
Bitcoin’s $100M Hack
Posted August 05, 2026
Chris Campbell
In 2014, two guys in Prague built a little plastic vault for your Bitcoin.
They called it Trezor. (Czech for “vault.”)
It was a way to self-custody your own crypto without knowing how to code or figure out complex encryption methods.
It was the first of what we now call "hardware wallets," or "cold wallets"—cold because they never touch the internet.
They’re the kind of thing Obama once warned about when he moaned that encryption was putting "a Swiss bank account in your pocket."
Kickstarter rejected them. They sold 13,000 anyway.
Then the crypto exchanges started dying. Mt. Gox. Bitfinex (died three times). QuadrigaCX. Much later, FTX.
Each collapse sent a fresh wave of believers running to cold storage.
In fact…
After FTX, hardware wallets had their biggest sales day in history—twice in one week. "Not your keys, not your coins" became gospel.
Millions of devices. Billions secured. An entire industry built on one promise: the keys never leave the device.
Then, on July 30, 2026, that promise was broken.
Someone drained $100 million from ColdCard hardware wallets in 41 minutes—without touching a single device.
The keys to the vault never left. They didn't have to. The flaw was baked in.
So let's get into it—what happened, why, and three takeaways. (The first takeaway isn't even about crypto. It's about AI.)
The Sad Truth
It didn’t take long to figure out what really happened. And it’s the stupidest thing ever.
Here's the simple version.
A hidden bug in ColdCard wallets made the "random" keys protecting people's Bitcoin guessable.
Hackers, likely armed with AI, guessed them.
Over $100 million gone, mostly from long-term savers who did everything right. No shady exchanges. No careless mistakes. Coins stacked patiently for years, vanishing from cold storage in minutes.
Blockchain sleuths are tracking the stolen funds—most sit untouched, for now—while the industry scrambles to audit every wallet on the market.
I’m rooting for the non-zero chance the attackers get caught and the funds are recovered. (It’s happened before.)
But right now, the overall reaction is this: "Self-custody is dead. Keep it on Coinbase. Buy IBIT. Let Saylor hold it."
Slow down.
Should everyone run out and buy a hardware wallet? Probably not. But self-custody isn't going anywhere—and now matters more than ever.
What’s a Wallet, Anyway?
People say self-custody exists because custodians are single points of failure.
But they have it backwards.
Custodians exist because self-custody—doing it right, at least—is complicated and scary.
But here’s one thing to keep in mind: Whether you're BlackRock or John Doe on Park Avenue, there's exactly one way to custody it: a wallet holding private keys. Hot, cold, hardware, paper—pick your flavor. All of it reduces to keys in a wallet.
That's the entire technology.
BlackRock uses wallets. Fidelity uses wallets. Every Bitcoin treasury company on Earth uses wallets. Somebody holds the keys no matter what you buy.
The only questions are who and what do you get in return?
Buy IBIT and you own a promise. A claim on Bitcoin that BlackRock controls. Worse, retail shareholders have no redemption rights. Every other custodian sits somewhere on the same spectrum—your coins, their permission.
Remove self-custody from the equation, you remove one of the things that makes Bitcoin valuable: the exit option. And the exit option is what disciplines everyone else.
Exchanges have to honor withdrawals because users can leave—that's what keeps the whole system honest.
Three Takeaways
There are three things I’m taking away from this ColdCard event, and the first one isn’t what you would expect.
One: Open-weight AI is essential. This has been a debate outside of crypto, but crypto just showed why it’s important. The “white hats” (good hackers) defending Bitcoin keep hitting safety guardrails on the frontier models—and fall back on Chinese open-source AI to fight attackers who face no such constraints. Unless the closed labs dial back the restrictions, the bad guys outgun the good guys by default and everyone’s left defenseless. That's a nonstarter.
Two: The great hardening has begun. Real people lost life savings, and that's the worst part. But every wallet company is now running deeper audits, tighter reviews, harder internal questions—with AI on code-check duty like never before. Innovation with self-custody is set to accelerate faster than any corner of this space.
Three: Self-custody isn't dead—it's about to rise. Every cycle proves the same thing: trust in middlemen decays, and the tools for holding your own keys get better. The ColdCard hack won't reverse that trend. It'll accelerate it.
The next generation of self-custody will make today's cheap, plastic devices look primitive. And the demand isn't going anywhere, because the alternative isn't going anywhere: counterparty risk, frozen accounts, promises instead of property.
Every exchange failure minted new self-custodians. This failure will mint better ones.
Of course, this is no solace for those who lost money. They did everything right—and got robbed anyway. That’s the part that really stings.
But Bitcoin’s survived Mt. Gox, China bans, FTX, and a thousand obituaries. Each time, the response wasn't retreat. It was better tools, harder code, smarter custody.
This time will be no different.
