HomeCommerceColdcard Bitcoin Wallet Breach: $100M Stolen

Coldcard Bitcoin Wallet Breach: $100M Stolen

Published on

Coldcard, a bitcoin-only hardware wallet, has become the recent victim of a data breach, with hackers reportedly siphoning over $100 million US worth of bitcoin from Coldcard hard wallets, as per blockchain intelligence firm Galaxy Research. Coldcard, developed by Coinkite, a Toronto-based company, is a hardware wallet that does not store bitcoin but enhances security by keeping “seed phrases” offline within the physical device, away from internet connection. These seed phrases serve as a master key to the bitcoin-only wallet, enabling users to authorize transactions securely.

Coinkite issued a warning to users about a software bug that allowed hackers to reconstruct wallet seed phrases, leading to multiple attacks where hackers gained access to users’ bitcoin wallets without physical access to the device. Galaxy Research reported three confirmed attack waves and additional smaller incidents resulting in the theft of 1,596 bitcoin from approximately 7,300 addresses. If a fourth wave is confirmed, the total loss could amount to around 2,055 bitcoin, valued at $130 million US. The perpetrators behind the attacks remain unidentified.

Coinkite’s Co-founder and CEO, Rodolfo Novak, advised users to transfer their funds immediately and released firmware updates for affected products. The company acknowledged that the vulnerability originated in March 2021 due to a flaw in the software that compromised the generation of wallet seeds. Novak cautioned other developers about the risks posed by AI in identifying latent bugs in firmware.

All Coldcard users are potentially at risk of wallet compromise due to the software bug. Roughly 90% of the stolen bitcoin remains stagnant in the wallets where they were sent after the theft, indicating they have not been further transferred or exchanged. The ongoing investigation details have been shared with U.S. law enforcement agencies, cryptocurrency exchanges, and cyber-investigation groups to track down attackers.

To safeguard against compromised wallets, users are advised to update to Coldcard’s latest firmware, particularly for wallets created post-fix. Existing seed phrases generated on vulnerable devices are recommended for replacement. Coinkite emphasized ongoing investigations and the need for a formal technical review. Affected users can transfer funds to other secure addresses or custodians while retaining their Coldcard devices for potential fund recovery efforts with law enforcement cooperation.

Latest articles

“Hamster’s Strava Stardom: Mollie’s Nightly Runs Go Viral”

Physicist and hamster owner Thijs de Buck recently shared in an interview that his...

Human Rights Groups Sue Trump Admin Over ICC Sanctions

Four U.S.-based human rights organizations have taken legal action against President Donald Trump's administration...

Dump Columnist Discovers Emotional Bonds with Discarded Items

Meg Whitton, a resident of Simcoe County in southern Ontario, shared her experience at...

“Gilmore Girls Documentary in the Works: Behind-the-Scenes Revealed!”

Get ready to cozy up in your warmest sweater, grab a large cup of...

More like this

“Hamster’s Strava Stardom: Mollie’s Nightly Runs Go Viral”

Physicist and hamster owner Thijs de Buck recently shared in an interview that his...

Human Rights Groups Sue Trump Admin Over ICC Sanctions

Four U.S.-based human rights organizations have taken legal action against President Donald Trump's administration...

Dump Columnist Discovers Emotional Bonds with Discarded Items

Meg Whitton, a resident of Simcoe County in southern Ontario, shared her experience at...