Roughly 40 minutes. That is all it took for attackers exploiting a critical firmware vulnerability in the Coldcard hardware wallet to reconstruct victims' seed phrases and empty wallets holding $70 million in Bitcoin. The incident has sent shockwaves through the self-custody community and drawn a blunt public response from Changpeng Zhao — better known as CZ — who warned that no wallet, hardware or otherwise, can be considered fully safe.

For years, hardware wallets have occupied a privileged position in the Bitcoin security stack. The entire proposition rests on a single promise: your private keys never leave the device, and the firmware that governs the device is trusted, audited, and hardened against attack. The Coldcard exploit shatters that narrative, at least partially. When a firmware bug can be weaponized to reconstruct the very seed phrase that a wallet is designed to protect, the air-gap model — the cornerstone of cold storage theology — begins to look considerably less impenetrable than advertised.

How the Attack Unfolded

According to the reporting, the Coldcard firmware flaw gave attackers a pathway to rebuild seed phrases, the master keys from which all private keys in a Bitcoin wallet are derived. Once a seed phrase is compromised, an attacker gains complete, irreversible control over every address generated by that wallet. There is no two-factor authentication to bypass, no custodian to call, no transaction to reverse. The $70 million in BTC was gone in the time it takes to watch a feature film — approximately 40 minutes from the moment the attack was launched to the moment the wallets were emptied.

The speed of the drain is as alarming as the vulnerability itself. A 40-minute window suggests either a highly automated exfiltration process or that the attackers had significant preparation time before executing, meaning reconnaissance may have preceded the visible theft by an unknown period. Either scenario underscores that the operational window for victim intervention was essentially zero.

CZ Weighs In

CZ, the former chief executive of Binance and one of the most followed voices in the crypto industry, used the incident to deliver a broader warning to the self-custody community. His message was unambiguous: no wallet is fully safe. Coming from someone who spent years at the helm of the world's largest centralized exchange — and who has witnessed virtually every category of crypto security failure — the comment carries particular weight. It is not a dismissal of self-custody, but rather a sober acknowledgment that hardware wallets carry their own threat surface, one that is easy to underestimate precisely because the devices feel so physical, so tangible, so unhackable.

The irony runs deep. A significant portion of the Bitcoin community migrated assets into hardware wallets specifically in response to exchange hacks and custodial failures. The implicit contract was: take your coins off exchanges, hold your own keys, and you are protected from the institutional incompetence or malfeasance that has cost the industry billions. The Coldcard incident does not invalidate that logic entirely, but it forces a more nuanced conversation. Firmware is software. Software has bugs. And bugs in firmware that manages $70 million in Bitcoin are not theoretical risk — they are existential risk.

The Structural Problem with Firmware Trust

Hardware wallet security has always depended on a trust hierarchy: you trust the manufacturer to ship a genuine device, you trust the firmware to be what the manufacturer says it is, and you trust the cryptographic implementation within that firmware to be sound. Each layer in that chain represents an attack surface. Supply chain integrity, firmware update mechanisms, and the quality of the underlying cryptographic code are all potential vectors. What this incident appears to demonstrate is that the firmware layer — perhaps the most critical and most opaque of the three — can be exploited in ways that produce catastrophic outcomes at extraordinary speed.

For the broader self-custody ecosystem, the fallout raises urgent questions about firmware audit practices, the frequency and transparency of security disclosures, and whether the hardware wallet industry has matured its security culture to match the value it now custodies. When devices hold assets in the tens or hundreds of millions of dollars, the standards that applied when hardware wallets were niche enthusiast products are no longer adequate.

What This Means for Bitcoin Holders

The $70 million Coldcard breach is not an argument against self-custody — it is an argument for treating self-custody with the same disciplined rigor that institutional custodians apply to their own systems. Multi-signature arrangements, geographically distributed key shards, air-gapped signing ceremonies, and regular firmware audits by independent parties are no longer optional layers for paranoid maximalists. They are baseline practices for anyone holding material value in Bitcoin. CZ's warning — that no wallet is fully safe — is uncomfortable precisely because it is true, and the 40-minute clock that drained $70 million from Coldcard users is now the starkest possible evidence of what is at stake.

Written by the editorial team — independent journalism powered by Bitcoin News.