What to Know

  • Attackers exploited a five-year-old firmware flaw affecting Coldcard hardware wallets.
  • The defect was tied to a March 2021 firmware update for the Coinkite-made wallet.
  • Almost 1,600 BTC valued at over $100 million was swept from around 7,300 addresses, according to Galaxy Research.
  • Three waves of attack drained bitcoin from vulnerable wallets.
  • Swan CEO Cory Klippsten said the incident pushed bitcoin holders to reexamine custody decisions rather than abandon self-custody.
  • Swan paused withdrawals for at-risk clients, sent in-app warnings and expanded migration support beyond its own user base.
  • Nearly 90% of the stolen coins remain unmoved onchain a week after the attack.
  • Confirmed attacker addresses have been shared with U.S. federal law enforcement.
  • Toronto-based Coinkite has patched every affected device line.
  • A volunteer team funded by OpenSats scanned more than 150 open-source repositories and found no evidence that the issue extended beyond Coldcard.
  • Some market participants now see collaborative multisig vaults as a stronger model because no single compromised device can put funds at risk.

Coldcard Exploit Forces a Hard Look at Bitcoin Custody

A major Coldcard exploit has become one of the most consequential self-custody security events in recent bitcoin history, forcing holders, wallet makers and service providers to reassess how private keys should be protected. The attack targeted a firmware flaw that had gone undetected for five years, exposing a weakness in a widely used hardware wallet setup and triggering a rapid industry response aimed at moving vulnerable coins to safer arrangements.

The incident unfolded when attackers began draining bitcoin from thousands of Coldcard hardware wallets. The flaw was linked to a March 2021 firmware update for the Coinkite-made device, which left affected users with private keys that were less secure than they should have been. After three waves of attack, almost 1,600 BTC valued at over $100 million had been swept from around 7,300 addresses, according to Galaxy Research.

For many bitcoin holders, the episode was especially painful because the affected users had attempted to follow one of the core security principles often promoted across the industry: remove coins from exchanges and take direct control of private keys. The exploit did not undermine the basic idea of self-custody, but it did expose how much security depends on implementation details, firmware quality, wallet generation processes and the resilience of backup plans.

Swan Moves to Help At-Risk Holders

Swan CEO Cory Klippsten said the attack immediately prompted bitcoin holders to reassess their custody decisions. He was in Paris for a wedding when messages began arriving from people trying to determine whether their coins were exposed and how quickly they needed to act. Klippsten described the weekend as brutal for those who lost bitcoin and said he was sending messages at 4 a.m. to help someone on Pacific Time move coins to safety.

Swan, a U.S.-based platform that helps individuals buy, hold and self-custody bitcoin, responded by pausing withdrawals for at-risk clients, sending in-app warnings and opening migration support well beyond its own customer base. Klippsten said the team dropped everything to start calling clients, then expanded assistance to anyone who needed help, including people who had never been Swan clients.

That response reflected a broader emergency posture across parts of the bitcoin ecosystem. When a hardware wallet vulnerability becomes actively exploited, speed matters. Holders must determine whether a device or seed was affected, decide whether to move funds, create a safer destination, verify addresses and avoid making mistakes under stress. For inexperienced users, that process can be difficult even in normal conditions; during an active exploit, the operational risk rises sharply.

Why the Exploit Hit the Self-Custody Debate

The attack quickly fueled debate over whether direct bitcoin custody is too complex for many investors. Some industry voices suggested that investors should consider gaining exposure through products such as exchange-traded funds rather than holding bitcoin themselves. That argument is not new, but the Coldcard exploit gave it fresh urgency by showing that even users attempting to follow recognized self-custody practices can face unexpected technical risks.

Klippsten rejected the idea that the event marks a retreat from self-custody. His view is that affected users and concerned holders are not giving up on holding their own bitcoin. Instead, they are examining how to make their bitcoin harder to access by an attacker. He said people are moving into Swan Vault, the firm’s collaborative multisig product, where no single device can put a user’s funds at risk.

The distinction is central to the future of bitcoin security. Basic single-device self-custody can give users direct control, but it can also create a single point of failure. If the wallet, seed generation process, backup method or signing device is compromised, the user may have limited protection. Collaborative multisig changes that risk model by requiring multiple keys or approvals, so one compromised device is not enough to drain funds by itself.

Collaborative Multisig Gains Momentum

Collaborative multisig arrangements have existed for years, but the Coldcard attack may accelerate adoption among users who previously considered a single hardware wallet sufficient. In a multisig structure, different keys can be held across separate devices, locations or parties. A collaborative vault can allow a user to retain meaningful control while adding safeguards that help prevent a single technical failure from becoming a total loss.

Market participants increasingly view that model as a pragmatic middle ground between fully independent self-custody and complete reliance on a centralized custodian. It does not eliminate responsibility. Users still need to understand recovery procedures, verify devices, protect backups and maintain access to the required signing quorum. However, it can reduce the chance that one compromised wallet, one flawed firmware update or one exposed key leads directly to a complete theft.

Klippsten framed the migration into stronger custody systems as an upgrade rather than a retreat. His argument is that users are learning from the failure and moving toward setups designed to withstand a wider range of attacks. In that sense, the exploit has become a catalyst for a more mature custody conversation, one focused less on slogans and more on specific threat models.

Onchain Status and Containment Efforts

A week after the exploit, nearly 90% of the stolen coins remain unmoved onchain. That fact does not reverse the loss for victims, but it gives investigators and market observers a clearer window into attacker behavior. Confirmed attacker addresses have also been shared with U.S. federal law enforcement, creating a path for continued monitoring and potential action if the coins later move through identifiable infrastructure.

Coinkite, the Toronto-based maker of Coldcard, has patched every affected device line. That patching effort is an important containment step, though it does not erase the damage from the exploit or the urgency for users to review their own setups. Hardware wallet security depends not only on fixes after a vulnerability is discovered, but also on how quickly users apply updates, verify releases and migrate from unsafe configurations.

A volunteer team funded by OpenSats scanned more than 150 open-source repositories and found no evidence that the problem extended beyond Coldcard. That finding may help limit fears of a broader ecosystem-wide flaw, though careful wallet review remains prudent. Open-source security often relies on the ability of independent reviewers to inspect code, but the incident shows that serious issues can still remain hidden for long periods.

What It Means for Bitcoin Holders

For bitcoin holders, the main lesson is not that self-custody has failed. The lesson is that self-custody is a spectrum of risk models. A single hardware wallet stored at home is different from a collaborative multisig vault. A device with outdated firmware is different from one maintained under a disciplined update process. A seed phrase stored in one place is different from a recovery setup designed for both security and survivability.

The Coldcard attack exposed the danger of assuming that one popular tool is enough on its own. Bitcoin’s design allows users to hold assets without permission from a bank, broker or exchange, but that freedom places weight on operational security. As balances grow, the custody model often needs to become more robust. Technical traders and long-term holders alike are likely to pay closer attention to whether their setup can survive a compromised device, a lost backup or an emergency migration.

Klippsten described his conclusion with measured optimism. He acknowledged that it was awful that people lost coins, particularly because many believed they had done what respected voices in the industry had advised. Yet he also argued that Bitcoin is antifragile and that the tools are getting stronger by the hour. In his view, the episode could ultimately become a turning point that strengthens self-custody rather than weakens it.

A Turning Point for Wallet Standards

The exploit is likely to intensify scrutiny of firmware development, wallet entropy, signing processes and user education. Hardware wallet makers may face more pressure to provide clearer upgrade guidance, transparent security reviews and better emergency communication. Service providers may also place greater emphasis on assisted migration, vault design and custody checks that help users identify vulnerabilities before attackers do.

For the bitcoin market, the reputational impact of the event depends on what happens next. If users move toward stronger systems and wallet developers improve review practices, the incident may be remembered as a painful but constructive security reset. If complacency returns, it could become another warning that went unheeded. For now, the immediate direction is clear: many holders are not walking away from self-custody. They are demanding versions of it that are harder to break.

Frequently Asked Questions (FAQs)

What happened in the Coldcard exploit?

Attackers exploited a five-year-old firmware flaw affecting Coldcard hardware wallets and drained bitcoin from vulnerable addresses in three waves of attack.

How much bitcoin was stolen?

Almost 1,600 BTC valued at over $100 million was swept from around 7,300 addresses, according to Galaxy Research.

What caused the Coldcard vulnerability?

The weakness was tied to a defect in a March 2021 firmware update for the Coinkite-made wallet, which left affected users with private keys that were less secure than they should have been.

Did the exploit affect wallets beyond Coldcard?

A volunteer team funded by OpenSats scanned more than 150 open-source repositories and found no evidence that the problem extended beyond Coldcard.

Has Coinkite fixed the issue?

Toronto-based Coinkite has patched every affected device line, though users still need to review their own custody setups and follow appropriate safety steps.

Are bitcoin holders abandoning self-custody?

Klippsten said clients are not retreating from self-custody. Instead, many are looking at stronger models such as collaborative multisig vaults that reduce single-device risk.

Why is collaborative multisig considered safer by some users?

Collaborative multisig can require more than one key or device to move funds, which means a single compromised device does not automatically put all funds at risk.

What did Swan do after the attack?

Swan paused withdrawals for at-risk clients, sent in-app warnings and expanded migration support beyond its user base to help affected holders move coins to safety.

Have the stolen coins moved onchain?

A week after the attack, nearly 90% of the stolen coins remain unmoved onchain, and confirmed attacker addresses have been shared with U.S. federal law enforcement.

Photo by https://kaboompics.com/ on Pexels