A significant data breach has impacted Coldcard, a bitcoin-only hardware wallet, resulting in hackers siphoning more than $100 million US worth of bitcoin, as per findings from Galaxy Research. Coldcard, developed by Coinkite in Toronto, acts as a hardware wallet that does not store bitcoin but enhances security by storing “seed phrases” offline within the physical device. These seed phrases serve as a master key for the bitcoin-only wallet, enabling users to authorize transactions securely.
Recently, Coinkite alerted users of a software bug that allowed hackers to reconstruct wallet seed phrases, leading to multiple attack waves and the theft of 1,596 bitcoin from around 7,300 addresses. If a fourth wave is confirmed, the total loss could rise to 2,055 bitcoin, equivalent to approximately $130 million US. The culprits behind the attacks remain unidentified.
Affected users are advised to transfer their funds immediately, as Coinkite released firmware updates to address the issue. The vulnerability stemmed from a flaw in the software dating back to March 2021, which compromised the generation of wallet seeds. Users are urged not to generate new seeds until the update is installed. The ongoing investigation has also involved sharing details with law enforcement and cyber-investigation agencies.
To mitigate risks, Coldcard users should consider moving their funds to secure addresses or custodians, as existing seed phrases generated on vulnerable devices remain exposed. Coinkite assures ongoing efforts to rectify the situation and collaborate with law enforcement for fund recovery. The incident underscores the importance of promptly addressing security vulnerabilities in cryptocurrency hardware devices.
