HomeBusiness"Bitcoin Hardware Wallet Coldcard Hit by $100M Breach"

“Bitcoin Hardware Wallet Coldcard Hit by $100M Breach”

Published on

Coldcard, a bitcoin-only hardware wallet, has fallen victim to a recent data breach where hackers managed to steal over $100 million US worth of bitcoin. The breach, which was identified by blockchain intelligence firm Galaxy Research, has impacted numerous users of the Coldcard wallets. The hardware wallet, developed by Coinkite based in Toronto, operates by storing “seed phrases” offline within the physical device, providing an added layer of security for bitcoin transactions on the public blockchain network.

Following the discovery of a bug in the Coldcard software, Coinkite issued a warning to users regarding the vulnerability that enabled hackers to reconstruct wallet seed phrases. This flaw allowed attackers to access users’ bitcoin wallets without requiring physical access to the device. The ongoing investigation has revealed that approximately 1,596 bitcoin has been stolen from about 7,300 addresses in three confirmed attack waves, with the potential for further losses totaling around 2,055 bitcoin, valued at roughly $130 million US if a suspected fourth wave is confirmed.

Coinkite’s co-founder and CEO, Rodolfo Novak, has urged users who have generated seed phrases using Coldcard wallets to transfer their funds immediately. Coinkite has released firmware updates to address the affected products and is working to regain users’ trust following the breach. Notably, the vulnerability in the software, which originated in March 2021, was due to the use of a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator.

To mitigate the risks associated with compromised wallets, users are advised not to keep their bitcoin in potentially compromised wallets and to install the latest firmware update provided by Coinkite. Customers are also encouraged to refrain from generating new seed phrases on vulnerable devices until the update is installed. Galaxy Research emphasized the importance of staying informed about the ongoing investigation and following security recommendations to safeguard their cryptocurrency holdings.

In response to the breach, users are recommended to transfer their funds to secure addresses or seek assistance from reputable custodians or exchanges to protect their assets. Coinkite has highlighted the necessity of retaining affected devices for potential fund recovery efforts, indicating collaboration with law enforcement agencies to identify and hold accountable those responsible for the breach. The repercussions of the hack underscore the critical need for enhanced security measures in the cryptocurrency space to protect users and their digital assets.

Latest articles

“Ontario IndyCar Event Hit by Track Construction Delay”

The inaugural Ontario Honda Dealers Indy at Markham experienced a setback during the starting...

“Drought in British Columbia Sparks Salmon Rescue Efforts”

Parts of British Columbia are facing severe drought conditions this summer. In Bessette Creek,...

“Trump Urges Apple to Rename Lake Ontario ‘Lake America'”

President Donald Trump has reportedly urged Apple to change the name of Lake Ontario...

“Canadian Parliament to Probe Security Screening Amid NATO Intern Espionage Case”

A parliamentary committee in the House of Commons has agreed to investigate the security...

More like this

“Ontario IndyCar Event Hit by Track Construction Delay”

The inaugural Ontario Honda Dealers Indy at Markham experienced a setback during the starting...

“Drought in British Columbia Sparks Salmon Rescue Efforts”

Parts of British Columbia are facing severe drought conditions this summer. In Bessette Creek,...

“Trump Urges Apple to Rename Lake Ontario ‘Lake America'”

President Donald Trump has reportedly urged Apple to change the name of Lake Ontario...