Coldcard Bitcoin Wallet Breach: $100M Stolen

Date:

Coldcard, a bitcoin-exclusive hardware wallet, has recently fallen victim to a data breach resulting in hackers siphoning over $100 million US worth of bitcoin from the wallets. The breach, which has prompted concerns among bitcoin users, involves the exploitation of a software bug within the Coldcard system that allowed attackers to reconstruct wallet “seed phrases.”

Coldcard, developed by Coinkite based in Toronto, functions as a hardware wallet that enhances security by storing seed phrases offline within the physical device instead of holding the actual bitcoins. These seed phrases serve as a master key to the bitcoin-only wallet, enabling users to authorize transactions securely. Despite its reputation as a secure “cold storage” option for long-term bitcoin holders, the recent breach has raised alarms within the cryptocurrency community.

The vulnerability in the Coldcard software, disclosed by Coinkite last week, has led to multiple attack waves resulting in the theft of 1,596 bitcoin from around 7,300 addresses. Galxy Research, a blockchain intelligence firm, reported that if a suspected fourth wave is confirmed, the total loss could reach 2,055 bitcoin, valued at approximately $130 million US. The perpetrators behind these attacks remain unidentified.

Coinkite has urged users who generated a seed using Coldcard to transfer their funds to safeguard their assets following the release of firmware updates addressing the security flaw. The company acknowledged the software flaw’s origin in March 2021 and emphasized the importance of installing the latest firmware to protect new wallets. However, seed phrases created on vulnerable devices remain at risk and should be replaced to prevent further exploitation.

In response to the breach, ongoing investigations are being conducted, with details shared with relevant authorities and cybersecurity entities to identify attacker addresses. Coldcard users are advised to take precautionary measures, such as transferring funds to secure addresses or custodians, and refrain from generating new seeds until the firmware update is implemented. Despite efforts to mitigate the impact, experts suggest that the complexity of the workaround may pose challenges for affected users, underscoring the need for swift action to secure their assets.

Share post:

Popular

More like this
Related

“Wildfires Ravage British Columbia: Evacuation Orders Remain Amid Growing Concerns”

The most recent updates on the wildfires in British...

“Debate Ignites Over Alberta’s Use of Dogs to Hunt Black Bears”

The Alberta government has authorized the use of dogs...

“Canada Imposes Sanctions on Iranian Officials in Strait of Hormuz Dispute”

Canada's foreign affairs minister announced that five senior Iranian...

“Progressive Surge: El-Sayed’s Win Reflects Leftist Momentum”

Abdul El-Sayed's triumph in Michigan's Democratic Senate primary is...