HomeLBank News Center
Jameson Lopp says Coldcard exploit exposes limits of Bitcoin's 'don't trust, verify' mantra
jameson-lopp-coldcard-exploit-exposes-limits-bitcoins-dont-trust-verify-mantra
Jameson Lopp says Coldcard exploit exposes limits of Bitcoin's 'don't trust, verify' mantra
Lopp said AI is reshaping wallet security by helping attackers uncover hidden bugs and developers audit code faster.Researchers continue to identify new waves of Coldcard-related thefts, pushing the estimated losses well beyond the initial $70 million.
2026-08-04 Source:theblock.co

Last week's ongoing Coldcard exploit has already drained more than 1,300 bitcoin (BTC), worth roughly $83 million, from thousands of addresses across multiple waves, making it one of the biggest self-custody failures in Bitcoin history.

The incident is also sparking conversations over how users should approach self-custody.

For Bitcoin security researcher and Casa co-founder Jameson Lopp, the incident doesn't invalidate self-custody, but he does see it as exposing the limits of one of Bitcoin's oldest principles: "Don't trust, verify."

Speaking with The Block on Monday's The Starting Block podcast, Lopp argued that the challenge isn't whether "don't trust, verify" is a worthwhile or valid principle; it's that few users can realistically put it into practice.

"It's a good mantra ... But you have to understand that verification of complex software and hardware is simply not feasible for 99.9% of the population," Lopp said.

Shifting trust

The Coldcard vulnerability was introduced in its seed-generation process in 2021. It reduced the entropy used in randomizing wallet seeds, allowing attackers to brute-force affected wallets without ever needing to physically touch the devices.

Blockchain researchers have continued to identify fresh waves of thefts — up to a potential fourth as of Sunday, according to Galaxy Digital head of research Alex Thorn — days after the vulnerability became public.

Lopp said the incident shows that even with Bitcoin, the element of trust exists for most who practice self-custody. Users inevitably end up relying on hardware vendors, software developers and security researchers to validate systems they cannot audit themselves.

"Ultimately, what happens is ... we end up trusting someone that we suspect has verified it," he said.

That doesn't mean self-custody is fundamentally broken, Lopp said, but it shows why users shouldn't rely on any single piece of the puzzle.

"The entire point ... is to not trust any one thing. Not trust any one hardware vendor, not trust any one piece of software," he said. 

Foundation co-founder and CEO Zach Herbert expressed a similar view earlier in the program, calling it "really dangerous" to conclude that self-custody is dead because of the Coldcard exploit. Instead, Herbert said it should motivate the industry to strengthen best security practices.

Self-custody comes with responsibility

Lopp said the exploit doesn't change the value proposition of self-custody, but it reinforces the responsibilities that come along with it.

"Self-custody is for anyone willing to take on the responsibility that comes with it," he said.

AI and wallet security

Lopp believes advances in artificial intelligence likely accelerated the discovery of the Coldcard vulnerability.

"Advancements in large language models are drastically changing the security landscape," he said, pointing to a growing number of obscure software flaws that AI has uncovered in widely used products.

While AI is making it easier for attackers to identify vulnerabilities, it is also dramatically reducing the cost of code review for defenders, creating a race between the two sides, Lopp said.

That echoes comments from CoinKite CEO Rodolfo Novak, who took responsibility for the firmware bug last week and described the incident as "a sober reality of the new AI paradigm." Novak said AI-assisted code review can uncover latent vulnerabilities faster than experienced security researchers, potentially allowing attackers to exploit publicly available code before defenders find the same flaws.

Not the end of self-custody

While the Coldcard exploit has been devastating for affected users, Lopp noted that critical hardware wallet failures have happened before, and they haven't changed the fundamental case for self-custody.

"It has happened, I wanna say, a dozen times before, and I fully expect it to happen again," he said, adding that each incident has raised security standards across the industry.

The challenge, he argued, is recognizing those assumptions of trust, and reducing them wherever possible.


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.