Coldcard, a bitcoin-exclusive hardware wallet, has fallen victim to a recent data breach where hackers managed to siphon off over $100 million US in bitcoin from Coldcard hard wallets, as per findings from Galaxy Research. Coldcard, developed by Coinkite based in Toronto, is a hardware wallet that enhances security by storing “seed phrases” offline within the physical device, offering an additional layer of protection for bitcoin stored on the public blockchain network. The seed phrases serve as a secure key for authorizing transactions in the bitcoin-only wallet.
Coinkite issued a warning to its users about a software bug allowing hackers to reconstruct wallet seed phrases, resulting in multiple attack waves that led to the theft of approximately 1,596 bitcoin from around 7,300 addresses. If a fourth wave is confirmed, the total stolen amount could escalate to roughly 2,055 bitcoin, valued at around $130 million US. The perpetrators behind these attacks remain unidentified.
To mitigate the risks, Coinkite advised users to transfer their funds immediately if they generated a seed using a Coldcard wallet. The company released firmware updates for affected products to address the vulnerability in the software. The flaw was traced back to March 2021, where the firmware mistakenly relied on a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator for generating wallet seeds.
All Coldcard users are potentially impacted by this breach, with about 90% of the stolen bitcoin remaining stagnant in the same wallets since the theft occurred. The ongoing investigation details are being shared with U.S. law enforcement agencies, cryptocurrency exchanges, and cyber-investigation groups. Aneirin Flynn, CEO of FailSafe, emphasized the importance of understanding that even with offline storage, crypto assets can be vulnerable if the underlying security measures are compromised.
Users are urged not to keep their bitcoin in compromised wallets and to install the latest firmware updates provided by Coinkite. The company is conducting an investigation, and a technical review will be released soon. Affected users have the option to transfer their funds to a secure address at a custodian/exchange or generate a fresh seed for safety. Additionally, Coinkite recommended not disposing of affected devices, as they may be crucial for potential fund recovery efforts coordinated with law enforcement agencies.
