Coldcard Exploit Drains $70M in BTC from Over 1,200 Addresses
A key-generation flaw in Coldcard hardware wallets has led to over $70 million in losses as approximately 1,000 BTC were drained from roughly 1,200 addresses.
Coldcard, a popular choice among Bitcoin enthusiasts for its advanced security features, was found to have a vulnerability that allowed attackers to derive private keys without physical access to the devices.
The attack is believed to have occurred over an extended period and affected users who used a specific firmware version or configuration. Galaxy Research's findings indicate that the exploit likely targeted users who did not update their firmware.
Coldcard has released patches and urged users to upgrade their firmware, but the incident highlights the need for ongoing vigilance in self-custody solutions. Even hardware wallets are not immune to sophisticated attacks, underscoring a growing concern in the cryptocurrency community.