The attack exposed a five-year-old firmware flaw and swept more than 1,600 bitcoin from thousands of addresses, but custody operators say the response is an upgrade rather than an exit.
A Coldcard hardware-wallet exploit has turned a device-level flaw into a broader debate about how bitcoin holders should organize custody. The attack used a vulnerability introduced in a firmware update released in March 2021 and swept about 1,600 bitcoin, worth more than $100 million at the time, from roughly 7,300 addresses, according to Galaxy Research.
Swan paused withdrawals for clients considered at risk, issued warnings and helped noncustomers migrate funds. Coinkite patched the affected device lines. Nearly 90% of the stolen coins remained unmoved a week after the theft, while the attacker addresses were shared with U.S. federal law enforcement.
The response is operational first
The immediate challenge was identifying which wallets might have been exposed and moving funds without creating a second failure. Users had to distinguish between devices that carried the vulnerable firmware, addresses that had actually been used and funds that could be transferred safely under time pressure.
OpenSats volunteers scanned nearly 90 open-source repositories for similar issues and found no evidence of another affected project in the review described by CoinDesk. That result narrows the incident, but it does not remove the need for users to audit their own firmware and signing procedures.
Why multisig is the next step
Cory Klippsten, chief executive of Swan, said users were moving toward collaborative multisignature custody rather than abandoning self-custody. Multisig spreads signing authority across devices or people, so one compromised firmware path is less likely to control the full balance.
That design adds recovery and coordination work. Keys must be stored in different locations, signing policies need to be documented and an emergency process must be tested before it is needed. The exploit has therefore made self-custody a governance problem as much as a hardware choice: the safest setup is the one whose controls are understood, separated and rehearsed.