A recent data breach targeted Coldcard, a bitcoin-exclusive hardware wallet, resulting in hackers siphoning over $100 million US worth of bitcoin from Coldcard hard wallets, as per Galaxy Research. Coldcard, developed by Coinkite in Toronto, functions as a hardware wallet that enhances security by storing “seed phrases” offline within the physical device, never requiring an Internet connection. These seed phrases, serving as master keys to the bitcoin-only wallet, enable users to authorize transactions securely.
The breach was caused by a software bug identified by Coinkite on Thursday, allowing hackers to reconstruct wallet seed phrases and access users’ bitcoin wallets remotely. Galaxy Research reported that approximately 1,596 bitcoin were stolen from around 7,300 addresses in confirmed attack waves, with the potential for further losses if a fourth wave is verified. The total amount lost could reach around $130 million US if all incidents are included.
It remains uncertain who orchestrated the attacks. Coinkite’s CEO, Rodolfo Novak, recommended users who generated a seed using a Coldcard wallet to transfer their funds immediately after issuing firmware updates. Coinkite acknowledged the flaw’s origin in March 2021, emphasizing the importance of installing the latest update and refraining from generating new seeds on vulnerable devices until the fix is in place.
All Coldcard users are at risk due to the software bug, with approximately 90% of the stolen bitcoin remaining stagnant in the wallets they were sent to post-theft. Investigations are ongoing, with details being shared with U.S. law enforcement agencies, cryptocurrency exchanges, and cyber-investigation groups. Advice from experts suggests moving funds to a secure address, updating firmware, and abstaining from generating new seeds on vulnerable models until the necessary patches are installed.
