Coldcard Hack Exposes 5-Year Firmware Flaw, $100M Stolen in Bitcoin Theft

iconCoinDesk
Share
AI summary iconSummary
A crypto hack targeting Coldcard hardware wallets exposed a 5-year-old firmware flaw, leading to the theft of nearly 1,600 BTC (over $100 million) from 7,300 addresses. The vulnerability, introduced in a 2021 update, was exploited recently. Swan helped impacted users and opened migration support. Around 90% of the stolen coins remain untouched. Coinkite has patched all affected devices. The exchange hack highlights ongoing risks in self-custody platforms.

Cory Klippsten was at a wedding in Paris when the messages started coming in.

"It was a brutal weekend for so many who lost bitcoin," the CEO of Swan said in an interview. "I was sending messages at 4 a.m. to help someone on Pacific Time get their coins to safety."

That was last Thursday, when attackers began draining bitcoin from thousands of Coldcard hardware wallets, exploiting a firmware flaw that had sat undetected for five years.

A defect in a March 2021 firmware update for the Coinkite-made wallet left users with private keys that were less secure than they should have been. By the time three waves of attack had rolled through, almost 1,600 BTC valued at over $100 million had been swept from around 7,300 addresses, according to Galaxy Research.

Swan, a U.S.-based platform that helps individuals buy, hold and self-custody bitcoin, paused withdrawals for at-risk clients, shipped in-app warnings and opened its migration support well beyond its user base.

"Our team dropped everything to start calling clients, and then we opened it up to anyone who needed help, whether they had ever been a Swan client or not," Klippsten said.

A week on, nearly 90% of the stolen coins remain unmoved onchain, confirmed attacker addresses have been shared with U.S. federal law enforcement and Toronto-based Coinkite has patched every affected device line. A volunteer team funded by OpenSats scanned more than 150 open-source repositories and found no evidence the problem extended beyond Coldcard.

The exploit led some in the industry to question the value of self-custody, suggesting investors should consider buying bitcoin through, for example, exchange-traded funds rather than holding it themselves.

Klippsten, however, said clients are not retreating from self-custody. Instead, they’re examining ways of making their bitcoin harder to access.

"People are moving into Swan Vault right now," he said, referring to the firm's collaborative multisig product, where no single device can put a user's funds at risk. "Instead of abandoning self-custody, many are upgrading it."

His verdict on the week is measured optimism.

"It is awful that people lost coins, and they did everything right according to what a lot of well-known people in the industry told them. But Bitcoin is antifragile and the tools are getting stronger by the hour. This might end up being the best thing that ever happened to self-custody."

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.