• security
  • news
  • 1 hour

Hackers Steal $89 M via a Coldcard Wallet Vulnerability

A flaw in seed phrase generation allowed attackers to reconstruct the private keys of thousands of wallets. Over the course of several days, they stole more than 1,367 BTC, and the attacks are still ongoing.

0

nft.eu
  • rating +26
  • subscribers 113

Hackers have stolen more than 1,367 bitcoins worth about $89 M from wallets created using vulnerable firmware versions of Coldcard hardware wallets manufactured by Coinkite. The large-scale thefts began on July 30 and affected at least 4,585 wallets within three days. Late on August 2, analysts detected signs of a new wave of attacks, meaning the total losses could climb even higher.

How the Attacks Unfolded

The first wave took place on July 30, when the attackers stole 1,083 BTC. The following day, researchers at Galaxy Research identified additional thefts, bringing the total amount of stolen funds to 1,159 BTC.

A third wave followed on August 2, bringing the total losses to 1,367 BTC. Later, Alex Thorn, head of research at Galaxy Research, reported an additional transfer of 389 BTC worth about $24.5 M and suggested that a fourth coordinated attack had begun. According to him, the stolen funds have not yet been moved.

The Nature of the Vulnerability

The incident was caused by a firmware flaw that had existed since March 2021. Instead of relying on the hardware random number generator, some Coldcard firmware versions used a predictable software algorithm when generating seed phrases. This allowed the attacker to reconstruct the private keys for some wallets created with the vulnerable firmware.

Owners of early Coldcard models faced the highest risk, although Coinkite recommends that users of newer devices check their devices as well.

Read Also: Crypto Wallets Without Seed Phrases: MPC, Account Abstraction and AI‑Native Wallets

The vulnerability does not affect users who added at least 50 random dice rolls when generating their seed phrase using the Add Dice Rolls feature. A BIP-39 passphrase also provides an additional layer of protection by making key recovery significantly more difficult. Even so, Coinkite recommends that these users move their funds to a new wallet.

The issue does not affect TAPSIGNER, OPENDIME, or SATSCARD devices, as they use a different codebase.

Coinkite’s Response

Coinkite has acknowledged responsibility for the firmware flaw, released a fix for all affected models, and urged users to immediately move their funds to new wallets with newly generated seed phrases. The company stressed that updating the firmware only protects newly created wallets and does not make previously generated seed phrases safe.

The company also promised to publish a detailed technical analysis of the incident once the investigation is complete. In addition, it said it is prepared to assist affected users with filing reports with law enforcement, insurance claims, and their own investigations.

It remains unknown who discovered the vulnerability or who is behind the attacks. Coinkite said it is still assessing the full scope of the incident and will not speculate until its technical investigation is complete.

Read also:

This post is for informational purposes only and does not constitute advertising or investment advice. Please do your own research before making any decisions.

0

Comments

0