The theft of more than $100 million in bitcoin from Coldcard hardware wallets has pushed the self-custody debate into a new arena: liability. On the latest episode of Unchained’s “DEX in the City,” three crypto general counsels took up the question that follows the hack itself — if users followed the security playbook and still lost their coins, can they sue anyone? Their answer was cautious. Possibly. But the law does not fit this kind of case neatly.
A 2021 firmware flaw sits at the center of the theft
According to the report, the exploit traces back to a Coldcard firmware flaw from 2021. The bug generated wallet seed phrases with too little randomness, which allowed attackers to reconstruct private keys and drain funds.
Galaxy Research’s on-chain analysis first identified 1,367 BTC drained from 4,585 addresses in coordinated waves. As new attacks surfaced, the total kept rising and moved past $100 million.
Why the case cuts deeper than a typical security incident
What made the episode unusually difficult, the panel said, is that the victims appear to have done what the industry routinely tells users to do. They used self-custody and believed they had removed one of the biggest risks in crypto ownership, only to lose their bitcoin anyway.
Vy Le, general counsel of Veda, said on the show that self-custody does not eliminate trust. It relocates it. Users may no longer rely on a centralized custodian, but they still rely on the people who built and reviewed the device. “You’re trusting the engineers who designed the hardware and the firmware that generated your keys. You’re trusting the people who reviewed the code, the auditors,” she said.
That shift in framing is what turns the Coldcard episode from a pure security story into a legal one. Le said the real question is what duty a hardware wallet manufacturer owes to its users. She ran through several possible legal theories on the show: negligence, product liability, consumer protection law, and breach of warranty.
Product liability may be the obvious claim, but not an easy one
The panel agreed that product liability is the most instinctive route. That body of law usually covers goods that are defectively designed or manufactured, or sold without adequate warnings.
Still, hardware wallet failures do not sit comfortably inside that framework when the defect is in code rather than in a physical component. The report notes that similar weaknesses have surfaced in other devices before without producing a clear legal remedy.
Katherine Kirkpatrick Bos, a co-host of the show and a longtime crypto general counsel, said there is no precedent that squarely addresses how this works in cryptography. Courts, she said, have not treated software bugs consistently as product defects, and they are not handled the same way as physical flaws. In her view, that makes a product liability suit an uphill battle even if it is the first theory many litigators would reach for on behalf of victims.
Decentralized projects make accountability even harder
Jessi Brooks, general counsel and chief compliance officer at Ribbit Capital, pointed to a harder version of the same issue in parts of crypto that do not have a company behind them at all.
For decentralized projects, Brooks said on the show, product liability might still be the best framework for addressing a flaw. The practical obstacle is different: even if a case gets through, finding an entity that can actually compensate victims may be difficult.
An accountability question for a maturing industry
Le argued that the implications go beyond one hardware wallet maker. She said crypto has long operated with a buyer-beware ethic, something that may have been tolerable when the user base was made up of a small number of people willing to accept the risks, but less so now.
Kirkpatrick Bos put it plainly on the podcast: “If crypto wants to grow up, then there does need to be that accountability.”
Le said she now hopes the episode ends up in court, not because she welcomes litigation, but because she sees it as a force that may be needed to drive change. “I do hope that there is litigation,” she said. “I hate to say it, but I think we are at the point now where litigation may be the only way to force things to improve.”
Coinkite has accepted responsibility and issued a fix
On the manufacturer side, Coinkite, the Canadian company behind Coldcard, has publicly accepted blame for the flaw. The company has released patched firmware for every model, halted shipments of units built with the vulnerable software, and emailed affected customers.
The report also notes a key limitation: the fix protects only newly generated seeds. It does not repair seeds that were already created using the buggy firmware. Chief executive Rodolfo Novak has publicly apologized, said Coinkite accepts full responsibility, and urged anyone who generated a seed on an affected Coldcard device to move funds immediately.
Whether public responsibility becomes legal responsibility is still unresolved
The discussion ended without a firm legal conclusion. The open question left hanging by the hosts was whether the accountability Coinkite has already acknowledged will ever become legal accountability in court.
Le said on the show that the law in this area is going to develop a lot over the next few years. For now, the panel’s takeaway was not a verdict so much as a warning: self-custody remains a right worth protecting, but it was never the same thing as trusting no one.

