Coldcard Hack Puts Bitcoin Self-Custody Under Pressure
A 2021 firmware bug affected thousands of Coldcard wallets and led to the theft of nearly 1,600 BTC. The case is putting hardware wallets and multisig back in the spotlight as self-custody tools.

Key Takeaways
- A 2021 firmware bug in Coldcard hardware wallets triggered a major Bitcoin self-custody security incident.
- Attackers drained nearly 1,600 BTC, worth more than $100 million, from about 7,300 addresses.
- The response has centered on patches, law enforcement reports, and more attention on layered security such as multisig.
A five-year-old firmware bug in Coldcard hardware wallets has turned into one of the largest recent security incidents in Bitcoin self-custody. Attackers began emptying thousands of wallets last Thursday, and Galaxy Research says nearly 1,600 BTC, worth more than $100 million (€86.6 million), was stolen from roughly 7,300 addresses.
How the Attack Worked
The flaw came from a March 2021 firmware update for Coinkite's Bitcoin-only wallet. In practice, that meant private keys were not protected as securely as users would have assumed. The theft unfolded in three waves and largely affected people who believed their coins were safely under their own control.
Swan Bitcoin, a U.S. platform for buying, storing, and self-managing Bitcoin, moved quickly to add extra protections. The company paused withdrawals for customers at risk, pushed in-app alerts, and widened its migration support beyond its own user base. CEO Cory Klippsten said the team dropped everything to call customers and later extended help to anyone who needed it.
Industry Response
A week later, nearly 90 percent of the stolen coins are still unmoved onchain. The attacker’s confirmed addresses have been passed to U.S. federal law enforcement, while Coinkite has patched every affected device line. A volunteer group funded by OpenSats also reviewed more than 150 open-source repositories and found no evidence that the problem extended beyond Coldcard.
Coldcard has long been marketed as a Bitcoin-only hardware wallet with security-focused features, including air-gapped transactions via microSD and a transparent case designed to make tampering easier to spot. That makes the impact of this exploit even more notable, since it hits a product category built around the idea of local security and trust.
Why This Matters
The hack has brought the self-custody debate back into focus, but Klippsten says users are not backing away in large numbers. Instead, more of them are looking for ways to reduce single points of failure, including collaborative multisig. For European crypto users, that is a reminder that real-world security is increasingly about layers, not just a hardware wallet.
Some of the market had already started reacting with extra caution after the exploit became public, as older wallets began moving in large numbers, including an older Bitcoin wallet that moved $31 million.