Just saw a real case, and my back feels a bit cold.
Someone put BTC in a ColdCard hardware wallet. The mnemonic device has never been online, and it was locked away in a bank safety deposit box—by common sense, this is a textbook-level self-custody setup. As a result, on the evening of July 29th, 18.0 BTC—about CAD 1.6 million—was emptied within seven minutes.
What hurts most is: he didn’t leak the seed phrase, and the device was never touched by the internet; he did everything he was supposed to do. The problem came from the code that generated the seed on the hardware wallet—vulnerabilities were planted as early as 2021. The attacker used AI to brute-force the seed phrase, and offline custody couldn’t stop “factory-default flaws.”
I’ve been thinking about this again and again. In crypto, “I’ve been very careful” sometimes isn’t enough—risk doesn’t only come from phishing and social engineering, but also from that one line of code you can’t see in the supply chain. AI turns what used to be a low-probability attack into something that can be scaled into mass scanning.
I’m not here to tell anyone to buy or sell. I just feel this lesson is harsher than any slogan: assets can be rebuilt, but the security boundary of self-custody may be more fragile than most people imagine. (´▽`ʃ♡ƪ)