The exploit, which researchers say stemmed from a flaw in the wallet’s firmware, has resulted in at least 1,816 bitcoin, worth about $114 million, being drained from more than 5,200 addresses since July 30, underscoring the risks even self-custodied assets face when wallet security is compromised.
FRNT Financial echoed that view, saying the exploit exposed a key tradeoff in self-custody. While many bitcoin holders prefer to control their own assets, they still place their trust in the hardware and software used to generate private keys.
“The reaction within the BTC community to the exploit was one of heartbreak,” FRNT wrote in a Wednesday report, noting many affected users had followed long-standing best practices around self-custody.
The firm compared the incident to the 2023 “Milk Sad” exploit, in which flawed key generation led to the theft of roughly $900,000 in digital assets. Rather than undermining self-custody altogether, FRNT said it expects the latest breach to spur wallet providers to strengthen their products as users demand greater security assurances.
For investors unwilling to accept the operational risks of managing private keys, the growing availability of spot bitcoin ETFs provides an increasingly attractive alternative, FRNT said.
Read more: Coldcard hack sparks a self-custody security overhaul: Cory Klippsten




