Advertisement

Bitcoin Wallet Hack Forces Security Rethink as Cory Klippsten Urges Stronger Self-Custody

The Coldcard attack exposed a firmware vulnerability that had remained hidden for years, but the industry’s quick response is accelerating the shift toward stronger collaborative multisignature security models.

Cory Klippsten was attending a wedding in Paris when reports of the attack began reaching him.

“It was a painful weekend for many people who lost bitcoin,” the Swan CEO said in an interview. “I was up at 4 a.m. sending messages to help someone on Pacific Time move their funds to safety.”

The incident began last Thursday when attackers exploited a flaw in Coldcard hardware wallets, draining bitcoin from thousands of affected devices.

The vulnerability was linked to a March 2021 firmware update from Coinkite, the company behind Coldcard. The update introduced a weakness that reduced the security of private keys generated by affected wallets. After multiple attack waves, attackers had moved nearly 1,600 BTC, worth more than $100 million, from roughly 7,300 addresses, according to Galaxy Research.

Swan, a U.S.-based bitcoin services company focused on buying, holding, and self-custody solutions, responded by suspending withdrawals for potentially affected customers, sending security alerts through its platform, and providing migration support to the wider bitcoin community.

“Our team immediately put everything else aside to reach out to customers, and then we expanded our efforts to support anyone who needed help, regardless of whether they were Swan users,” Klippsten said.

A week after the attack, around 90% of the stolen bitcoin remained untouched on-chain. Wallet addresses linked to the attackers were shared with U.S. federal investigators, while Coinkite released updates to address the issue across impacted device models. A volunteer group supported by OpenSats analyzed more than 150 open-source projects and found no evidence that the vulnerability affected wallets outside the Coldcard ecosystem.

The incident also reignited discussions about the risks of self-custody, with some industry observers suggesting that investors may prefer alternatives such as bitcoin exchange-traded funds instead of managing their own private keys.

Klippsten, however, said the response from users has been the opposite. Rather than abandoning self-custody, many bitcoin holders are looking for more advanced security methods.

“People are moving into Swan Vault now,” he said, referring to the company’s collaborative multisignature custody service, where a single device failure cannot compromise a user’s entire bitcoin balance. “Instead of walking away from self-custody, users are upgrading their security approach.”

Klippsten described the aftermath of the attack with cautious confidence.

“It is heartbreaking that people lost coins, especially because many followed guidance from respected figures in the industry and believed they were doing everything correctly. But Bitcoin is antifragile, and the security ecosystem is improving faster than ever. This could eventually become a major milestone for the future of self-custody.”