A firmware vulnerability in the Coldcard bitcoin hardware wallet led to bitcoin worth up to $89 million being taken from more than 1,200 addresses, prompting bitcoin critic Peter Schiff (피터 시프) to raise cryptocurrency security concerns again.
U.Today, a blockchain media outlet, reported on Aug. 3 that Schiff argued advances in artificial intelligence (AI) and quantum computing would make hacking easier and could increase security risks for bitcoin holders.
The incident is seen as one of the biggest hardware wallet security cases in recent years. Researchers viewed a Coldcard firmware defect as the cause of a large-scale organised theft. The issue occurred in the wallet's random seed generation process. The attacker used the vulnerability to reconstruct wallet seeds and was reported to have drained assets from affected addresses in sequence.
The estimated losses also grew. Initial estimates were near $70 million, but rose to about $89 million as additional compromised wallets were identified. Schiff said of the incident: "As AI and quantum computing make hacking easier, the situation will only get worse."
The attack itself did not occur because of AI or quantum computing. The direct cause was a firmware defect, not improved processing performance. The target was not the bitcoin blockchain or the cryptographic technology itself. A software design error in a hardware wallet that had emphasised security became the starting point of the incident.
This point is read as a significant warning to market participants who prefer self-custody. Coldcard has been seen as a security-focused bitcoin hardware wallet. With a high level of trust among users seeking to hold their own assets, the incident showed that cold storage does not necessarily mean absolute safety.
The cryptography community's view differs somewhat from Schiff's argument. Many cryptographers believe there is still no quantum computer capable of actually breaking bitcoin's cryptographic system. That means the network still has time to prepare through future protocol improvements.
The key takeaway from the case is not whether the bitcoin network was breached, but how vulnerable the surrounding infrastructure can be. Self-custody security is not completed by the blockchain alone. Operational security, device manufacturing, seed generation and wallet firmware can all be points of failure.
Schiff warned that future technologies could create an environment more favourable to attackers, using this incident as an example. The actual path of the incident, however, was a more traditional software defect. In the end, the Coldcard hack showed that even if the bitcoin protocol is not compromised, vulnerabilities in surrounding custody infrastructure alone can expose users to major losses.