[123rf]
[123rf]

Cold wallets — offline storage devices kept separate from the internet — have long been considered the most secure way to hold virtual assets. That reputation took a hit late last month when a large-scale hack struck Coldcard, a hardware wallet designed exclusively for bitcoin. According to Bloomberg on Sunday, roughly 5,000 Coldcard devices were compromised, with 1,755 bitcoin — worth about 157 billion won ($111 million) — drained from them.

The hardware itself was not at fault. A standard bitcoin wallet generates a recovery phrase, typically a random sequence of 12 to 24 words, that serves as the master key to the wallet. The breach traced back to that key. A flaw was found in firmware distributed in March 2021 for older Coldcard models: the bug undermined the randomness of the recovery phrase, allowing hackers to reconstruct it and seize the bitcoin. Within roughly three days of the incident coming to light, Coldcard users had moved their coins to exchanges.

Corporations rarely rely on consumer-grade hardware wallets like Coldcard. But what this incident exposed was not a flaw unique to one device — it was a systemic vulnerability in how cryptographic keys are generated and protected. According to cybersecurity firm Blockaid, the majority of virtual asset losses in the first half of this year stemmed from key leaks or poor key management. Multi-signature wallets and custody services that corporations typically use distribute key generation across multiple parties, but they are not immune: the generation process itself can harbor flaws.

The difference between individual and corporate holders becomes stark after an incident occurs. Under accounting supervision guidelines for virtual assets, companies that hold such assets must maintain an internal control framework covering the entire lifecycle from acquisition to disposal, and that framework is subject to external audit. Switching custody providers is therefore not a simple asset transfer — it requires revisiting internal control procedures and updating disclosures in financial statement footnotes.

A more fundamental problem is the shortage of qualified custodians. South Korea's Act on Reporting and Using Specified Financial Transaction Information does not regulate custody as a standalone business category. Because the law licenses trading, exchange and storage as separate activities, any operator — exchange or cold-wallet provider alike — may offer custody as a sideline. That is the backdrop for a proposal raised at an academic conference held at the National Assembly on July 23, which called for mandating that corporations and institutional investors use independent custodians and for separating trading and storage functions.

In this environment, the first thing a company should verify is governance: whether its custodian also handles trading, and if so, whether customer assets are genuinely segregated from the custodian's own assets at the ledger and wallet level. The next area to examine is security architecture — specifically, whether cryptographic keys are distributed across multiple parties so that no single actor can move assets unilaterally. As the Coldcard case shows, flaws in the key-generation stage can surface long after the fact, so companies should also confirm whether that process has undergone independent verification and whether the results are publicly available. Finally, companies need to assess incident-response readiness: whether the custodian carries insurance, whether coverage limits are adequate relative to assets held, and whether liability — its scope and the responsible party — is spelled out in the contract. The time required to transfer assets to a new custodian is another detail worth establishing in advance.

South Korea will soon open the virtual asset market to corporate participants. When that happens, listed companies holding digital assets will face questions that go well beyond the size of their holdings. They will be asked where those assets are stored, how they are stored, and how their safety can be demonstrated. The answers to those questions need to be ready before the moment of decision — not at it.


kyoung@heraldcorp.com