Coldcard, a bitcoin-only hardware wallet, has fallen victim to a data breach resulting in hackers siphoning off over $100 million US worth of bitcoin from users’ wallets, as reported by Galaxy Research. Coldcard, developed by Coinkite, is a hardware wallet that enhances security by storing “seed phrases” offline, providing an extra layer of protection without the need for an internet connection. These seed phrases serve as a master key for the bitcoin-only wallet, enabling users to authorize and sign transactions securely.
The breach was discovered due to a software bug that allowed hackers to reconstruct wallet seed phrases without physical access to the device, leading to multiple waves of attacks resulting in the theft of 1,596 bitcoin from approximately 7,300 addresses. If a suspected fourth wave is confirmed, the total amount lost could reach 2,055 bitcoin, equivalent to around $130 million US. The culprits behind the attacks remain unidentified.
Coinkite has issued firmware updates to address the vulnerability and advised users to transfer their funds immediately. The compromised firmware, which relied on a deterministic pseudo-random generator instead of a hardware-backed true random number generator, has been replaced, halting further shipments of affected products. Coinkite’s co-founder, Rodolfo Novak, emphasized the importance of moving funds and warned developers about the risks posed by artificial intelligence in identifying software vulnerabilities.
To safeguard themselves, Coldcard users are urged to update their wallets with the latest firmware, especially if their seed phrases were generated using vulnerable devices. Galaxy Research highlighted the significance of not generating new seeds on affected models until the update is installed. The ongoing investigation into the breach has involved sharing details with law enforcement agencies, cryptocurrency exchanges, and cyber-investigation groups to track down the attackers.
Experts advise affected users to transfer their funds to secure addresses or custodians, as the compromised seed phrases remain at risk. Coinkite is conducting a technical review, but the impact of the breach has already been felt. The complexity of the workaround poses challenges for users, prompting the need for swift action to protect their assets.
In conclusion, the breach serves as a stark reminder of the vulnerabilities in crypto security measures and the importance of proactive measures to mitigate risks.
