Coldcard, a bitcoin-exclusive hardware wallet, has fallen victim to a recent data breach resulting in the theft of over $100 million US in bitcoin. The breach allowed hackers to access users’ wallet “seed phrases” through a software bug, leading to the theft of 1,596 bitcoin from approximately 7,300 addresses. The total loss could rise to 2,055 bitcoin, valued at around $130 million US, if a suspected fourth wave is confirmed.
Coinkite, the Toronto-based company behind Coldcard, has advised users to move their funds immediately and has issued firmware updates to address the vulnerability. The flaw, discovered in March 2021, compromised the generation of wallet seeds by relying on a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator.
The ongoing investigation into the breach has uncovered that 90% of the stolen bitcoin remains untouched in the original wallets, indicating that the hackers may be waiting before making any further transactions. Address details of the attackers and victims have been shared with law enforcement agencies, exchanges, and cyber-investigation groups.
To safeguard their assets, Coldcard users are urged to install the latest firmware update and refrain from generating new seeds on vulnerable devices until the fix is in place. Coinkite reassures customers that an investigation is ongoing, and a technical review will be released soon. However, experts warn that the impact of the breach may have lasting consequences.
Galaxy Research recommends affected users transfer their funds to a secure address or a trusted custodian/exchange until the situation is resolved. Coinkite also advises against disposing of affected devices, as they may be crucial in potential fund recoveries. The company pledges to collaborate with law enforcement to identify the perpetrators of the breach.
