Bitcoin Hardware Wallet Coldcard Breach Exposes $100M Loss

Coldcard, a bitcoin-exclusive hardware wallet, has fallen victim to a recent data breach resulting in the theft of over $100 million in bitcoin. The breach, disclosed by blockchain intelligence company Galaxy Research, has impacted numerous users. Coldcard, developed by Coinkite based in Toronto, functions as a hardware wallet that does not store bitcoin but enhances security by storing “seed phrases” offline within the physical device. These seed phrases serve as a master key to the bitcoin-only wallet, enabling users to authorize transactions securely.

The breach was attributed to a software bug that allowed hackers to reconstruct wallet seed phrases, facilitating unauthorized access to users’ bitcoin wallets without physical access to the device. Galaxy Research reported multiple attack waves resulting in the theft of 1,596 bitcoin from approximately 7,300 addresses, with a potential total loss of 2,055 bitcoin valued at around $130 million. The perpetrators behind the attacks remain unidentified.

Coinkite’s CEO, Rodolfo Novak, urged users to transfer their funds immediately and released firmware updates to address the vulnerability. The exploited flaw, discovered in March 2021, stemmed from the use of a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator for generating wallet seeds. Coinkite has taken steps to rectify the issue, including halting shipments of affected products.

All Coldcard users are advised to be cautious as their wallets could be compromised due to the software bug. Galaxy Research emphasized the importance of installing the latest firmware to protect newly created wallets. The company is conducting an investigation, and a technical review will be published soon. However, experts caution that the damage may already be irreversible.

To safeguard their assets, affected Coldcard users are encouraged to move their funds to secure addresses or seek assistance from custodians or exchanges. Coinkite recommends retaining the device in case of fund recovery efforts. It is essential for users to remain vigilant and take necessary precautions to secure their cryptocurrency holdings amidst the ongoing breach.

The incident highlights the vulnerability of cryptocurrency security systems and underscores the importance of proactive measures to mitigate risks associated with digital asset storage.