The attack revealed a firmware vulnerability that had remained unnoticed for five years, but the industry’s swift reaction is pushing more users toward collaborative multisignature security solutions.
Cory Klippsten was attending a wedding in Paris when the first alerts began arriving.
“It was a devastating weekend for many people who lost their bitcoin,” the Swan CEO said in an interview. “I was messaging at 4 a.m. to help someone in the Pacific Time zone move their funds to safety.”
The incident unfolded last Thursday when attackers started draining bitcoin from thousands of Coldcard hardware wallets by exploiting a long-standing firmware weakness.
The issue originated from a March 2021 firmware update for the Coinkite-developed wallet, which left some users with private keys that did not have the expected level of security. After three separate attack waves, nearly 1,600 BTC worth more than $100 million had been transferred from approximately 7,300 addresses, according to Galaxy Research.
Swan, a U.S.-based bitcoin platform focused on purchasing, holding, and self-custody services, responded by temporarily halting withdrawals for vulnerable customers, issuing warnings through its app, and extending migration assistance beyond its own users.
“Our team immediately shifted focus to contacting customers, and then we expanded the support effort to anyone who needed assistance, even if they had never used Swan before,” Klippsten said.
One week later, nearly 90% of the stolen bitcoin had still not moved on-chain. Confirmed attacker addresses were provided to U.S. federal authorities, while Toronto-based Coinkite released fixes across all affected device models. A volunteer group supported by OpenSats reviewed more than 150 open-source repositories and found no indication that the vulnerability affected products beyond Coldcard.
The exploit sparked debate across the crypto industry, with some questioning whether self-custody remains worth the risks and suggesting alternatives such as bitcoin exchange-traded funds.
Klippsten disagreed, saying the incident has not pushed users away from self-custody. Instead, he believes many are looking for stronger ways to protect their holdings.
“People are moving into Swan Vault right now,” he said, referring to the company’s collaborative multisig solution, which prevents any single device from having complete control over a user’s funds. “Rather than giving up on self-custody, people are improving how they secure it.”
Despite the severity of the attack, Klippsten expressed cautious optimism about the long-term impact.
“It is terrible that people lost their bitcoin, especially because they followed advice from some of the most respected voices in the industry. But Bitcoin is antifragile, and security tools are improving rapidly. This could ultimately become one of the most important moments for strengthening self-custody.”

More Stories
JPMorgan Warns Hyperliquid ETF Momentum Has Slowed as Rival Products Gain Ground
Sandisk and Western Digital’s 10% Drop Sparks Market Concerns Over Bitcoin’s Next Move
Bitcoin and Ether Gain Ground as Investors Return to Crypto’s Biggest Assets