Crypto
Home›Crypto›Market Structure›Coldcard hack drives shift toward collaborative multis…
Coldcard hack drives shift toward collaborative multisig vaults
After attackers exploited a five year firmware flaw, about 1,600 BTC was drained before most stolen coins remained unmoved on chain a week later.
CoinDesk reports that a Coldcard hardware wallet attack exploited a firmware flaw that had gone undetected for five years, leading to theft from thousands of wallets. The defect, introduced in a March 2021 update for Coinkite made devices, left some private keys less secure than intended, according to the report.
By the time three waves of attacks had run, attackers had swept almost 1,600 BTC, valued at over $100 million, across roughly 7,300 addresses, according to Galaxy Research, the outlet said. A week after the incident, nearly 90% of the stolen coins were still unmoved on chain, and confirmed attacker addresses were shared with U.S. federal law enforcement and Toronto based Coinkite, which has patched every affected device line.
Swan CEO Cory Klippsten told CoinDesk that the hack prompted bitcoin holders to reexamine custody decisions, with the industry moving toward vault style protections designed to reduce the risk from any single compromised device. Klippsten said Swan paused withdrawals for at risk clients, sent in app warnings, and opened migration support beyond Swan customers.
The outlet added that Swan mobilized a team to help affected users move their coins to safety, and that a volunteer group funded by OpenSats scanned more than 150 open source repositories without finding evidence the issue spread beyond Coldcard. Klippsten said clients are not retreating from self custody, instead looking at harder to access setups such as Swan Vault.
Latest closeBitcoin $64,170.04 ▲0.2%