear market. That kind of institutional steadiness, however one interprets it, signals to other large holders that the situation is manageable.
What This Means for Custody Practice
The Coldcard breach will likely accelerate a broader conversation about custody standards, particularly among institutions and high-net-worth holders. A few things are worth watching:
- Firmware verification: The exploit has highlighted how critical it is to verify firmware integrity before and after any update.
- Multi-signature setups: Using multiple independent signing devices makes a single-point hardware failure far less catastrophic.
- Dormant wallet movement: CoinDesk reports that a 12-year-old wallet moved $31 million on Monday, part of a broader wave of old coins shifting since the hack — possibly holders spooked into action by the news.
The episode is a reminder that security in Bitcoin is not a one-time decision. It requires ongoing attention to the specific hardware, firmware version, and operational practices a holder is using. No single product or method is permanently safe. The threat environment changes, and custody practices have to change with it.
For anyone holding bitcoin on behalf of others — including charitable organizations managing donated funds — this is exactly the kind of event that makes clear documentation of custody procedures and regular security reviews essential, not optional.