“Coldcard Breach: $100M Bitcoin Heist Sparks Security Concerns”

A recent breach has targeted Coldcard, a bitcoin-only hardware wallet favored by bitcoin users. Hackers managed to siphon off more than $100 million US worth of bitcoin from Coldcard wallets, as revealed by blockchain intelligence firm Galaxy Research. The breach has caused concern among Coldcard users, prompting questions about the impact and necessary security measures.

Coldcard, developed by Coinkite in Toronto, functions as a hardware wallet that does not store bitcoin directly. Instead, it enhances security by keeping “seed phrases” offline within the physical device, adding a protective layer to the public blockchain network where bitcoin resides. These seed phrases, serving as master keys, authorize users to sign transactions and control their bitcoin holdings securely. Marketed as “cold storage,” Coldcard has garnered acclaim for its security features, appealing to long-term bitcoin holders seeking offline key storage.

The breach, first flagged by Coinkite, exposed a software bug enabling hackers to reconstruct wallet seed phrases without physical access to the device. The breach resulted in multiple attack waves, leading to the theft of 1,596 bitcoin from approximately 7,300 addresses, with potential losses reaching 2,055 bitcoin ($130 million US) if additional breaches are confirmed. The culprits behind the attacks remain unidentified, raising concerns within the cryptocurrency community.

Coinkite quickly responded by advising users to transfer their funds and issued firmware updates to mitigate the vulnerability. In a subsequent update, Coinkite acknowledged the flaw’s origin in March 2021 due to reliance on a deterministic pseudo-random generator instead of a secure hardware-backed random number generator. The company has taken steps to address the issue, emphasizing the importance of prompt action to safeguard affected users’ assets.

To ensure security, Coldcard users are urged to update their firmware, especially for wallets created after the fix, as existing vulnerable seed phrases remain at risk. Galaxy Research emphasized the importance of not generating new seeds on susceptible models until updates are applied. Despite ongoing investigations and technical reviews, the breach’s repercussions highlight the challenges faced by affected users and the need for vigilance in the evolving cybersecurity landscape.

The breach underscores the vulnerability of cryptocurrency assets and the importance of proactive security measures. Affected Coldcard users are advised to consider moving their funds to secure addresses or platforms, while preserving the affected devices for potential recovery efforts. The incident serves as a reminder of the risks associated with digital assets and the critical role of user vigilance in safeguarding investments.

Latest articles

Related articles