A data breach has targeted Coldcard, a bitcoin-only hardware wallet, resulting in hackers siphoning over $100 million US worth of bitcoin, as reported by Galaxy Research. Coldcard, developed by Toronto-based Coinkite, enhances security by storing “seed phrases” offline on the physical device without requiring an internet connection. These seed phrases serve as a secure master key for the bitcoin-only wallet.
Recently, Coinkite warned users of a software bug that allowed hackers to reconstruct wallet seed phrases, enabling unauthorized access to users’ bitcoin wallets. The breach has resulted in the theft of 1,596 bitcoins from around 7,300 addresses, potentially escalating to 2,055 bitcoins worth approximately $130 million US if a fourth wave of attacks is confirmed.
Coinkite CEO Rodolfo Novak advised users to transfer their funds immediately and issued firmware updates to address the vulnerability. The flaw in the software, discovered in March 2021, stemmed from using a deterministic pseudo-random number generator instead of the intended hardware-backed true random number generator for generating wallet seeds.
All Coldcard users are at risk, with 90% of the stolen bitcoins remaining stagnant in the wallets they were sent to after the theft, according to Galaxy Research. Law enforcement agencies and cryptocurrency exchanges have been provided with details from the ongoing investigation to identify attacker addresses.
To safeguard their assets, users are advised to move funds from compromised wallets, install the latest firmware updates, and refrain from generating new seeds on vulnerable devices until updated. Coinkite is conducting an investigation, and a formal technical review will be released soon. Users have the option to transfer their funds to a secure address at a custodian or exchange if uncertain about the safety of their Coldcard.


