Coldcard Attack Wave Swells to $114 Million as Fourth Wave Hits
A firmware bug that was shipped in March 2021 has led to a series of attacks on Coldcard hardware wallets, resulting in an estimated $114 million in losses. The bug made seeds generated on affected devices guessable, allowing attackers to drain funds without needing the device's private key.
The latest wave of attacks began on Monday and has seen 448.7 BTC swept from 709 potential victim addresses at a rate of 13.8 sweeps per block. This brings the estimated total to about $114 million in losses since Thursday, with over 1,816 BTC drained from more than 5,200 addresses.
Coldcard maker Coinkite has released emergency firmware for every affected model and is urging users to move their funds to a freshly generated seed. The company halted shipments as soon as it confirmed the vulnerability and destroyed all remaining units at its facilities with affected firmware installed.