If you use bitcoin, you might be familiar with Coldcard, a bitcoin-only hardware wallet that has recently fallen victim to a data breach.
According to Galaxy Research, hackers managed to siphon off over $100 million worth of bitcoin from Coldcard hard wallets.
Here’s what we know about the ongoing breach, who is impacted, and steps to safeguard your cryptocurrency.
Operation of Coldcard
Coldcard, developed by Coinkite, a Toronto-based company, functions as a hardware wallet that doesn’t store your bitcoin. Instead, it enhances security by offline storage of “seed phrases” within the physical device, disconnected from the internet.
The “seed phrases” are complex sequences of random words serving as a master key for the bitcoin-only wallet.
These phrases or keys enable users to authorize and sign transactions, acting as the bitcoin owner.
Coldcard is marketed as “cold storage” for long-term bitcoin holders seeking to keep their keys offline, earning accolades from users and security experts as one of the most secure bitcoin storage solutions.
Incident Details
Coinkite warned users about a software bug enabling hackers to reconstruct wallet “seed phrases.” This flaw allowed hackers to access users’ bitcoin wallets remotely without physical access to the device.
As per Galaxy Research, three confirmed attack waves and various smaller incidents have led to the theft of 1,596 bitcoins from approximately 7,300 addresses. If a suspected fourth wave is verified, the total loss could reach 2,055 bitcoins, equivalent to about $130 million.
The attackers’ identity remains unknown.
Rodolfo Novak, Coinkite’s co-founder and CEO, advised Coldcard wallet users to transfer their funds immediately after releasing firmware updates for affected products.
Coinkite acknowledged the software flaw’s origin in March 2021 and took steps to rectify the issue by halting shipments of vulnerable firmware.
Novak cautioned other developers about the risks posed by AI-assisted code review.
User Impact
All Coldcard users face potential wallet accessibility due to the software bug. Most of the stolen bitcoins remain inactive in the same wallets post-theft, indicating no further transfer, sale, or exchange.
Information from the ongoing investigation has been shared with U.S. law enforcement, exchanges, and cyber-investigation groups.
Aneirin Flynn from FailSafe highlighted the vulnerability of “offline” crypto assets due to compromised underlying mathematics.
Protective Measures
If you suspect your wallet’s security, avoid keeping bitcoins in it. Installing Coldcard’s new firmware safeguards only post-fix wallets, necessitating replacement of vulnerable device-generated seed phrases.
Coinkite advises customers to install the latest update and refrain from generating new seeds on vulnerable models until the fix is applied.
Galaxy Research suggests migrating funds to secure addresses or fresh seeds and not disposing of affected devices.
