Attackers have drained nearly $114 million in bitcoin from more than 709 addresses after exploiting a Coldcard firmware flaw that weakened wallet seed randomness. The incident is forcing the self-custody community to confront uncomfortable questions about verification, reputation, and how security review is encouraged or discouraged.