Solana Mobile Issues Phishing Warning Following Brevo Security Breach
CFTC Investigates Polymarket for Suspected Insider Trading
HYPE Price Eyes $100 After $28.8M Whale Accumulation
Revolut Leaks Customer Data to Hackers Posing as State Agency
Morgan Stanley Initiates Coverage on Coinbase with 'Neutral' Rating and $250 Price Target
GTA Mod Adds Flock Cameras—And Lets Players Destroy Them
Nasdaq and Boerse Stuttgart Want the EU's Tokenisation Cap Gone
XRP Ledger just quietly activated critical foundation for its upcoming new lending protocol
Community Banks Urged to Adopt Digital Payments and Stablecoins
solana CO-FOUNDER toly CALLS RobinhoodCrypto’S L2 MODEL A SHIT BUSINESS ESPECIALLY FOR A...
Whale 0x3305 keeps buying $HYPE every day!Over the past 15 days, the whale has bought a total of...
Zcash Mining Activity Rises Over 2.5x in 2026, Now More Profitable Than Bitcoin’s — Grayscale Research
Denmark Raises Interest Rates to 2.10% in Response to ECB Hike
Bitcoin Price Takes a $3,215 Ride Just to Land Back at $77K
This Textbook XRP Chart Pattern Could Trigger Rally Toward $60, Analyst Asserts
UK Reform Party Receives £72 Million in Donations from Two Crypto Tycoons in Two Days
Solana’s weekly transaction count surpassed 1B, crossing a new ATH record....
Staked ether should be seen as the benchmark of the decentralized economy
The dilution trap where Bitcoin holdings rise while shareholder value stalls
Morgan Stanley Predicts Yen Decline Amid Carry Trade Rebuilding
170,811,658 $USDC (170,806,533 USD) transferred from USDC Treasury to #Kraken...
Bitcoin’s Price Just Drew an $85M Bet From Last Year’s ETH Top-Caller
110,819,258 $USDC (110,815,933 USD) minted at USDC Treasury...
USDC Treasury Mints Approximately 111 Million USDC on Ethereum Chain
Mexican Authorities Dismantle Clandestine Crypto Mining Operation Linked to Cartels
Investigator ZachXBT says he was blocked by Revolut on X after data breach alert....
Polymarket Indicates High Probability of Federal Reserve Rate Hike on September 16
ChatGPT Images 2.5 vs Nano Banana 2: Which One is Better?
Revolut Exposed Passports and Bitcoin Records After Fake Government Request: Report
Polymarket and Kalshi Lack EU Authorization for Event Contracts, ESMA Says
Solana Reclaims Top Spot in Daily DEX Volume, Surpassing Robinhood Chain
Hunter Biden’s LAPTOP Burns $3.5M After Eric Trump and Beeple Mentions
Anchorage Digital Gives Institutions Direct Access to…
Weekly Project Updates: Base App reverts to Coinbase Wallet, Kalshi launch Gold & Silver...
Coinbase User Alleges $1.3M USDC Freeze Led to Hyperliquid…
StonkFun's 24-Hour Revenue Surpasses Hyperliquid, Pump.fun, Fomo, and GMGN
Tokenized Grindr Stock on Solana Achieves $31 Million in Trading Volume
Donut AI Founder Reveals Significant On-Chain Holdings and Trading Profits
ICYMI: Bybit AI is live.Our CEO @benbybit went live to reveal it himself. What it does, how it...
LaunchOnSF FLIPS HyperliquidX, Pumpfun, fomo, gmgnai IN 24H REVENUE - ponsdotfamily...
Pineapple Financial Tokenizes Over $1 Billion in Mortgages on Injective Blockchain
Ethereum Price Momentum Builds as $1M+ Whale Transactions Surge
zachxbt SAYS HE WAS BLOCKED BY Revolut AND revolutsupport ON X ...
WuBlockchain note: Arthur Hayes has a relatively poor historical track record on market forecasts...
Betmgm Bets on Injury Refunds and a $50K Free-to-Play NFL Jackpot
Clearpool Proposes Migration to XRP Ledger for Institutional Lending
Ripple (XRP) Price Outlook: Two Key Metrics Are Flashing Warning Signs
BTC Settles at $77K After a Wild Ride, ETH Slumps Following Major Rally: Weekend Watch
ESMA Warns Crypto's Deepening Ties to Finance Could Amplify the Next Shock
Wall Street is building tokenized deposits to lock in customer balances
Corporate America Anticipates $2.5 Trillion AI Spending Surge Amid Mixed Returns
Revolut Allegedly Leaks User Data in Targeted Attack on High-Net-Worth Clients
Tokenized Stock Asset Holders Surge 619.1% in Past 90 Days, Reaching 3.6 Million
Bitcoin activity, passports exposed after Revolut falls for fake government request
Arthur Hayes: I Don't Follow Any Bitcoin Technical IndicatorsI In an August 23, 2026 video...
Bitwise is closing the lowest-fee Dogecoin ETF after rivals captured nearly all the capital
ZachXBT: Revolut Allegedly Leaks User Data, Likely Targeting High-Net-Worth IndividualsOn-chain...
Latam Banking Giant Nu Launches US Operations With Lead Bank
Revolut Handed Over Bitcoin Histories, Passports on Spoofed Government Email
Alameda/FTX Address Unlocks $20.62 Million in SOL for Creditor Compensation
India's Demat 2.0 Pilot Settles $107M in Bonds Using the Digital Rupee
Follow the Money: Over $200 Million in Venture Investments, a $400 Million Acquisition, and Weak Activity From Corporate Investors
Trader's $114.37M ETH Long Position Turns from $4.9M Floating Loss to $1.98M Profit
Robinhood CEO Spoke Out Against Issuers’ Right to Block Shares’ Tokenization
Bitcoin ETFs See $461M Outflows This Week With Zero Inflows
Ethereum Whales Just Woke Up as ETH Exploded to 8-Month High: What’s Next?
Blockstream bets 600 Bitcoin by rejecting Liquid hacker’s $50 million bounty demand
A16z Wants Your Crypto Private and Your Car Tracked by Flock
BNB Price Faces $750 Test After Sharp Rebound: Can Bulls Push Higher?
The ColdCard "Hack" Should Not Be Called Theft

We are going to take a somewhat-odd sounding position here. ColdCard was clearly exploited in some sense. But the nature of the product, and the inability due to product design to differentiate between "theft" and intentional use, leaves us thinking users should not have recourse as though their assets were stolen. We do think they are welcome to go after the team for a number of terrible decisions and defective work products. But "hack" in the conventional sense of "unauthorized access leading to asset loss which law enforcement should try to claw back" does not fit this case.
The Setup
One point of self-custody is to frustrate directives from the legal system. Possession of the keys is intended to be the sole arbiter of ownership. This is many people's main motivation to use Bitcoin. And it is on the short list of motivations for many more. ColdCard was marketed at least in part as a way to escape traditional rules. This does not, in and of itself, mean hacks cannot happen or users deserve this kind of treatment. But we think on a fuller analysis of the circumstances "hack" is the wrong word.
Of course we cannot know the intentions and desires of each and every user of ColdCard (or any other piece of software). But ColdCard's own docs make clear that escaping the possibility of government control is part of the sales pitch. And many voices in and around the self-custody space constantly preach about escaping the possibility of control. No company selling a product is going to come out and say "our use case is frustrating court orders" so we do have to read between the lines a bit. Censorship resistance is often code for this.
At the same time there needs to be a single policy for the entire class of users. All these users opted into a self-custody system with censorship resistance as a core feature. There are many ways to keep assets safe. And these users should be forced to live with the consequences of their decisions. Again: we are not saying this automatically means your assets are a free-for-all for hackers. And we need to look at the entire ColdCard situation.
If you put valuables in a safe the intent is to keep them safe. But you do not intend that whoever can open the safe owns the contents. If you intend for the keys to convey ownership then let the keys convey ownership. We should not encourage people to enact this opt-out and defer entirely to control over the keys and then to get a do-over if they trusted the wrong scheme. What was your justification for trying to use private self-custody anyway? We know for at least a reasonable fraction of people it is non-compliance with various laws.
Users that want to frustrate the legal system in this way might well deserve what they get. If you do not intend to follow court orders directing you to use your private keys to open a lock then you should not be able to go to that same court and claim someone else picked your lock and you want your money back.
If the intent is to frustrate court orders then it is too rich to expect you can go get one to recover your money. Similarly, if you intend to rely on a system where a known mathematical process controls all you have to take more responsibility for checking how the system works than when you rely on, say, the courts. Giving up one for the other must be understood in total. All the circumstances matter.
Is This About Fairness?
No. It is not about fairness. Life is not fair. This is not about fairness – it is about enforcing the bargain these users made in a way that is consistent with other sorts of bargains other users make. You wanted to opt out of the traditional legal/asset-protection system. And you should not be allowed to now cancel that move and go crawling back when you need that system's help. That would be not just unfair to everyone that participates in and supports the traditional system – it would be unfair to self-custody users who expend resources to do it properly. The cost of user negligence cannot simply be inconvenience.
There is of course a line somewhere. Hacks are still possible. But as we will cover below it sure looks like users here intended to defer to a system they did not realize was broken for years. Only when their inability to detect the problem – or maybe just their lack of interest in looking for the problem – led to disaster did they became unhappy with the system. Self-custody must impose a larger burden on users than bank- or exchange- or whatever-regulated businesses or "traditional" custody. We are not saying in every case this means a "hack" is not a hack. But sometimes it might be. Start by opening up to this possibility.
Remember that when we are talking about hacks and thefts and such there often are no good answers. The "good" answer, such as it is, is for the hack to have never occurred. But conditioned on the hack happening it is normal for all the available options to feel bad. To the extent there is a real fairness issue here: the problem is that the team did not treat their own customers and users fairly. The problem is that there are not enough assets around to satisfy everyone with their hand out. Even if assets can be clawed back that takes time and energy and resources from law enforcement. Someone has to pay for that. And law enforcement will, again by construction, do this instead of something else. Someone is going to be unhappy no matter what we do.
The recall the root cause: a bunch of self-custody users never bothered to check if the thing they trusted was in fact trustworthy. Society as a whole has no interest in encouraging blind faith in tools people do not understand and do not check for themselves. So there is a bit of a broader social interest in disincentivizing users from allowing this to happen again. And make no mistake: the flaws that were exploited here was publicly visible for a long time. These self-custody users allowed this to happen. This is not victim blaming – it is stating the plain fact that users did not do sufficient due diligence on a product that should be all about due diligence.
Fraud
The team seems to have known about the problem for quite some time. If they were selling a product with this kind of security vulnerability and covered that up then users almost certainly can claim they were defrauded. Even if the team did not know – and, again, there is mounting evidence they did know – at some point incompetence is negligence is legal liability. ColdCard can have defrauded its users even while we do not think those users were actually hacked.
There is also evidence the team were, in general, careless and had bad security practices. To some extent this rhymes with FTX where after the blow-up everyone pled ignorance and moaned "how could we have known?" But when you go back and look at the record – whether it is SBF interviews or information emerging about ColdCard – there were obvious red flags. People just chose not to look. Or not to believe.
Does that excuse fraud? Of course not. But users here were victims of incompetence and fraud, not theft. And as we will see below, the alternative where this is considered a hack and users try to claw back assets introduces a whole other set of difficult problems.
We would also point out that the errant code was publicly visible for years. This is the core of the "it is not a hack because users did not exercise sufficient care over their self-custody solution" argument. And the company can try a defense like:
- Yes we made marketing statements which were inaccurate. Marketing is allowed to be a bit inaccurate. Puffery and such
- We had disclaimers
- The code with the problems was always public. So, inclusive of the disclaimers, users were supposed to check.
- All software has bugs. So rejecting 2+3 as a defense is a bad precedent.
We do not really think that will work given evidence the team was notified of the problem and did not proactively notify users or fix the problem. We do think the team is heavily at fault and liable here.
But in a counterfactual world where the team was never told, and has no internal communications about the bug, that theory might fly. To be clear: we do not think a jury will accept that theory. But a judge might throw out a verdict on that basis. Maybe.
Refusal to Admit the Real Problem
CoinKite, the company behind this steaming pile, put out a Technical Deep Dive that is a strange blend of bland descriptions for serious problems, unnecessary technobabble to mask how dumb these problems were, and some false statements.
The Summary section begins:
A complex and subtle series of bugs prevented the hardware RNG from contributing randomness in certain versions of the firmware. We were unaware of the bug until today.
Not only were the problems not "complex and subtle" but there is at least some evidence the team knew for a long time.
So here too we have a classic setup. Team does something dumb and amateur. This results in a large problem. And the team then puts out technobabble in a feeble attempt to cover up how dumb and incompetent their actions were.
The simplest explanation here is that the technobabble sounds and reads the way it does for the same reason the team made the mistake to begin with: their understanding of the field in which their company operates is far less than it should be. And it is far less than the team believes it is. Calling the people involved arrogant and incompetent feels more like a factual observation than an opinion.
Choosing Self-Custody Must Be Irreversible
Courts should recognize that derivations of private keys without any actual theft – hacking or stealing someone's device, physically threatening someone, etc. – do actually transfer ownership. This sounds ridiculous but is actually just a straightforward consequence of other reasonable-sounding things. The easiest way to see this is correct is to consider the alternatives.
Say you want self-custody to be recognized as legal and legitimate. Fine. So courts cannot forcibly relocate assets. And securing an order or sentence for contempt to cajole someone into doing something "voluntarily" that is really involuntary requires evidence of a crime or some misdeed not just an arbitrary desire to relocate assets. If the court cannot press the button for you then it needs solid evidence to, in the limit, send someone to jail for not pressing the button following an order.
Now say you send someone assets to make a purchase or as part of a swap or other financial transaction. What stops you from claiming that transfer was theft? The entire thing is supposed to be based on control over private keys. Your outgoing transfer was signed with the keys so it is legitimate. The receiver controls assets with their keys so ownership is legitimate. The bar to upset this situation needs to be evidence of a hack or break-in or theft or something. Merely claiming "hey I did not transfer this" cannot be enough. Why? Because then you have chaos. Self-custody will not be legitimate and usable if you can run to court without direct evidence of a crime. Not a theoretical way someone could have exploited something to take your money. Direct evidence. Or it is chaos.
If these transfers are considered theft and people try to claw back how is that going to get adjudicated? How many people will claim to claw back payments they actually did make? The whole thing is supposed to be based on keys = control = ownership. If we upset that balance then every transaction can and will get litigated. Anyone paying out of a ColdCard (of the relevant versions) can claim they were a victim and there really is no way to tell.
Scam-Adjacent
There are already scams out there where criminals falsely claim to have been defrauded and report people to the police to get their tokens frozen and clawed back. Variants of this problem exist today.
Our position is merely that a claim assets were "stolen" from self-custody should require direct evidence of an independent hack or intrusion or similar crime. Bad random numbers do not give that kind of trail. User's private data was never touched. A bunch of simultaneous transfers the users claim were involuntary sure is suggestive of a problem. And the ColdCard team surely did things wrong. But theft? How can we differentiate between the "hacker" and someone that just wants to reverse a legitimate payment?
From a digital forensics perspective there is nothing that differentiates a legit ColdCard payment from one borne of this incident. If we cannot tell one from the other we cannot treat them differently. The nature of the flaw in ColdCard is that there are no logs. This is a feature of self-custody. Maybe it is a feature users do not now want but it has been there all along.
Further, any trail that tries to prove there was a hack needs to also show the assets came from some kind of legitimate place. Self-custody itself is not proof anything wrong happened – but the process needs to be thorough enough that users running unlicensed money changers and the like cannot use the police to recover assets which were themselves proceeds of crime. Trying to claw back flows out of systems where "hacks" are technically indistinguishable from legitimate transfers can clearly introduce some big issues.
If you try to report the theft of a large quantity of cash from your house the police are reasonably going to ask where it came from even though holding cash is perfectly legal. This is no different.
If someone had logs proving their computer was hacked. Or video footage of someone breaking into a safe: yes sure those are hacks. Those are theft. But we must distinguish this case from those if self-custody is to retain any meaning over the medium- to long-term. Otherwise it will either be a court-approved license to crime or always and everywhere suspect. Neither of those is compatible with self-custody being legitimate, accepted and legal.
Our core thesis here is really very simple: To live outside the law you must be honest. If you want to lean on self-custody in a way that consciously, knowingly, frustrates court orders and capital controls and the like then you need to take responsibility for verifying the code which manages your custody. Users relying on intentionally ungovernable systems should not be able to go to law enforcement and ask for help later. Because if they can the entire system will unravel in short order.
On a related note: if you trust your assets to an platform that lacks the required licenses, and your assets are lost in a spear phishing attack: yes we think that is a hack and yes law enforcement should be responsive. But we do not think those efforts deserve much priority in much the same way a drug dealer can absolutely report a crime if they are held up at gunpoint but we do not really expect them to report it or the police to spend a lot of time on the matter.
If you want to operate further from oversight you should expect to have fewer people to call when something goes wrong. Impacted users can (and almost surely will) sue the ColdCard team. Fair enough. They also are unlikely to get much money back. That, too, is both a bug and a feature of self-custody.
Source: Blockhead