If you utilize bitcoin, you might know about Coldcard, a bitcoin-only hardware wallet that has experienced a recent data breach.
According to Galaxy Research, hackers managed to siphon off over $100 million US worth of bitcoin from Coldcard hardware wallets.
Here’s the latest on the ongoing breach, the impacted individuals, and steps to safeguard your cryptocurrency.
Functionality of Coldcard
Coldcard, developed by Coinkite, a Toronto-based company, is a hardware wallet that does not store bitcoin for users. Instead, it enhances security by storing “seed phrases” offline within the physical device, isolated from the Internet.
The “seed phrases” are complex, hard-to-guess words that serve as the master key to the bitcoin-only wallet.
These phrases act as digital signatures, allowing users to authorize and sign transactions as bitcoin owners.
Coldcard is promoted as “cold storage” for long-term bitcoin holders who prefer to keep their keys offline, earning acclaim from users and security experts as one of the most secure ways to store bitcoin.
Incident Details
Coinkite alerted users about a software bug on Thursday that enabled hackers to reconstruct wallet “seed phrases.”
This critical software vulnerability facilitated successive attacks, granting hackers access to users’ bitcoin wallets without needing physical possession of the device.
Galaxy Research reported that as of Monday, three confirmed attack waves and several smaller incidents resulted in around 1,596 bitcoin being stolen from approximately 7,300 addresses.
If a fourth wave is confirmed, the total losses could rise to about 2,055 bitcoin, valued at approximately $130 million US.
The attackers’ identities remain unknown.
Coinkite’s Co-founder and CEO, Rodolfo Novak, advised users who generated a seed with Coldcard to transfer their funds immediately following the release of firmware updates for affected products.
Novak expressed regret that funds could not be recovered and acknowledged the need to regain users’ confidence.
Coinkite acknowledged in an update that the exploited flaw dated back to March 2021, where affected firmware utilized a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator.
Novak cautioned fellow developers about the risks posed by artificial intelligence in code review processes.
User Impact
All Coldcard users are potentially affected by the software bug, exposing their wallets to compromise.
Most of the stolen bitcoin remains untouched, indicating that the funds are still in the same wallets where they were initially sent post-theft.
Details from the investigation have been shared with relevant authorities, exchanges, and cyber-investigation groups to track the attackers.
Aneirin Flynn from FailSafe emphasized the vulnerability of supposedly offline crypto assets and the risks associated with compromised underlying math.
Recommended Actions
If you suspect your wallet is compromised, avoid leaving your bitcoin in the current wallet.
Coinkite advised that the new firmware only protects wallets created post-update, urging users to replace vulnerable seed phrases generated on at-risk devices.
Customers are encouraged to install the latest update and refrain from generating new seeds until the fix is in place.
Coinkite assured ongoing investigations and pledged to release a technical review promptly, despite experts suggesting the irreparable damage already incurred.
Users have the option to transfer funds to another secure address at a custodian/exchange or generate a fresh seed if uncertain about Coldcard’s safety.
Coinkite recommended retaining the affected device, which may be crucial if funds are recovered, with legal assistance provided to identify responsible parties.
