Coldcard Exploit Pushes Bitcoin Custody Users Toward Multisig Safeguards

A Coldcard hardware wallet exploit tied to an old firmware flaw led to nearly 1,600 BTC being drained from about 7,300 addresses. Swan Bitcoin CEO Cory Klippsten said the episode is pushing users toward collaborative multisig vaults rather than away from self-custody.

Coldcard Exploit Pushes Bitcoin Custody Users Toward Multisig Safeguards

What happened?

A Coldcard hardware wallet exploit tied to an old firmware flaw led to nearly 1,600 BTC being drained from about 7,300 addresses. Swan Bitcoin CEO Cory Klippsten said the episode is pushing users toward collaborative multisig vaults rather than away from self-custody.

Why it matters

Swan, which helps users buy, hold and self-custody bitcoin, paused withdrawals for clients considered at risk, sent in-app warnings and opened migration support beyond its own customer base. Klippsten said the company moved quickly to contact clients and assist anyone who needed help moving funds.

A Coldcard hardware wallet exploit has triggered a broader reassessment of bitcoin self-custody practices after attackers drained nearly 1,600 BTC from roughly 7,300 addresses, according to Galaxy Research figures cited by CoinDesk. The attack targeted a firmware flaw in Coinkite’s Coldcard wallets that had reportedly gone unnoticed for five years.

The incident matters because Coldcard is used by bitcoin holders who choose to control their own keys rather than rely on exchanges or funds. A compromise affecting hardware-wallet security can shake confidence in self-custody, but Swan Bitcoin CEO Cory Klippsten told CoinDesk that many affected users are looking for stronger custody setups instead of giving up on holding bitcoin directly.

Swan, which helps users buy, hold and self-custody bitcoin, paused withdrawals for clients considered at risk, sent in-app warnings and opened migration support beyond its own customer base. Klippsten said the company moved quickly to contact clients and assist anyone who needed help moving funds.

One week after the attack, CoinDesk reported that close to 90% of the stolen coins had not moved onchain. Confirmed attacker addresses were shared with U.S. federal law enforcement, while Coinkite patched all affected device lines. A volunteer team funded by OpenSats also reviewed more than 150 open-source repositories and found no evidence that the issue extended beyond Coldcard.

Klippsten said the response is accelerating interest in collaborative multisig vaults, where one compromised device is not enough to move funds. The episode has become a high-profile test for the self-custody sector: painful for users who lost coins, but also a catalyst for more layered security practices across bitcoin storage.

Source: CoinDesk

Keep exploring

Related stories

Boltz Suspends Bitcoin Swaps as AI Speeds Up Bug Discovery

Boltz Suspends Bitcoin Swaps as AI Speeds Up Bug Discovery

Non-custodial Bitcoin swap provider Boltz has suspended swaps indefinitely after saying attackers are finding vulnerabilities faster than its team can fix them. The shutdown highlights a security pressure point for crypto infrastructure as AI accelerates vulnerability discovery.

Read
Ethereum Researchers Propose Cutting Staking Rewards as Participation Nears 50%

Ethereum Researchers Propose Cutting Staking Rewards as Participation Nears 50%

Ethereum researchers have published EIP-8363, a draft proposal aimed at reducing net consensus-layer rewards as the network’s staking ratio moves toward 50%. Critics cited in the source say the approach could backfire.

Read
Bybit’s EU Payments Arm Secures Austrian E-Money License

Bybit’s EU Payments Arm Secures Austrian E-Money License

Bybit’s Austrian payments subsidiary has received regulatory approval to develop electronic money services in Europe. The license supports planned card, merchant, open-banking and person-to-person payment products.

Read