Recent security failures within the Coldcard hardware wallet and the Liquid Network sidechain have caused nearly $500 million in losses. these 2024 exploits have shaken the foundational belief that self-custody eliminates third-party risk.

Advertisement

The $100 million firmware flaw in Coldcard wallets

The Coldcard hardware wallet, often considered a gold standard for offline security, suffered a critical vulnerability that compromised thousands of users. As the report notes , a coding error in firmware versions dating back to March 2021 caused the device to bypass its secure hardware random number generator. Instead, the device relied on a more predictable, software-based generator.

This technical oversight allowed remote attackers to brute-force recovery seed phrases, leading to the unauthorized transfer of over $100 million in Bitcoin. The incident highlights a growing realization in the industry: even when users take personal responsibility for their assets, they remain tethered to the integrity of the device's firmware and the security of the hardware supply chain.

A $320 million drain through the Liquid Network and SideSwap

A separate but equally massive exploit targeted the Liquid Network, a federated sidechain developed by Blockstream. Rather than a direct compromise of the federation's 11-of-15 multisig keys, the attack exploited a consensus bug within the Elements node software. This flaw allowed an attacker to mint unbacked L-BTC and subsequently cash it out through the SideSwap platform.

According to the source, the attacker successfully processed a 4,000 L-BTC order, valued at approximately $320 million at the time. SideSwap's role in the escalation was significant; the firm acknowledged that keeping its peg-out authorization key online for automated payouts, combined with a lack of velocity and origin checks, allowed the massive, unverified order to process without human intervention.

Shifting the blame from FTX-style exchange failures

These recent exploits represent a departure from the traditional security crises that have plagued the cryptocurrency market.. In previous years, major losses were typically attributed to the collapse of centralized , unregulated entities like FTX. In those instances, users could point to the failure of a custodian as the primary cause of loss.

The current landscape is different. With the approval of Bitcoin ETFs from institutions like BlackRock and Fidelity, much of the institutional market has moved toward regulatted, custodial solutions. however, these new failures in the Coldcard and Liquid ecosystems target the very peopple who sought to avoid centralized risk entirely. this suggests that the industry is moving from a period of "user error" toward a period of "systemic technical error," where the complexity of the code itself becomes the primary threat vector.

The mystery of the 598.5 Bitcoin windfall

While much of the stolen Liquid Network funds were eventually recovered, a significant portion remains missing. The attackers, who initially claimed to be "white-hat" security researchers, returned 3,400 Bitcoin but kept 598.5 BTC, worth roughly $47 million. The identity of these individuals and the ultimate destination of these funds remain unknown.

Furthermore, the source does not address whether these vulnerabilities could be linked to broader supply-chain tampering during the manufacturing or shipping of hardware wallets. It also remains unclear if the automated systems used by SideSwap will be updated with the necessary size and velocity checks to prevent a repeat of this $320 million drain.