Coldcard, a bitcoin-only hardware wallet, has been the recent victim of a data breach, with hackers reportedly siphoning off over $100 million US worth of bitcoin from Coldcard hard wallets, as per blockchain intelligence company Galaxy Research. Coldcard, created by Coinkite, a Toronto-based firm, functions as a hardware wallet that stores “seed phrases” offline for added security without requiring an internet connection. These seed phrases are complex sequences of words that serve as a master key to the bitcoin-only wallet, allowing users to authorize and sign transactions.
The breach was disclosed following the discovery of a software bug by Coinkite, enabling hackers to reconstruct wallet seed phrases and gain access to users’ bitcoin wallets without physical access to the device. Three confirmed attack waves and several smaller incidents resulted in approximately 1,596 bitcoin being stolen from around 7,300 addresses, with a potential total loss of 2,055 bitcoin worth about $130 million US if a fourth wave is confirmed. The culprits behind the attacks remain unidentified.
Coinkite CEO Rodolfo Novak advised Coldcard users to move their funds immediately following the release of firmware updates to address the security flaw. The vulnerability, originating in March 2021, arose from the use of a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator. Coinkite has ceased shipping affected products and destroyed remaining inventory produced with the vulnerable firmware.
All Coldcard users are potentially exposed to the breach, with about 90% of the stolen bitcoin remaining idle in the same wallets since the theft. Investigations are ongoing, with details shared with law enforcement agencies, exchanges, and cyber-investigation groups. Experts caution that the breach underscores the risks of holding crypto assets offline, emphasizing the need for prompt action in response to compromised wallets.
Coldcard users are advised to install the latest firmware update, which safeguards newly created wallets post-update, while existing vulnerable seed phrases should be replaced. Coinkite is conducting an investigation, with a technical review forthcoming. Users have the option to transfer funds to safer addresses or engage third-party custodians for asset protection. The company recommends retaining affected devices as they may be required for potential fund recovery efforts.
