Coldcard Hack Exploits 5-Year Firmware Bug, $100M+ in Bitcoin Drained
AI Market Summary
A five-year-undetected Coldcard firmware flaw enabled attackers to steal ~1,600 BTC (>$100M) from thousands of addresses, highlighting residual operational risk in hardware self-custody. Although devices are now patched, law enforcement has been notified, and most stolen coins remain unmoved on-chain, the incident can raise near-term risk premia and shift flows toward multisig solutions or regulated wrappers (e.g., ETFs), potentially weighing on BTC sentiment.
Impact level
● High
Affected assets
BTC/USDT+0.25%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Swan CEO Cory Klippsten said he was attending a wedding in Paris when urgent messages began pouring in from people trying to protect their bitcoin. "It was a brutal weekend for so many who lost bitcoin," he said, describing late-night efforts to help users on Pacific Time move funds to safety.
The incident began last Thursday, when attackers started siphoning bitcoin from thousands of Coldcard hardware wallets by exploiting a firmware weakness that went unnoticed for five years. Galaxy Research said the root cause traces back to a March 2021 firmware update for the Coinkite-made wallet, which left some users with private keys that were less secure than intended.
After three waves of attacks, about 1,600 BTC valued at more than $100 million had been taken from roughly 7,300 addresses, according to Galaxy Research.
Swan, a U.S.-based platform that helps individuals buy, hold and self-custody bitcoin, temporarily paused withdrawals for clients deemed at risk, pushed in-app alerts, and expanded migration support beyond its own customer base. Klippsten said the company began calling clients immediately and then offered help to anyone affected, regardless of whether they had ever used Swan.
A week later, nearly 90% of the stolen bitcoin remains unmoved on-chain. Confirmed attacker addresses have been shared with U.S. federal law enforcement, and Toronto-based Coinkite said it has patched all affected device lines.
A volunteer team funded by OpenSats reviewed more than 150 open-source repositories and reported finding no evidence that the flaw extends beyond Coldcard.
The exploit has reignited debate over self-custody, with some industry voices arguing investors may want exposure through products such as exchange-traded funds rather than holding bitcoin themselves. Klippsten disagreed, saying clients are not backing away from self-custody. Instead, he said they are adopting stronger setups to make funds harder to compromise.
"People are moving into Swan Vault right now," he said, referring to the firm's collaborative multisig product designed so no single device can place a user's funds at risk. "Instead of abandoning self-custody, many are upgrading it."
Klippsten said his takeaway is cautious optimism: the losses are severe, even for people who followed widely recommended best practices, but he argued Bitcoin is "antifragile" and that security tooling is improving rapidly. He added that the episode could ultimately strengthen self-custody over time.