$130 Million Stolen from Offline Cryptocurrency Wallets Amid Ongoing Hack
More than $130 million in cryptocurrency has been stolen from users of offline hardware wallets called Coldcard, devices designed to keep digital assets safe. Hackers have exploited a vulnerability in the seed phrase generation process, allowing them to brute-force users' passwords and gain access to their wallets. This attack is part of a larger trend: hackers carried out over 200 crypto attacks between January and July this year, resulting in losses of $972 million.
Coldcard wallets are considered 'cold,' meaning they're not connected to the internet or other devices, making them a supposedly secure option for storing cryptocurrency. However, the vulnerability has now been patched with firmware updates available on Coinkite's official download pages. Users should update their devices and migrate their wallets to new seed phrases following specific instructions.
Using cold wallets provides some protection, but experts recommend a diversified storage strategy to minimize losses in case one wallet is compromised. This includes leaving minimal assets in hot wallets at any given time.