A breach has targeted Coldcard, a bitcoin-only hardware wallet, resulting in hackers siphoning over $100 million US in bitcoin from the wallets, as per blockchain intelligence firm Galaxy Research. Coldcard, developed by Coinkite in Toronto, acts as a secure storage for users’ keys offline, safeguarding “seed phrases” that are pivotal for authorizing bitcoin transactions.
Coinkite recently alerted users to a software flaw enabling hackers to reconstruct wallet seed phrases, leading to multiple attack waves. Galaxy Research noted the theft of 1,596 bitcoin from around 7,300 addresses, with a potential rise to 2,055 bitcoin worth about $130 million US if a fourth wave is confirmed. The perpetrators behind the breach remain unidentified.
Coinkite CEO advised users to move their funds and issued firmware updates to rectify the affected products. The vulnerability stemmed from the use of a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator. The company ceased shipments of devices with the flawed firmware and destroyed remaining inventory.
All Coldcard users face potential risks from the software bug. Most of the stolen bitcoin remains untouched, residing in the same wallets post-theft. Investigations are ongoing, with details shared with U.S. law enforcement agencies, exchanges, and cyber-investigation groups. The incident underscores the challenge of keeping crypto assets offline, emphasizing the importance of prompt actions to secure compromised wallets.
Affected users are urged to install the latest firmware, with existing vulnerable seed phrases advised for replacement. Coinkite assured ongoing investigations and vowed to release a technical review soon. Experts emphasize the complexity of addressing the workaround and urge affected users to consider transferring their funds to secure addresses or alternative custodial services.
