Coldcard hack sparks a self-custody security overhaul: Cory Klippsten

A firmware vulnerability in Coldcard hardware wallets led to the theft of over $100 million in Bitcoin, prompting a security overhaul in the self-custody sector. Despite the breach, industry leaders report that users are shifting toward more secure multisig solutions rather than abandoning self-custody entirely.
Why it matters
This incident highlights the inherent risks of hardware-based crypto storage and is driving a shift toward more robust, multi-signature security standards for digital asset management.
"It was a brutal weekend for so many who lost bitcoin," the CEO of Swan said in an interview. "I was sending messages at 4 a.m. to help someone on Pacific Time get their coins to safety."
That was last Thursday, when attackers began draining bitcoin from thousands of Coldcard hardware wallets, exploiting a firmware flaw that had sat undetected for five years.
A defect in a March 2021 firmware update for the Coinkite-made wallet left users with private keys that were less secure than they should have been. By the time three waves of attack had rolled through, almost 1,600 BTC valued at over $100 million had been swept from around 7,300 addresses , according to Galaxy Research.
Swan, a U.S.-based platform that helps individuals buy, hold and self-custody bitcoin, paused withdrawals for at-risk clients, shipped in-app warnings and opened its migration support well beyond its user base.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in