Cory Klippsten Warns Coldcard Incident Could Reshape the Future of Self-Custody Security
The Coldcard exploit revealed a five-year-old firmware flaw, but the industry’s response is accelerating the shift toward more advanced self-custody solutions, particularly collaborative multisignature security.
Cory Klippsten, CEO of Swan, was attending a wedding in Paris when the first reports of the attack began arriving.
“It was a brutal weekend for many bitcoin holders who lost their funds,” Klippsten said in an interview. “I was sending messages at 4 a.m. to help someone on Pacific Time move their bitcoin to a safer location.”
The attack unfolded last Thursday, as hackers exploited a previously unknown weakness in Coldcard hardware wallets and began draining bitcoin from thousands of addresses.
The issue was linked to a March 2021 firmware update released by Coinkite, the company behind Coldcard. The flaw affected the security of private keys generated by certain devices, leaving users more vulnerable than expected. Following three attack waves, approximately 1,600 BTC valued at more than $100 million were removed from roughly 7,300 addresses, according to Galaxy Research.
Swan, a U.S.-based bitcoin platform that helps users buy, store, and self-custody bitcoin, quickly responded by suspending withdrawals for potentially affected customers, issuing warnings through its application, and offering migration assistance to anyone who needed support.
“Our team immediately focused on reaching out to clients, and then we expanded our efforts to help anyone affected, even people who had never been Swan customers,” Klippsten said.
One week after the breach, nearly 90% of the stolen bitcoin had not been transferred from the attackers’ wallets. The confirmed attacker addresses were provided to U.S. federal law enforcement, while Coinkite released patches for all affected device categories. A volunteer group funded by OpenSats also reviewed more than 150 open-source repositories and found no evidence that the vulnerability spread beyond Coldcard.
The incident reignited debate over the challenges of self-custody, with some critics arguing that investors should consider bitcoin exchange-traded funds or other managed products instead of controlling private keys themselves.
Klippsten said the attack has not caused users to abandon self-custody. Instead, he believes many are looking for stronger security methods that reduce individual points of failure.
“People are moving into Swan Vault right now,” he said, referring to the company’s collaborative multisignature product, which requires multiple approvals and prevents one compromised device from putting funds at risk. “Rather than giving up on self-custody, users are improving it.”
Despite the severity of the incident, Klippsten remains optimistic about the long-term impact on bitcoin security.
“It is awful that people lost bitcoin, especially when they followed recommendations from some of the most trusted voices in the industry. But Bitcoin is antifragile, and the security ecosystem is becoming stronger every day. This could ultimately become a major turning point for self-custody.”
Share this content:













