Coldcard Exploit Triggers $130M in Stolen BTC, Exchanges See Massive Influx
A major security exploit in Coldcard hardware wallets has led to the theft of at least $130 million worth of Bitcoin. The flaw, which dates back to March 2021, allowed attackers to reconstruct private keys remotely without obtaining the device or recovery words.
Galaxy Research reported that at least three major attack waves and 14 smaller incidents have resulted in the loss of around 1,596 BTC from approximately 7,300 addresses. The firm has also identified a possible fourth wave, which could increase the total losses to 2,055 BTC.
The exploit affects users who generated recovery seeds using a weaker software process instead of drawing sufficient randomness from the hardware random-number generator. Updating the firmware prevents new weak seeds from being created, but it cannot protect wallets that already have vulnerable recovery phrases.
Coldcard's manufacturer, Coinkite, has urged users to install the security update and create a new seed to transfer their Bitcoin. However, this process can be complex and may leave users exposed to phishing attempts and scammers seeking to obtain their recovery words directly.