A firmware flaw in Coldcard hardware wallets let an attacker drain roughly $70.2 million in Bitcoin in 41 minutes, prompting BlockTower Capital founder Ari Paul to argue that crypto custody can never be made fully secure. ShapeShift founder Erik Voorhees pushed back, while separate data shows phishing and wallet-draining exploits, not protocol attacks, are driving most 2026 crypto losses.
A firmware flaw affecting multiple generations of hardware wallets from Coldcard let an attacker steal roughly 1,082.65 BTC, worth about $70.2 million at the time, in just 41 minutes. BlockTower Capital founder Ari Paul said the breach proves a blunt point about custody. Paul wrote on X: "there is simply no way to secure crypto."
Entrepreneur Jonathan Goodman said on X that $1.6 million worth of his Bitcoin was stolen from a Coldcard device that he kept in cold storage inside a safety deposit box never connected to the internet.
Neither custody model is safe, Paul argues
Paul argued that neither self-custody nor third-party custody offers full protection. Custodians such as Coinbase get hacked frequently with no compensation for users, he said, while holding coins yourself can still end in a Coldcard-like compromise. He said the same vulnerabilities extend past a single manufacturer, since every custody method depends on hardware and software that could carry flaws.
He added that the legal system remains a more reliable safeguard for financial assets than cryptography today in most of the developed world, though he said crypto may still work better in countries where legal institutions and property rights are less dependable.
Voorhees pushes back
ShapeShift founder Erik Voorhees rejected the idea that the Coldcard incident proves crypto cannot be secured, though he conceded that no single storage system is perfectly risk-free. He argued that every method of storing wealth carries different tradeoffs rather than identical risks, and noted that hundreds of billions of dollars in crypto have been stored securely for years.
Phishing, not a protocol break, drives the losses
No major Bitcoin-native protocol has issued a warning about a network-level attack, and nobody has broken the blockchain's SHA-256 consensus. Instead, phishing and wallet-draining exploits siphoned more than $1.1 billion from crypto users across 212 separate incidents in the first half of 2026.
The dominant attack vector over 2025 and 2026 has shifted toward operational compromises, including social engineering, compromised employee credentials and phishing emails, with a significant portion of major incidents attributed to North Korea-linked, state-sponsored actors. Guarding seed phrases, using hardware wallets and treating unsolicited messages with skepticism remain the most effective defenses.
Sources: U.Today, Crypto Briefing
Trading involves risk.