Coldcard, a bitcoin-only hardware wallet, has recently been targeted in a data breach resulting in over $100 million US worth of bitcoin being drained from the wallets, as reported by Galaxy Research. The breach exposed a software bug allowing hackers to reconstruct wallet “seed phrases” without physical access to the device. This vulnerability led to multiple attack waves resulting in the theft of 1,596 bitcoin from around 7,300 addresses, with a potential total loss of 2,055 bitcoin valued at approximately $130 million US.
Coinkite, the company behind Coldcard, issued a warning to users about the bug and advised them to move their funds immediately. The exploited flaw in the software stemmed from a firmware issue dating back to March 2021, where the generation of wallet seeds was compromised. Coinkite has released firmware updates for affected products and halted shipments of vulnerable devices.
Users are urged to take action if they suspect their wallets may be compromised. Installing the latest firmware update protects newly created wallets, while existing seed phrases from vulnerable devices should be replaced. Galaxy Research emphasized the importance of not generating new seeds on affected models until the update is installed.
The ongoing investigation into the hack has revealed that most of the stolen bitcoin remains untouched in the same wallets, potentially awaiting further transactions by the hackers. Details of the attacks have been shared with law enforcement agencies and cybersecurity groups to track down the perpetrators. Coinkite emphasized the need for users to stay vigilant and consider migrating their funds to safer addresses or exchanges if they are uncertain about the security of their Coldcard wallets.
