The Coldcard exploit revealed a firmware weakness that had gone unnoticed for nearly five years, but the industry’s response is now accelerating the move toward more secure collaborative multisignature custody solutions.
Cory Klippsten was attending a wedding in Paris when the first reports of the attack started appearing.
“It was an incredibly difficult weekend for many people who lost bitcoin,” said the Swan CEO in an interview. “I was sending messages at 4 a.m. to help someone located in the Pacific Time zone secure their funds.”
The attack began last Thursday, when hackers exploited a vulnerability in Coldcard hardware wallets and started moving bitcoin from thousands of affected addresses.
The flaw originated from a March 2021 firmware update released for Coinkite’s Coldcard wallet. The issue weakened the security of private keys generated by impacted devices. Following three separate attack waves, nearly 1,600 BTC worth more than $100 million had been stolen from around 7,300 addresses, according to Galaxy Research.
Swan, a U.S.-based bitcoin platform offering buying, holding, and self-custody services, quickly took action by pausing withdrawals for users considered at risk, sending security alerts through its application, and launching a migration assistance program for the broader bitcoin community.
“Our team immediately shifted all attention toward contacting clients, and we later opened the support effort to anyone who needed assistance, even if they were not Swan customers,” Klippsten said.
Seven days after the incident, almost 90% of the stolen bitcoin had not moved from the attackers’ addresses. The identified wallet addresses were shared with U.S. law enforcement agencies, while Coinkite released fixes for all affected Coldcard models. A volunteer group backed by OpenSats also reviewed more than 150 open-source repositories and found no evidence that the vulnerability extended beyond Coldcard devices.
The exploit sparked renewed debate around the risks of holding bitcoin independently, with some critics arguing that investors should consider regulated products such as exchange-traded funds instead of managing private keys themselves.
Klippsten, however, said the event has not pushed users away from self-custody. Instead, many bitcoin holders are exploring stronger protection methods.
“Users are moving into Swan Vault right now,” he said, pointing to the company’s collaborative multisignature solution, which removes reliance on a single device by requiring multiple approvals to access funds. “Rather than abandoning self-custody, people are making it more resilient.”
Looking back at the incident, Klippsten said the outcome could ultimately strengthen the self-custody ecosystem despite the losses.
“It is devastating that people lost bitcoin, especially when they followed recommendations from trusted voices and believed they were taking the right precautions. But Bitcoin is antifragile, and the security tools around it are improving every day. This could become a defining moment that makes self-custody stronger than ever.”





