0x733df5eb733d…733df5e8

ConfirmedSecurity548 vB81 sat/vB3 min decode

Coldcard Exploit Drains $89M as Investors Move Bitcoin Back to Exchanges

CoinDesk reports $89 million in losses tied to a Coldcard hardware wallet compromise have driven bitcoin inflows to centralized exchanges — a flow opposite to the withdrawals seen after FTX's November 2022 collapse.

Unlike the FTX collapse, the $89 million Coldcard exploit has investors sending bitcoin back to exchanges - coindesk.com
WitnessUnlike the FTX collapse, the $89 million Coldcard exploit has investors sending bitcoin back to exchanges - coindesk.comAI-generated

Outputs

  1. $89 million in losses attributed to Coldcard exploit, per CoinDesk

  2. Investors moving bitcoin back to centralized exchanges, contrasting with post-FTX withdrawals

  3. FTX bankruptcy on Nov. 11, 2022 triggered roughly $7 billion in BTC exchange outflows

  4. Coldcard is made by Toronto-based Coinkite Inc.

  5. CoinDesk framed the incident as a device-side compromise rather than a platform-wide solvency failure

An $89 million exploit tied to Coldcard hardware wallets has triggered net bitcoin inflows to centralized exchanges, according to CoinDesk reporting — a flow direction opposite to what followed the November 2022 collapse of FTX.

What happened to Coldcard users

Coldcard, a Canadian-made hardware wallet marketed to bitcoin self-custody advocates, is at the center of an incident in which on-chain analysts and wallet users have flagged losses aggregating roughly $89 million, per the CoinDesk report. The publication framed the episode as a single-actor or single-campaign drain rather than a platform-wide solvency failure.

Where the BTC is going

The distinguishing data point is flow direction. After FTX filed for bankruptcy on Nov. 11, 2022, exchange balances fell as users withdrew assets to private custody, draining roughly $7 billion in spot BTC from venue wallets over the subsequent weeks. CoinDesk reports the opposite pattern this time: investors are returning bitcoin to exchanges, suggesting they prefer third-party custody when a hardware-vendor compromise is involved rather than when a venue itself fails.

The behavioral split maps onto the threat model. FTX was a custodial counterparty risk — the exchange held the keys. The Coldcard exploit, by contrast, appears tied to a device or supply-chain vector that users cannot easily audit after purchase, shifting perceived risk toward the endpoint rather than the venue.

Why Coldcard matters

Coldcard (manufactured by Coinkite Inc., based in Toronto) holds an outsized share of the advanced-user segment. It supports air-gapped signing, multisig workflows and BIP-39 passphrase entry, features that appeal to treasuries and high-net-worth holders rather than retail newcomers. A compromise reaching this user base therefore carries reputational weight disproportionate to its overall market share.

Custody risk, recast

The episode reframes a long-running industry debate. The post-FTX consensus — "not your keys, not your coins" — pushed capital toward self-custody wallets, including hardware devices. The CoinDesk report indicates that thesis now carries an asterisk when the wallet vendor itself becomes the weak link. Counterparty risk at exchanges is replaced by firmware, supply-chain and physical-tampering risk at the device level.

What it means for exchanges

Centralized venues benefit operationally from the inflows. Higher on-exchange balances support deeper order books, tighter spreads on BTC pairs and increased spot lending collateral. Compliance and custody teams also gain additional KYC footprint on assets that re-enter regulated venues after extended cold-storage holds.

What does this change for hardware-wallet buyers?

For users, the practical lessons are procurement and verification: sourcing devices only from tamper-evident packaging, validating firmware hashes directly against vendor documentation, avoiding resale channels and rotating seed phrases after any suspected exposure. None of these steps would have prevented every vector in the FTX case, but they target the failure mode the Coldcard incident surfaced.

Looking ahead

The report lands as several hardware-wallet vendors face renewed scrutiny over firmware-signing practices and third-party component sourcing. Expect wallet makers to publish supply-chain attestations, and expect major exchanges to cite custody inflows in their next quarterly market reports. Watch on-chain exchange netflow dashboards over the next 30 days; a sustained reversal of the post-Coldcard inflow trend would mark the first sign that user confidence in self-custody hardware has stabilized.

via Google News - Crypto Hack Exploit (Source)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles