Summary
- Swan CEO Cory Klippsten said the Coldcard attack prompted bitcoin holders to reexamine their custody decisions.
- He said he mobilized his team to help affected holders move their coins to safety, including people who were not Swan clients.
- Rather than abandoning self-custody, affected users are migrating toward vaults that prevent any single compromised device from putting funds at risk.
Cory Klippsten was at a wedding in Paris when the messages started coming in.
“It was a brutal weekend for so many who lost bitcoin,” the CEO of Swan said in an interview. “I was sending messages at 4 a.m. to help someone on Pacific Time get their coins to safety.”
That was last Thursday, when attackers began draining bitcoin from thousands of Coldcard hardware wallets, exploiting a firmware flaw that had sat undetected for five years.
A defect in a March 2021 firmware update for the Coinkite-made wallet left users with private keys that were less secure than they should have been. By the time three waves of attack had rolled through, almost 1,600 BTC valued at over $100 million had been swept from around 7,300 addresses, according to Galaxy Research.
Swan, a U.S.-based platform that helps individuals buy, hold and self-custody bitcoin, paused withdrawals for at-risk clients, shipped in-app warnings and opened its migration support well beyond its user base.
“Our team dropped everything to start calling clients, and then we opened it up to anyone who needed help, whether they had ever been a Swan client or not,” Klippsten said.

