Coinkite Bitcoin Wallet Hack Exposes Vulnerability in Self-Custody
A major vulnerability in Bitcoin wallets has left holders shaken and re-evaluating their storage options. Hackers exploited a coding error in hardware wallets made by Coinkite Inc., stealing over $140-million worth of Bitcoin in the past week.
Vancouver-based cybersecurity analyst Eric Chennells said, 'There is a lot of soul-searching and re-evaluating going on. The bug was just shockingly bad.'
The vulnerability, which affected Coinkite's Coldcard wallets, allowed hackers to guess seed phrases used as master keys for the wallets.
Seed phrases are meant to be generated with high randomness from a huge pool of potential seeds, but the coding error introduced in 2021 made them easier to guess. The bug was discovered by attackers who could use the easily-guessed seed phrases to determine wallet keys and find ones containing Bitcoin.
Coinkite has destroyed its remaining inventory of vulnerable Coldcard wallets and issued software patches to prevent further loss, but some investors are rethinking their storage options.