After Coldcard Hack, Bitcoin Community Reassesses Hardware Wallet Security Standards

The Coldcard security breach exposed a firmware vulnerability that had existed for five years, but the industry’s rapid response is helping drive wider adoption of collaborative multisignature security solutions.

Swan CEO Cory Klippsten was attending a wedding in Paris when messages about the incident began flooding in.

“It was a terrible weekend for many people who lost bitcoin,” Klippsten said in an interview. “I was sending messages at 4 a.m. trying to help someone on Pacific Time move their funds to safety.”

The attack started last Thursday, when hackers exploited a hidden weakness in Coldcard hardware wallets and began draining bitcoin from thousands of affected devices.

The vulnerability was traced back to a March 2021 firmware update for Coinkite’s Coldcard wallet. The update left some users with private keys that were not as secure as intended. After three rounds of attacks, nearly 1,600 BTC worth more than $100 million had been taken from approximately 7,300 addresses, according to Galaxy Research.

Swan, a U.S.-based bitcoin company focused on buying, holding, and self-custody services, responded by temporarily freezing withdrawals for vulnerable accounts, sending alerts through its app, and providing migration support to anyone affected — including people who were not Swan customers.

“Our team immediately stopped everything else to contact clients, and then we expanded our assistance to anyone who needed help, regardless of whether they had previously used Swan,” Klippsten said.

A week after the incident, nearly 90% of the stolen bitcoin remained in the attackers’ wallets without movement. The identified attacker addresses were shared with U.S. federal authorities, while Coinkite released security updates covering all impacted Coldcard devices. A volunteer group supported by OpenSats also examined more than 150 open-source repositories and found no signs that the issue affected other wallet projects.

The breach triggered renewed debate over the risks of bitcoin self-custody, with some industry participants suggesting that investors may be better off using alternatives such as bitcoin exchange-traded funds rather than holding their own private keys.

Klippsten disagreed with that view, saying the incident has encouraged users to improve their security practices rather than abandon self-custody altogether.

“People are moving into Swan Vault right now,” he said, referring to the company’s collaborative multisignature custody service, which prevents a single device from becoming a single point of failure. “Instead of walking away from self-custody, many users are upgrading their approach.”

Klippsten said the attack, while painful for victims, could ultimately lead to a stronger bitcoin security ecosystem.

“It is heartbreaking that people lost coins, especially because many followed advice from respected industry figures and believed they were doing everything correctly. But Bitcoin is antifragile, and the tools protecting it are improving rapidly. This could become one of the most important developments for the future of self-custody.”

  • Related Posts

    AI Crypto Darling Falls From $2.4B Valuation After Founder Declares Its End

    Eliza Labs founder Shaw Walters has confirmed the closure of the ELIZAOS Foundation and urged token holders to sell their holdings, bringing the project’s token journey to an end after…

    Continue reading
    Lockup Expiration Sends SpaceX Lower as Market Focus Shifts to Rising Capital Needs

    SpaceX did not sell any bitcoin during the second quarter, but its shares fell ahead of Wednesday’s market opening as investors focused on the company’s significant capital spending plans, potential…

    Continue reading