Cold Crypto Wallets Hacked: $130 Million Stolen
Hackers have stolen over $130 million in cryptocurrency from users of offline hardware wallets, specifically Coldcard crypto wallets made by Coinkite.
The attack exploited a vulnerability in the seed phrase generation process, making it predictable and allowing threat actors to brute-force victims' passwords via trial and error.
According to a security advisory from Coinkite, the vulnerability has been patched for all affected firmware, and users should install available updates and migrate their wallets to a new seed phrase following specific instructions in the advisory.