After Coldcard Hack, Bitcoin Community Reassesses Hardware Wallet Security Standards

The Coldcard security breach exposed a firmware vulnerability that had existed for five years, but the industry’s rapid response is helping drive wider adoption of collaborative multisignature security solutions.

Swan CEO Cory Klippsten was attending a wedding in Paris when messages about the incident began flooding in.

“It was a terrible weekend for many people who lost bitcoin,” Klippsten said in an interview. “I was sending messages at 4 a.m. trying to help someone on Pacific Time move their funds to safety.”

The attack started last Thursday, when hackers exploited a hidden weakness in Coldcard hardware wallets and began draining bitcoin from thousands of affected devices.

The vulnerability was traced back to a March 2021 firmware update for Coinkite’s Coldcard wallet. The update left some users with private keys that were not as secure as intended. After three rounds of attacks, nearly 1,600 BTC worth more than $100 million had been taken from approximately 7,300 addresses, according to Galaxy Research.

Swan, a U.S.-based bitcoin company focused on buying, holding, and self-custody services, responded by temporarily freezing withdrawals for vulnerable accounts, sending alerts through its app, and providing migration support to anyone affected — including people who were not Swan customers.

“Our team immediately stopped everything else to contact clients, and then we expanded our assistance to anyone who needed help, regardless of whether they had previously used Swan,” Klippsten said.

A week after the incident, nearly 90% of the stolen bitcoin remained in the attackers’ wallets without movement. The identified attacker addresses were shared with U.S. federal authorities, while Coinkite released security updates covering all impacted Coldcard devices. A volunteer group supported by OpenSats also examined more than 150 open-source repositories and found no signs that the issue affected other wallet projects.

The breach triggered renewed debate over the risks of bitcoin self-custody, with some industry participants suggesting that investors may be better off using alternatives such as bitcoin exchange-traded funds rather than holding their own private keys.

Klippsten disagreed with that view, saying the incident has encouraged users to improve their security practices rather than abandon self-custody altogether.

“People are moving into Swan Vault right now,” he said, referring to the company’s collaborative multisignature custody service, which prevents a single device from becoming a single point of failure. “Instead of walking away from self-custody, many users are upgrading their approach.”

Klippsten said the attack, while painful for victims, could ultimately lead to a stronger bitcoin security ecosystem.

“It is heartbreaking that people lost coins, especially because many followed advice from respected industry figures and believed they were doing everything correctly. But Bitcoin is antifragile, and the tools protecting it are improving rapidly. This could become one of the most important developments for the future of self-custody.”

  • Related Posts

    CoreWeave Rallies 16% as AI Infrastructure Revenue Reaches $2.58B

    CoreWeave Rallies 16% as AI Boom Drives $2.58B Revenue CoreWeave shares jumped 16% in premarket trading Wednesday after the AI infrastructure provider posted better-than-expected quarterly results and raised its revenue…

    Continue reading
    $1.78B Bitcoin Sell Pressure Builds as Overlooked Group Moves to Exit

    Public Bitcoin Miners Quietly Contribute $1.78B in Selling Pressure Publicly traded Bitcoin mining companies have become an overlooked source of BTC selling, adding meaningful supply to the market as Bitcoin…

    Continue reading