Coldcard hack sparks a self-custody security overhaul: Cory Klippsten
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk
AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
The Coldcard hardware wallet hack exposed a firmware vulnerability that allowed attackers to drain about 1,600 BTC worth over $100 million from roughly 7,300 addresses. Cory Klippsten, CEO of Swan Bitcoin, mobilized his team to assist both Swan clients and non-clients in securing their coins during the incident. Despite the security breach, many bitcoin holders are moving toward more secure self-custody solutions, such as multisignature vaults that reduce single-device risk.
Why it matters
The incident triggered a significant reevaluation of self-custody security among bitcoin holders and raised industry questions about whether self-custody remains a safe option. Instead of abandoning self-custody, users are adopting more secure methods, which could lead to stronger custody tools and practices in the bitcoin ecosystem. The event highlights the vulnerability of hardware wallets and the importance of ongoing security vigilance.
Key context
The Coldcard wallet firmware flaw originated from an update in March 2021 and remained undetected for five years before being exploited. The attackers conducted three waves of attacks over a weekend, quickly draining substantial bitcoin holdings. Swan Bitcoin responded by pausing withdrawals for affected clients and expanding support for anyone needing help migrating funds. The vendor, Coinkite, has since patched all affected devices. An independent review found no evidence the exploit impacted wallets other than Coldcard. Although the hack caused losses, over 90% of stolen coins remain unmoved onchain, and authorities are involved.
Key numbers and entities
The main entities involved are Coldcard hardware wallets, Coinkite (the device's manufacturer), Swan Bitcoin and its CEO Cory Klippsten, Galaxy Research providing data on theft volumes, and OpenSats funding a code review. The attackers compromised around 7,300 addresses and stole about 1,600 BTC valued at over $100 million. Nearly 90% of the stolen bitcoin has not been moved since the theft.
What remains unclear
The source does not flag any unresolved questions or uncertainties about the extent of the hack or whether additional vulnerabilities exist beyond Coldcard wallets. It notes the problem was limited to Coldcard based on current investigations.