Coinkite's Coldcard Wallets Hit by $88 Million Security Breach
A significant security event has struck the Bitcoin community, resulting in the theft of over $88 million worth of cryptocurrency. This incident occurred due to a flaw in the internal software of Coldcard hardware wallets, which are manufactured by Coinkite.
The vulnerability allowed attackers to generate private keys with an excessively low level of randomness, making them more predictable and vulnerable to reconstruction using computing power and automated scanning. In some cases, this resulted in funds being stolen from affected addresses within a short period.
According to researchers, the bug entered the code in version 4.0.0, which was released in March 2021, and remained in subsequent versions for years. The extent of exposure varies among different Coldcard models, with older models such as the Mk2 and Mk3 being particularly vulnerable.
The incident serves as a reminder that even cold wallets are not foolproof and require users to exercise caution and vigilance when managing their funds.