Coldcard, a bitcoin-exclusive hardware wallet, has recently fallen victim to a data breach resulting in over $100 million US worth of bitcoin being drained from the wallets. The breach was disclosed by Galaxy Research, a blockchain intelligence firm. Coldcard, developed by Coinkite based in Toronto, functions as a hardware wallet that enhances security by storing seed phrases offline within the physical device, without requiring an internet connection. These seed phrases serve as a critical component for authorizing and signing bitcoin transactions.
The breach was caused by a software bug identified by Coinkite, enabling hackers to reconstruct wallet seed phrases and access users’ bitcoin wallets without physical access to the device. As a result, approximately 1,596 bitcoin have been stolen from around 7,300 addresses, with the potential for this number to rise to 2,055 bitcoin worth around $130 million US if additional attacks are confirmed. The perpetrators behind the breach remain unidentified.
Coinkite has urged users who have generated seed phrases using Coldcard wallets to transfer their funds promptly. The company has released firmware updates to address the affected products. However, existing seed phrases created on vulnerable devices are still at risk and should be replaced. Galaxy Research emphasized the importance of installing the latest updates and cautioned against generating new seed phrases until the fix is applied.
In response to the breach, cryptocurrency exchanges, U.S. law enforcement agencies, and cyber-investigation groups have been provided with details from the ongoing investigation to identify attacker addresses. Aneirin Flynn, CEO of FailSafe, highlighted the vulnerability of offline crypto storage, emphasizing the need for strong password generation to prevent reverse engineering.
Users are advised not to keep their bitcoin in compromised wallets and to move funds to secure addresses. Coinkite is conducting an investigation, with a technical review to be released soon. The breach’s impact has raised concerns among experts, with cybersecurity precautions becoming increasingly crucial in the face of evolving threats.
