All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Coldcard hack prompts self-custody security upgrades, says Swan CEO

Created at 5 Aug · 10:06 AM1 source↑ Market-relevant
IN SHORT

Following a significant exploit of Coldcard hardware wallets, Swan Bitcoin CEO Cory Klippsten stated that users are not abandoning self-custody but are instead migrating to more secure, collaborative multisig solutions to protect their bitcoin.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

1,600 BTCstolen bitcoin amount
$100 millionvalue of stolen bitcoin
7,300affected addresses
March 2021firmware update release date
five yearsundetected flaw duration
90%stolen coins remaining unmoved

Who's Involved

Cory Klippsten
CEO of Swan Bitcoin, commenting on the Coldcard hack
Swan Bitcoin
Platform that paused withdrawals and offered migration support
Coinkite
Maker of Coldcard hardware wallets, which has patched affected devices
Galaxy Research
Provided data on stolen bitcoin amounts
OpenSats
Funded a volunteer team to scan open-source repositories
Coldcard hack prompts self-custody security upgrades, says Swan CEO

↳ Why This Matters

The Coldcard hack highlights the ongoing security challenges in cryptocurrency self-custody, prompting users to re-evaluate and upgrade their security measures, potentially driving adoption of more robust solutions like multisig vaults.

Key facts

  • Thousands of Coldcard hardware wallets were drained of bitcoin due to a firmware flaw.
  • Approximately 1,600 BTC, worth over $100 million, was stolen.
  • Swan Bitcoin CEO Cory Klippsten stated users are upgrading self-custody, not abandoning it.
  • Affected users are migrating to collaborative multisig solutions like Swan Vault.
  • Coinkite has patched all affected devices.

Thousands of Coldcard hardware wallets were compromised in a series of attacks that began on July 31, 2026, leading to the theft of approximately 1,600 BTC, valued at over $100 million. The exploit targeted a firmware flaw present since a March 2021 update, which had remained undetected for five years. Attackers swept funds from around 7,300 addresses across three waves of attacks.

Swan Bitcoin CEO Cory Klippsten described the event as a "brutal weekend" for many bitcoin holders. In response, Swan paused withdrawals for at-risk clients, issued in-app warnings, and extended migration support beyond its own customer base, assisting anyone needing help to secure their funds. Klippsten noted that his team worked through the night to help affected individuals.

Toronto-based Coinkite, the maker of Coldcard, has since patched all affected device lines. A volunteer team funded by OpenSats scanned over 150 open-source repositories and found no evidence that the vulnerability extended beyond Coldcard wallets. While nearly 90% of the stolen coins remain unmoved on-chain, confirmed attacker addresses have been shared with U.S. federal law enforcement.

The exploit has prompted some in the industry to question the viability of self-custody, with suggestions that investors consider alternatives like exchange-traded funds. However, Klippsten asserted that users are not abandoning self-custody but are instead seeking to enhance it. Many are migrating to collaborative multisig products, such as Swan Vault, where no single compromised device can put funds at risk.

Klippsten expressed measured optimism about the incident's long-term impact, suggesting that while it was devastating for those who lost coins, Bitcoin's antifragile nature and improving tools could ultimately strengthen the practice of self-custody.

Frequently asked questions

The Coldcard hack involved attackers draining bitcoin from thousands of Coldcard hardware wallets by exploiting a firmware flaw present since a March 2021 update.

Approximately 1,600 BTC, valued at over $100 million, was stolen from around 7,300 addresses.

Swan Bitcoin paused withdrawals for at-risk clients, provided warnings, and offered migration support to help affected users move their funds to safety.

According to Swan CEO Cory Klippsten, users are not abandoning self-custody but are instead upgrading to more secure solutions like multisig vaults.

What Happens Next

01U.S. federal law enforcement is investigating confirmed attacker addresses.
02Users continue to migrate to enhanced self-custody solutions.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Attackers began draining bitcoin from thousands of Coldcard hardware wallets on July 31, 2026.
A firmware flaw in a March 2021 update for Coinkite-made Coldcard wallets was exploited.
Nearly 1,600 BTC, valued at over $100 million, was stolen from approximately 7,300 addresses.
Swan Bitcoin paused withdrawals for at-risk clients and provided in-app warnings.
Swan offered migration support to affected users, including non-clients.
Coinkite patched all affected device lines, and no evidence of the flaw extending beyond Coldcard was found.
Some industry figures suggested abandoning self-custody for alternatives like ETFs.
Klippsten reported that affected users are upgrading their self-custody methods, moving to solutions like Swan Vault.

Sources

T1
Coldcard hack sparks a self-custody security overhaul: Cory KlippstenCoinDesk

Related Stories

At least 15 attackers exploited Coldcard vulnerability, Galaxy Digital says
4 Aug · 2:46 PM
Ledger: Coldcard Exploit Highlights Need for AI-Resistant Bitcoin Wallet Security
4 Aug · 9:21 PM
Coldcard hacker's wallet flooded with pleas and laundering offers via Bitcoin messages
5 Aug · 5:21 AM
BitGo to switch WBTC cross-chain provider from LayerZero to Chainlink
4 Aug · 1:06 PM
Strategy Wallet Moves 1,030 BTC Following $105M Bitcoin Sale
5 Aug · 10:51 AM