A Coldcard hardware wallet exploit has triggered a broader reassessment of bitcoin self-custody practices after attackers drained nearly 1,600 BTC from roughly 7,300 addresses, according to Galaxy Research figures cited by CoinDesk. The attack targeted a firmware flaw in Coinkite’s Coldcard wallets that had reportedly gone unnoticed for five years.
The incident matters because Coldcard is used by bitcoin holders who choose to control their own keys rather than rely on exchanges or funds. A compromise affecting hardware-wallet security can shake confidence in self-custody, but Swan Bitcoin CEO Cory Klippsten told CoinDesk that many affected users are looking for stronger custody setups instead of giving up on holding bitcoin directly.
Swan, which helps users buy, hold and self-custody bitcoin, paused withdrawals for clients considered at risk, sent in-app warnings and opened migration support beyond its own customer base. Klippsten said the company moved quickly to contact clients and assist anyone who needed help moving funds.
One week after the attack, CoinDesk reported that close to 90% of the stolen coins had not moved onchain. Confirmed attacker addresses were shared with U.S. federal law enforcement, while Coinkite patched all affected device lines. A volunteer team funded by OpenSats also reviewed more than 150 open-source repositories and found no evidence that the issue extended beyond Coldcard.
Klippsten said the response is accelerating interest in collaborative multisig vaults, where one compromised device is not enough to move funds. The episode has become a high-profile test for the self-custody sector: painful for users who lost coins, but also a catalyst for more layered security practices across bitcoin storage.