Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$75,691.4 -1.18%
ETH Ethereum
$2,395.66 -2.42%
SOL Solana
$97.1 -3.24%
BNB BNB Chain
$711.8 -0.86%
XRP XRP Ledger
$1.27 -10.06%
DOGE Dogecoin
$0.0792 -4.14%
ADA Cardano
$0.1925 -5.96%
AVAX Avalanche
$7.26 -3.62%
DOT Polkadot
$0.9745 -1.38%
LINK Chainlink
$10.71 -5.94%

Fear & Greed

51

Neutral

Market Sentiment

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$75,691.4
1
Ethereum
ETH
$2,395.66
1
Solana
SOL
$97.1
1
BNB Chain
BNB
$711.8
1
XRP Ledger
XRP
$1.27
1
Dogecoin
DOGE
$0.0792
1
Cardano
ADA
$0.1925
1
Avalanche
AVAX
$7.26
1
Polkadot
DOT
$0.9745
1
Chainlink
LINK
$10.71

🐋 Whale Tracker

🟢
0x0b4e...abdc
2m ago
In
4,008,813 DOGE
🔵
0x878f...e4d4
3h ago
Stake
12,674 BNB
🔵
0x6e59...5009
30m ago
Stake
1,186.61 BTC

💡 Smart Money

0x61c8...7077
Arbitrage Bot
+$5.0M
60%
0x280f...6d63
Institutional Custody
+$4.8M
74%
0x0826...a03a
Experienced On-chain Trader
+$1.8M
81%

🧮 Tools

All →
Metaverse

The Self-Custody Autopsy: BTCPay's Leaked Macaroons and Coldcard's $111 Million Silence

MaxMeta
The ledger remembers what the promoters forgot. Two incidents, separated by attack surface but united by a single theme, surfaced within days of each other. Galaxy Research confirmed that 1,719 BTC — approximately $111 million at current prices — was stolen from Coldcard users. BTCPay Server confirmed an actively exploited vulnerability in its payment processor: an unauthenticated remote attacker can seize LND credential files. The Bitcoin protocol itself was never touched. The self-custody tooling wrapped around it is another story. These are not failures of consensus. They are failures of the peripheral software stack that converts Bitcoin ownership into practical use. BTCPay Server occupies a precise niche in the Bitcoin ecosystem: an open-source, self-hosted payment processor that lets merchants receive on-chain and Lightning payments without a custodian. No KYC. No 1-3 percent processing fee. No third-party risk. In exchange, the operator assumes the full weight of security maintenance. LND — Lightning Network Daemon — is the node implementation that manages the Lightning channels through which those payments flow. Coldcard is a hardware wallet marketed as the gold standard of cold storage, engineered for users who assume their computer is already compromised. Galaxy Research played the role of loss assessor, tracking stolen funds on-chain and confirming the 1,719 BTC figure. The connective tissue between the two events is not the same technology. It is the same trust model. Custodial processors like BitPay absorb the security burden and price it into their fees. Self-custody flips the equation: the operator owns every risk, including the obligation to patch, monitor, and upgrade in a timely fashion. When a vulnerability is confirmed as actively exploited, the latency between disclosure and deployment becomes the true attack surface. The broader market, caught in a sideways drift, will likely absorb this news with indifference. That indifference is the story. The BTCPay attack chain is painfully short. A frontend vulnerability permits an unauthenticated remote attacker to read files from the server. Specifically, the attacker pulls the LND .macaroon file. In a Lightning deployment, admin.macaroon is effectively the master key to the node's API interface. It grants full control over Lightning channels, including the ability to route funds, close channels, and sweep balances. The attack path: read the file, authenticate as the node operator, route funds from open channels to the attacker's node, close the channels, withdraw to a controlled address. The entire sequence requires no user interaction, no phishing, no social engineering. Just port scanning, a crafted HTTP request, and a credential file that should never have been readable from the web layer. The fix architecture is instructive. BTCPay Server 2.4.2 patches the file-leak vulnerability itself. LND 0.21.1 goes a critical step further: the upgrade automatically regenerates macaroon credentials. Even if an attacker has already exfiltrated the old credentials, the upgrade invalidates them at the moment it is applied. Lost funds are not recoverable through this mechanism, but the bleeding stops. The team has deliberately withheld technical specifics — a responsible-disclosure posture that reduces the probability of mass exploitation against the long tail of unpatched instances. For users who cannot upgrade immediately, the official recommendation is unambiguous: take the node offline. There is a detail in the timeline that deserves scrutiny. The disclosure arrived with a patch already prepared. That means the vulnerability was discovered, assessed, and fixed before the public was informed. The attacker, by contrast, had already developed an exploit and was running it against internet-facing instances. The asymmetry is worth stating plainly: the attacker held a head start of unknown duration, and every vulnerable node exposed to the internet during that window must be assumed compromised. The scan-and-exploit cycle in the wild is measured in hours, not weeks. If the attacker harvested credentials across this interval, the confirmed losses could be well below the real figure. The deeper structural problem is architectural. An LND node is, by design, a hot wallet. Its private keys reside on an online server because Lightning channels require active participation in signing for routing and settlement. The macaroon is the sole gatekeeper between a web request and those keys. There is no second-factor authorization for large channel sweeps. No cold-signing requirement for balance transfers. No velocity check or transaction limit. A single vulnerability in the web-facing layer is sufficient to drain the entire node. This is exactly the pattern I have seen repeated across nearly three decades of observing this industry break and rebuild. In 2017, I spent four months dissecting the Solidity bytecode of a Layer-0 infrastructure project that had raised $120 million. I found that their "proprietary consensus" was a fork of the Geth client with renamed variables. The lesson that carried: most projects fail not at the cryptographic layer, but at the boundaries between layers — where developers assume a credential will never be readable and an interface will never be exposed. The macaroon model is the same failure mode with different clothes. The Coldcard incident is murkier and, in some ways, more disturbing. 1,719 BTC is not a rounding error. It represents either a substantial number of affected users or a single whale-scale operation. The specific attack vector has not been disclosed. What we know: hardware wallet users lost funds. What we do not know: whether the device itself was compromised, or whether the attack moved through the surrounding workflow — the SD card import process, the multisig coordinator tools, the companion desktop applications. From my audit experience, when a hardware wallet brand loses user funds at this scale, the probability that the silicon itself was defeated is low. The probability that the surrounding software ecosystem was compromised is significantly higher. Low probability is not zero probability, and the absence of a disclosed vector is, itself, a risk marker. The BTCPay and Coldcard events sit in the same workflow more often than not. A substantial fraction of self-custody merchants pair their BTCPay instance with a Coldcard for cold fund management, using tools like Specter or Electrum to coordinate. The natural coupling explains why both incidents landed in the same news cycle. It also exposes a deeper problem: the security of a self-custody stack is a chain, and the weakest link determines the strength of the whole. A compromised payment processor can drain funds that were secured by an uncompromised hardware wallet, because the funds pass through the processor's address management on their way to settlement. The hardware was fine. The workflow was not. The economic impact requires calibration. $111 million confirmed. A projected $130 million or more. Relative to Bitcoin's daily trading volume — consistently above $10 billion — this is statistical noise. Historical precedent confirms the pattern. Bitfinex lost 120,000 BTC in 2016, and BTC dropped roughly 20 percent before recovering. Ronin Bridge lost $625 million in 2022, and BTC barely moved. Atomic Wallet lost $100 million in 2023 with no measurable BTC reaction. A $100-300 million theft from peripheral tools has never moved the market in a sustained way. The market follows macro liquidity, not single-point risk events. But the absence of price impact does not mean the absence of economic consequence. The real damage is a trust discount applied to the self-custody narrative. Every merchant running BTCPay now faces a revised cost-benefit calculation: is the 1-3 percent saved in processing fees worth the hours of maintenance, the monitoring obligations, and the upgrade discipline the stack demands? The security tax of self-custody has become visible. For a non-technical merchant, the calculus may shift toward custodial options. The market consequence will not be a BTC sell-off. It will be a slow migration of less sophisticated users away from self-custody tooling, driven by the realization that sovereignty has a maintenance cost that most never budgeted for. The bulls deserve their due. The protocol survived. Bitcoin's consensus layer was not part of either attack. No cryptographic primitive was broken. No 51 percent attack occurred. The response teams performed professionally: patch releases within days, clear upgrade guidance, responsible disclosure. The ecosystem is learning, and the confirmed losses — while painful — represent a fraction of the total value secured by self-custody tools. The blind spot is structural fragility. A self-custody setup is only as secure as its least-maintained component. BTCPay users who fail to upgrade between disclosure and mass exploitation remain exposed, and history suggests that window is measured in weeks, not days. Attackers scan the entire internet for unpatched instances. The slowest maintainer in the ecosystem sets the effective security level for everyone who interoperates with them. The BTCPay and Coldcard events may well be unrelated — and the possibility remains that they are two observable signals from a broader campaign targeting self-custody users across multiple toolchains. The public data confirms two incidents. It does not rule out others. Every rug pull leaves a trail of gas fees. The 1,719 BTC will leave its own trail, visible to anyone with the patience to follow it. The likely near-term market response is uninspiring. Some users will migrate from Coldcard to Ledger or Trezor. Some merchants will shift from BTCPay to BitPay or OpenNode. Some institutional allocators will add a self-custody security checklist to their due diligence. None of these movements will register on a price chart. But they will compound over time. Security incidents operate on a slow fuse: the confidence erosion is invisible in the daily candle, and the effects surface months later in adoption curves, node counts, and the willingness of non-technical users to take self-custody seriously. The deeper question is not whether self-custody works. It does. The question is whether the people who sell self-custody as a simple alternative to banks are willing to be honest about the maintenance burden it imposes. Self-custody is a discipline, not a purchase. It must be earned through monitoring, verified through audit, and proven through timely response. Silence in the code is louder than the contract — and in this case, the code was not silent. It was leaking credentials to anyone who asked. The next incident will tell us who was listening.