A recent data breach targeted Coldcard, a bitcoin-only hardware wallet, leading to hackers stealing over $100 million worth of bitcoin from the wallets, as per blockchain intelligence firm Galaxy Research. Coldcard, developed by Coinkite in Toronto, is a hardware wallet that enhances security by storing seed phrases offline in the physical device, serving as a master key to the bitcoin-only wallet. The breach was linked to a software bug discovered by Coinkite, allowing hackers to access users’ wallets without physical possession.
As a result of the breach, approximately 1,596 bitcoins were stolen from around 7,300 addresses, with a potential total loss of 2,055 bitcoins worth about $130 million if a suspected fourth wave of attacks is confirmed. Coinkite has released firmware updates to address the issue and recommended users to move their funds immediately. The company acknowledged the flaw in the software that has been exploited since March 2021 due to a reliance on a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator.
All Coldcard users are advised to take precautions, with Galaxy Research urging users not to generate new seed phrases until the update is installed. The ongoing investigation has involved sharing details with law enforcement agencies and cyber-investigation groups. Coinkite emphasized the importance of installing the latest firmware update and refraining from generating new seeds on vulnerable devices until the fix is applied. The company’s formal technical review is forthcoming, while affected users are encouraged to consider moving their funds to secure addresses or seeking alternative custody options.
