A recent data breach has targeted Coldcard, a bitcoin-only hardware wallet, resulting in hackers siphoning over $100 million US worth of bitcoin from Coldcard hard wallets, as reported by Galaxy Research. Coldcard, produced by Coinkite in Toronto, acts as a secure vault for users’ “seed phrases,” the essential keys to their bitcoin-only wallets, keeping them offline and away from potential online threats.
Coinkite alerted users about a software bug enabling hackers to reconstruct wallet seed phrases, leading to multiple attack waves and the theft of approximately 1,596 bitcoin from around 7,300 addresses. If a suspected fourth wave is confirmed, the total loss could escalate to 2,055 bitcoin, valued at roughly $130 million US. The perpetrators behind these attacks remain unidentified.
To mitigate risks, Coldcard users are advised to move their funds immediately, especially if they have generated a seed using a Coldcard wallet. Coinkite has released firmware updates for affected products to enhance security. The company acknowledged that the exploited flaw originated in March 2021 due to an error in the wallet seed generation process.
As investigations continue, details from the attacks have been shared with U.S. law enforcement agencies, cryptocurrency exchanges, and cyber-investigation groups. Experts caution users not to keep compromised bitcoin in their wallets and to install Coldcard’s latest firmware to safeguard their assets. Affected users can transfer their funds to secure addresses at custodians or exchanges. Coinkite reassured customers that their legal team would cooperate with law enforcement to recover funds if possible.
