“Coldcard Bitcoin Wallet Hack: $100M Stolen”

Date:

Share post:

If you utilize bitcoin, you might know about Coldcard, a bitcoin-only hardware wallet that has experienced a recent data breach.

According to Galaxy Research, hackers managed to siphon off over $100 million US worth of bitcoin from Coldcard hardware wallets.

Here’s the latest on the ongoing breach, the impacted individuals, and steps to safeguard your cryptocurrency.

Functionality of Coldcard

Coldcard, developed by Coinkite, a Toronto-based company, is a hardware wallet that does not store bitcoin for users. Instead, it enhances security by storing “seed phrases” offline within the physical device, isolated from the Internet.

The “seed phrases” are complex, hard-to-guess words that serve as the master key to the bitcoin-only wallet.

These phrases act as digital signatures, allowing users to authorize and sign transactions as bitcoin owners.

Coldcard is promoted as “cold storage” for long-term bitcoin holders who prefer to keep their keys offline, earning acclaim from users and security experts as one of the most secure ways to store bitcoin.

Incident Details

Coinkite alerted users about a software bug on Thursday that enabled hackers to reconstruct wallet “seed phrases.”

This critical software vulnerability facilitated successive attacks, granting hackers access to users’ bitcoin wallets without needing physical possession of the device.

Galaxy Research reported that as of Monday, three confirmed attack waves and several smaller incidents resulted in around 1,596 bitcoin being stolen from approximately 7,300 addresses.

If a fourth wave is confirmed, the total losses could rise to about 2,055 bitcoin, valued at approximately $130 million US.

The attackers’ identities remain unknown.

Coinkite’s Co-founder and CEO, Rodolfo Novak, advised users who generated a seed with Coldcard to transfer their funds immediately following the release of firmware updates for affected products.

Novak expressed regret that funds could not be recovered and acknowledged the need to regain users’ confidence.

Coinkite acknowledged in an update that the exploited flaw dated back to March 2021, where affected firmware utilized a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator.

Novak cautioned fellow developers about the risks posed by artificial intelligence in code review processes.

User Impact

All Coldcard users are potentially affected by the software bug, exposing their wallets to compromise.

Most of the stolen bitcoin remains untouched, indicating that the funds are still in the same wallets where they were initially sent post-theft.

Details from the investigation have been shared with relevant authorities, exchanges, and cyber-investigation groups to track the attackers.

Aneirin Flynn from FailSafe emphasized the vulnerability of supposedly offline crypto assets and the risks associated with compromised underlying math.

Recommended Actions

If you suspect your wallet is compromised, avoid leaving your bitcoin in the current wallet.

Coinkite advised that the new firmware only protects wallets created post-update, urging users to replace vulnerable seed phrases generated on at-risk devices.

Customers are encouraged to install the latest update and refrain from generating new seeds until the fix is in place.

Coinkite assured ongoing investigations and pledged to release a technical review promptly, despite experts suggesting the irreparable damage already incurred.

Users have the option to transfer funds to another secure address at a custodian/exchange or generate a fresh seed if uncertain about Coldcard’s safety.

Coinkite recommended retaining the affected device, which may be crucial if funds are recovered, with legal assistance provided to identify responsible parties.

Source

Related articles

“Alberta Premier’s UCP Receives $471K Corporate Donations”

Following the United Conservative Party government's decision to reinstate corporate donations to provincial politics, Alberta Premier Danielle Smith’s...

New Brunswick Woman Reaches Settlement in Hospital Negligence Lawsuit

A woman from Hanwell, New Brunswick, who visited Horizon's Dr. Everett Chalmers Regional Hospital on March 22, 2022,...

Curling Trials Shape New Era in Canadian Curling

The Canadian Curling Trials held in Montana not only identified the representatives for the Winter Olympics but also...

“Rep. Ilhan Omar Assaulted at Minneapolis Town Hall”

A man sprayed an unknown substance on U.S. Rep. Ilhan Omar during a town hall in Minneapolis, where...