Coldcard Hack Drains $100M BTC, Spurring Multisig Shift
Key Takeaways
Cory Klippsten addresses the Coldcard firmware exploit that drained $100M in Bitcoin. Despite the breach, Swan reports users are upgrading to multisig solutions rather than abandoning self-custody, signaling a maturation of security practices.
Woofun AI reports that a critical firmware flaw in Coldcard hardware wallets triggered a massive security incident, prompting CEO Cory Klippsten to coordinate emergency response efforts from a Paris wedding. The vulnerability, originating in a March 2021 update by Coinkite, compromised private key security for thousands of users, leading to immediate operational disruptions across the self-custody ecosystem.
The technical breach unfolded over three distinct attack waves, exploiting a defect that had remained undetected for five years within the Coinkite-made device infrastructure. Galaxy Research data indicates that approximately 1,600 BTC, valued at over $100 million, was systematically swept from around 7,300 addresses. This rapid extraction highlighted the severe consequences of the underlying firmware weakness, which had left user private keys significantly less secure than intended.
Swan, a U.S.-based platform facilitating bitcoin acquisition and self-custody, implemented immediate crisis management protocols to mitigate client exposure. The firm paused withdrawals for at-risk accounts and deployed in-app warnings, while expanding migration support beyond its existing user base. Klippsten noted that teams began contacting clients at 4 a.m. Pacific Time, ensuring that assistance was available to anyone needing to secure their assets, regardless of their relationship with Swan.
Woofun AI data shows that nearly 90% of the stolen coins remain unmoved onchain, with confirmed attacker addresses shared with U.S. federal law enforcement. Toronto-based Coinkite has since patched every affected device line, while a volunteer team funded by OpenSats scanned more than 150 open-source repositories to confirm the issue was isolated to Coldcard. Despite these containment efforts, the exploit sparked industry debate, with some suggesting investors should pivot to exchange-traded funds rather than maintaining direct custody.
Contrary to calls for abandoning self-custody, Klippsten observes that clients are actively upgrading their security posture through Swan Vault, a collaborative multisig product.
This shift ensures that no single device can compromise user funds, reinforcing the antifragile nature of Bitcoin infrastructure. The incident may ultimately serve as a catalyst for stronger security tools, marking a pivotal evolution in self-custody practices.
Comments
No comments yet.