
Three crypto general counsels say product-liability law may not cover a firmware flaw, leaving $100M Coldcard hack victims few options as law develops.
More than $100 million in bitcoin has been drained from Coldcard hardware wallets, and the theft has pushed a question crypto long avoided into the open. Three crypto general counsels, speaking on the DEX in the City podcast, said victims who followed every self-custody precaution may still have no clear path to sue. Product-liability law, the natural fit, does not stretch easily to a firmware flaw.
The exploit traces to a 2021 Coldcard firmware bug that generated wallet seed phrases with too little randomness. The output was predictable enough for attackers to reconstruct private keys across thousands of wallets. On-chain analysis from Galaxy Research identified 1,367 BTC taken from 4,585 addresses. New attacks kept surfacing, and the total climbed past $100 million.
What makes the episode a legal puzzle, the hosts argued, is that the victims did exactly what the industry preaches. Vy Le, general counsel of Veda, said the hardest part is that owners believed they had retired the risk of holding their own crypto, then lost it anyway. The lesson, she argued, is that owning your own keys never erased the need to trust someone.
Self-custody, she said, "doesn't completely eliminate trust." Owners no longer trust a centralized custodian, Le said; they trust the device's makers. "You're trusting the engineers who designed the hardware and the firmware that generated your keys. You're trusting the people who reviewed the code, the auditors."
The reframing pushes the incident from a security story into a legal one. The hosts asked whether someone who did everything right and still lost their coins can sue anyone. "What duty does a hardware wallet manufacturer owe to its users?" Le asked on the show, running through the possible theories: negligence, product liability, consumer protection law, breach of warranty.
Product liability is the instinctive claim, the hosts agreed; it is the body of law covering goods that are defectively designed or sold without adequate warnings. The weakness in the Coldcard case lives in code, not casing, and that kind of flaw has surfaced in other devices before without producing a clear legal remedy.
Katherine Kirkpatrick Bos, a co-host and longtime crypto general counsel, said no precedent addresses how this works in cryptography. "Courts have not consistently treated software bugs as product defects," she said. "They're not treated the same as physical defects. So it's actually an uphill battle to even sue on the basis of product's liability." She added that the theory would be the natural instinct for any litigator representing a victim.
Jessi Brooks, general counsel and chief compliance officer at Ribbit Capital, raised the harder version of the problem for corners of crypto with no company behind them. For decentralized projects, product liability "might be the best way to address" the flaw, Brooks said, but "finding the entity that can pay the victim, assuming the whole case goes through, is difficult."
The stakes extend beyond one manufacturer, Le argued. Crypto has run on a "caveat emptor," buyer-beware ethic, she said, tolerable when the users were a handful of "degens" who accepted the risk, less so now. "If crypto wants to grow up, then there does need to be that accountability," Kirkpatrick Bos said.
Le said she hopes the episode ends up in court, not out of love for litigation. Litigation may be the only forcing function, she said: "I do hope that there is litigation. I hate to say it, but I think we are at the point now where" litigation may be "the only way to force" things to improve.
Coinkite, the Canadian company behind Coldcard, has accepted blame for the flaw. It released patched firmware for every model and halted shipments of units built with the vulnerable software. The company also emailed affected customers.
The fix protects only newly generated seeds, not seeds created on the buggy firmware.
Chief executive Rodolfo Novak apologized and said Coinkite accepts full responsibility. He urged anyone who generated a seed on an affected Coldcard to move funds immediately.
Whether that accountability ever becomes a legal one is the open question the hosts left hanging. Le said the law in this area "is going to develop a lot in the next few years." Their closing point was that self-custody remains a right worth protecting, and it was never the same thing as trusting no one.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.