A popular bitcoin hardware wallet known as Coldcard, designed specifically for bitcoin users, has recently fallen victim to a security breach resulting in hackers stealing over $100 million US worth of bitcoin from Coldcard hard wallets, as reported by Galaxy Research, a blockchain intelligence firm. This breach has raised concerns regarding the safety of cryptocurrency assets and has left users wondering about the security of their digital funds.
Coldcard, developed by Coinkite, a Toronto-based company, functions as a hardware wallet that does not physically store bitcoin. Instead, it enhances security by storing “seed phrases” offline within the device, disconnected from the internet. These seed phrases serve as a complex sequence of random words that function as a master key for the bitcoin-only wallet, allowing users to authorize and sign transactions securely.
Despite being marketed as a secure “cold storage” solution for long-term bitcoin holders, Coldcard faced a critical software bug that enabled hackers to reconstruct wallet seed phrases, leading to multiple waves of attacks. These attacks resulted in the theft of 1,596 bitcoins from approximately 7,300 addresses, with potential losses reaching 2,055 bitcoins valued at around $130 million US if a suspected fourth wave is confirmed.
Coinkite promptly issued warnings to its users and advised them to transfer their funds following the discovery of the vulnerability. The company released firmware updates to address the issue, urging affected users to take immediate action to safeguard their assets. Furthermore, Coinkite acknowledged the flaw in the firmware, which originated in March 2021, and emphasized the importance of implementing the latest updates to mitigate risks associated with the compromised seed phrases.
In response to the breach, Coinkite reassured users that an investigation is underway, and a formal technical review will be conducted to provide further insights. However, security experts have expressed concerns about the potential ramifications of the breach, emphasizing the urgency of taking proactive measures to protect digital assets.
To mitigate risks, Coldcard users are advised to install the latest firmware update, refrain from generating new seed phrases on vulnerable devices until updated, and consider transferring funds to secure addresses. Galaxy Research emphasized the importance of migrating funds to reputable custodians or exchanges for enhanced protection.
As the investigation continues, efforts are being made to identify the attackers and prevent further unauthorized access to compromised wallets. The incident underscores the need for heightened cybersecurity measures within the cryptocurrency community and serves as a cautionary tale for users to remain vigilant and prioritize security when managing their digital assets.
