Coldcard, a bitcoin-exclusive hardware wallet, has fallen victim to a recent data breach where hackers managed to siphon off over $100 million US worth of bitcoin from Coldcard hard wallets, as per findings from blockchain intelligence firm Galaxy Research. Coldcard, developed by Coinkite, a Toronto-based company, functions as a hardware wallet that enhances security by storing “seed phrases” offline within the physical device, without requiring an internet connection. These seed phrases serve as master keys for the bitcoin-only wallet, enabling users to authorize and sign transactions securely.
Following a software bug alert issued by Coinkite, it was revealed that hackers exploited a vulnerability to reconstruct wallet seed phrases, resulting in multiple attack waves. As confirmed by Galaxy Research, approximately 1,596 bitcoin from around 7,300 addresses have been stolen, with a potential increase to 2,055 bitcoin if a suspected fourth wave is confirmed, amounting to about $130 million US. The perpetrators behind the attacks remain unknown.
Users of Coldcard are advised to take precautionary measures given the software bug. Coinkite recommends moving funds generated using a Coldcard wallet and installing the latest firmware updates to safeguard against potential risks. The company acknowledged the flaw in the firmware, which led to the compromise, and emphasized the importance of immediate action to mitigate further losses. Additionally, affected users are encouraged to transfer their funds to secure addresses or alternative custodians to ensure the safety of their assets.