Coldcard Wallet Flaw Fuels $144 Million Bitcoin Heist
Synopsis
Hackers have reportedly stolen 1,596 Bitcoin from around 7,300 Coldcard wallets by exploiting a vulnerability first identified in 2021, with researchers warning the attacks are still ongoing.
A security flaw in the popular Coldcard Bitcoin hardware wallet has reportedly allowed hackers to steal more than 1,596 Bitcoin, worth around $144 million, from about 7,300 wallets.
Coldcard is a physical device that stores Bitcoin private keys offline and is designed to keep cryptocurrency secure by signing transactions without connecting those keys to the internet.
Researchers at Galaxy Digital first spotted the attacks after a large theft took place within 41 minutes on July 30. Since then, more attacks have been reported, with the total amount stolen rising from an estimated $98 million to about $144 million.
“The attack is ongoing,” Galaxy researchers said. Canada-based Coinkite, which makes Coldcard wallets, apologised to customers. “We are deeply sorry for the concern, disruption and uncertainty this has caused,” the company said.
Chief executive Rodolfo Novak also apologised, saying he was “devastated” and that the company’s team was heartbroken.
How the Security Flaw Worked
In an advisory, engineers and security researchers at Block, the fintech company founded by Jack Dorsey, said the issue was caused by a misconfiguration in some Coldcard devices.
Instead of using the device’s hardware-based randomness generator to create secure private keys, affected wallets relied on a software-based random number generator whose output could be predicted.
Because of this, attackers were able to steal funds without having physical access to the wallets. Block said the vulnerability had existed in affected devices since March 2021.
Users Urged to Move Their Bitcoin
Bitcoin security company WizardSardine said users are safe if none of their recovery seed was generated on a Coldcard device. Although a firmware update has been released, it does not protect Bitcoin already stored with affected keys.
“If any part of your key was generated on a Coldcard, you may be at risk,” WizardSardine warned.
Coinkite said it has destroyed all remaining unshipped devices with the vulnerable firmware but advised customers to keep affected devices in case they are needed for recovery efforts. The company has urged affected users to move their Bitcoin to a new wallet as soon as possible.
More Thefts Continue to Emerge
Galaxy Digital said the Bitcoin stolen during the first 41-minute attack was moved into four blockchain addresses and has not been moved since. The company believes the first wave was carried out by the same attacker.
Researchers later identified a second and third wave of attacks, along with three more blockchain addresses linked to the thefts.
Galaxy’s head of research, Alex Thorn, said he is also investigating a possible fourth wave affecting at least 709 wallet addresses. If confirmed, that wave would involve another 448 Bitcoin, worth about $40 million.
That would bring total losses to around 2,000 Bitcoin, valued at roughly $181 million. Coinkite said it is working directly with affected customers and plans to publish a full technical report on the incident.
“The last three days have been some of the hardest in this company’s history,” the company said.
“We owe the community better, and we’re beginning to understand the many ways in which our best efforts and designs could have allowed for this to happen.”
Source: Reuters
At Inspirepreneurs Magazine, covering entrepreneurship, business failures, and the human stories behind the world's most ambitious founders. She writes at the intersection of strategy and storytelling.