A $110 million question: How safe are crypto wallets, and what’s the best way to store Bitcoin?

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Coinkite's Coldcard hardware wallets were exploited via a software flaw, draining more than 1,755 Bitcoin (~$110 million) from investors who relied on devices previously considered extremely secure.
- Jonathan Goodman lost $1.6 million when all three of his Coldcard wallets were emptied in a seven-minute window between 9:36 and 9:43 p.m. on July 29; 'the moment it loaded I knew I was screwed,' he told Bloomberg News.
- BitSave CEO Zakhil Suresh said the Coldcard victims 'did nothing wrong,' arguing ordinary investors should not have to become security experts to hold Bitcoin safely.
- Bitcoin storage ultimately hinges on a private key — a recovery phrase of up to 24 words — that grants total control of the coins, which is why losing it or having it compromised means the Bitcoin is irrecoverable.
- Investors have three storage paths: leaving Bitcoin on a crypto exchange (convenient but vulnerable if the platform fails), self-custody via a hardware wallet (direct control but full personal responsibility), or an institutional custodian — the model used by US spot Bitcoin ETFs, with keys geographically split.
- BitSave holds 100% of client assets in insured institutional custody with keys split across geographies, Suresh said, a structure designed to eliminate the single point of failure that hit Coldcard holders.
Why it matters: Coldcards were the gold standard for self-custody investors who distrusted exchanges, so a flaw that drained $110 million in seven minutes strikes at the core 'not your keys, not your coins' promise. For long-term holders, the incident crystallizes a tradeoff the Mint piece spells out: self-custody gives full control but also makes the user solely accountable for any loss.
Ask SkimNews




