Coldcard, a specific bitcoin hardware wallet, has recently experienced a security breach resulting in hackers siphoning over $100 million worth of bitcoin, as per Galaxy Research. Coldcard, designed by Coinkite based in Toronto, is deemed a secure storage option for bitcoin users. However, a software bug allowed attackers to reconstruct wallet “seed phrases” without direct access to the physical device. This vulnerability has led to significant bitcoin theft from numerous addresses.
Coinkite has issued warnings to its users regarding the bug and urged them to transfer their funds immediately. The company disclosed that the flaw originated in March 2021 due to an error in generating wallet seeds. Coinkite has since ceased the production of affected inventory and provided firmware updates for post-fix wallets. Coinkite’s CEO, Rodolfo Novak, emphasized the importance of swift action to secure funds and restore user trust.
The ongoing investigation has revealed that the majority of stolen bitcoins remain untouched in their original wallets, indicating a potential delay in the hackers’ actions. Galaxy Research has shared details of the attack with law enforcement agencies and relevant entities to track down attacker addresses. Security experts have highlighted the critical need for proactive measures to safeguard cryptocurrency assets.
To mitigate risks, Coldcard users are advised to update their firmware, especially for wallets created post-fix. Existing seed phrases created on vulnerable devices are recommended for replacement. Coinkite is conducting a thorough review, and users are encouraged to stay informed about further developments. In the face of this breach, affected users are encouraged to relocate their funds to secure addresses and refrain from disposing of their Coldcard devices, which may be crucial for potential fund recovery efforts.
