A recent data breach has targeted Coldcard, a bitcoin-only hardware wallet, resulting in hackers siphoning over $100 million US worth of bitcoin from users’ wallets. The hardware wallet, designed by Toronto-based Coinkite, enhances security by storing “seed phrases” offline within the physical device, adding an extra layer of protection to users’ bitcoin stored on the public blockchain network.
The breach was attributed to a software bug that allowed hackers to reconstruct wallet seed phrases, granting them access to users’ bitcoin wallets without physical access to the device. The attacks, comprising three confirmed waves and additional smaller incidents, have led to the theft of approximately 1,596 bitcoin from around 7,300 addresses. With a potential fourth wave, the total loss could rise to 2,055 bitcoin, valued at roughly $130 million US.
Coinkite urged users who generated a seed using a Coldcard wallet to transfer their funds promptly and issued firmware updates for affected products. The company acknowledged the flaw originated in March 2021, advising other developers to be vigilant as AI advancements can expose latent bugs.
All Coldcard users are at risk due to the software bug, although about 90% of the stolen bitcoin remains stationary in the wallets where they were sent post-theft. Investigations have been shared with law enforcement agencies and cybersecurity groups to track the hackers and protect users’ assets.
To safeguard funds, users are encouraged to install Coldcard’s new firmware, replace vulnerable seed phrases, and refrain from generating new seeds until the update is applied. Affected users can consider moving their funds to a secure address or seek assistance from custodians/exchanges. Coinkite also recommended retaining the affected device for potential recovery efforts.
