In section Startups & Technology

Coldcard wallet flaw leads to $130 million in Bitcoin thefts

A security vulnerability in Coldcard hardware wallets has allowed attackers to siphon more than $130 million in Bitcoin from users who kept their keys entirely offline. By exploiting a flaw in how the devices generated seed phrases, hackers bypassed physical security measures to reconstruct private keys at scale.

Coldcard wallet flaw leads to $130 million in Bitcoin thefts

Security researchers at Block discovered that the affected hardware wallets utilized a predictable pattern when generating seed phrases, rendering the devices' offline protection moot. Rather than breaking into physical safes or digital vaults, attackers utilized the flaw to brute-force the keys, effectively manufacturing duplicates of the credentials. The breach has compromised at least a dozen different groups of attackers, according to data from Galaxy Research.

For victims like Jonathan Goodman, who reported a loss of $1.6 million, the theft highlights the precarious nature of hardware security. Despite storing devices in multiple physical safes and never connecting them to the internet, Goodman found his assets drained due to a single line of vulnerable code introduced in 2021. Coinkite, the manufacturer of Coldcard, issued an advisory urging users to update their firmware and migrate to new seed phrases to secure their remaining holdings. This incident adds to a broader trend of crypto-related heists, with over $950 million lost across 200 separate attacks this year.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!