More
    HomeBusinessBitcoin Hardware Wallet Coldcard Breach: $100M Stolen

    Bitcoin Hardware Wallet Coldcard Breach: $100M Stolen

    Published on

    For those using bitcoin, Coldcard, a bitcoin-only hardware wallet, has recently fallen victim to a data breach. According to Galaxy Research, hackers have siphoned off over $100 million US in bitcoin from Coldcard hard wallets.

    The breach has caused concern among users, prompting questions about who is affected and how to protect their cryptocurrency.

    Understanding Coldcard

    Developed by Coinkite, a Toronto-based company, Coldcard is a hardware wallet that does not store bitcoin but enhances security by securely storing “seed phrases” offline within the physical device without internet connection. These “seed phrases” are complex sequences of words serving as a master key for the bitcoin-only wallet.

    Coldcard is considered a top choice for long-term bitcoin storage by keeping keys offline, earning accolades from users and security experts for its robust security features.

    Recent Events

    Last week, Coinkite alerted users to a software bug allowing hackers to reconstruct wallet “seed phrases.” Exploiting this vulnerability, attackers gained unauthorized access to users’ bitcoin wallets without physical access to the device.

    As per Galaxy Research, multiple attack waves have resulted in the theft of 1,596 bitcoins from around 7,300 addresses. If a fourth wave is confirmed, the total loss could rise to 2,055 bitcoins, valued at approximately $130 million US.

    The identities of the perpetrators remain unknown.

    Rodolfo Novak, Coinkite’s CEO, recommended users who have generated seed phrases using Coldcard to move their funds immediately following firmware updates to address the issue.

    Impact on Users

    All Coldcard users are potentially at risk due to this software flaw. Despite the theft, about 90% of the stolen bitcoins remain in the same wallets, indicating that the tokens have not been further moved, sold, or exchanged.

    Information from the investigation has been shared with law enforcement agencies, exchanges, and cyber-investigation groups to track the attackers.

    Aneirin Flynn of FailSafe highlighted the vulnerability of offline crypto storage, emphasizing the importance of robust security measures.

    Recommended Actions

    Users with potentially compromised wallets are advised to transfer their funds to a secure address or a trusted custodian. Coinkite urges customers to install the latest firmware to safeguard new wallets, while existing vulnerable seed phrases should be replaced.

    Galaxy Research emphasized the importance of not generating new seeds on affected models until the update is applied.

    Coinkite assured users that a technical review is ongoing, but experts warn of the challenges in rectifying the situation after the fact.

    Source

    Latest articles

    “Canada’s Air Force to Receive New Air Tanker for Arctic Operations”

    Canada's air force is set to receive its first new air tanker by the...

    “Canadian Ghost Stories: Haunting Tales Revealed”

    As the fall season approaches, embracing all things Halloween becomes a thrilling experience. While...

    “El Niño to Peak by 2027, Bringing Extreme Weather”

    The El Niño weather pattern is expected to strengthen through 2027 and possibly become...

    “Insidious: Out of the Further” Struggles to Sustain Horror Momentum

    The primary challenge of "Insidious: Out of the Further" may lie in the expectation...

    More like this

    “Canada’s Air Force to Receive New Air Tanker for Arctic Operations”

    Canada's air force is set to receive its first new air tanker by the...

    “Canadian Ghost Stories: Haunting Tales Revealed”

    As the fall season approaches, embracing all things Halloween becomes a thrilling experience. While...

    “El Niño to Peak by 2027, Bringing Extreme Weather”

    The El Niño weather pattern is expected to strengthen through 2027 and possibly become...