Hackers Exploit Coldcard Wallet Flaw to Steal More Than $130 Million in Bitcoin
Hackers have stolen more than $130 million in Bitcoin by exploiting a flaw in Coldcard hardware wallets that made seed phrases predictable.
Hackers have stolen more than $130 million worth of cryptocurrency by exploiting a vulnerability in Coldcard hardware wallets, according to blockchain security firms tracking the ongoing thefts. Researchers say at least a dozen different attackers are targeting Bitcoin owners who use the offline wallets manufactured by Coinkite.
Galaxy Research estimated that approximately $130 million had been stolen as of Tuesday, a figure that Elliptic co-founder and chief scientist Tom Robinson said was broadly accurate. Researchers believe multiple hacking groups are involved, although those responsible have not yet been identified.
The attacks add to a year of significant cryptocurrency thefts. Blockchain monitoring firm TRM Labs said more than 200 attacks against cryptocurrency companies have resulted in losses exceeding $950 million so far this year.
Offline wallets compromised by predictable seed phrases
Coldcard devices are designed to store cryptocurrency seed phrases offline, allowing users to keep the private keys controlling their Bitcoin disconnected from the internet. This “cold wallet” approach is generally regarded as more secure than online wallets connected to exchanges, browser extensions or mobile applications.
According to security researchers at Block, the attackers exploited a flaw in how certain Coldcard wallets generated seed phrases, making them predictable. Rather than breaking into individual wallets, the hackers were able to brute-force the affected seed phrases and gain access to the associated cryptocurrency.
Jonathan Goodman, who said he lost approximately $1.6 million from his Coldcard wallet, wrote on X that he had never shared his seed phrase and had kept his devices offline in safes and safety deposit boxes. He attributed the theft to a vulnerability in the wallet’s seed phrase generation code dating back to 2021.
Coinkite urges users to update devices
Coinkite issued a security advisory last week warning customers about the vulnerability. The company advised users to update affected devices and migrate their cryptocurrency to newly generated seed phrases to reduce the risk of compromise.
The incident has drawn attention because hardware wallets are widely regarded as one of the safest methods of storing digital assets. The attacks demonstrate that weaknesses in the software used to generate cryptographic keys can undermine the security of even devices that remain disconnected from the internet.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0