Coldcard Hack Exposes Flaw in Bitcoin Storage Security
Canada-based Coinkite Inc., makers of the Coldcard device, recently notified users that a security flaw had compromised some Bitcoin wallets. The issue was caused by a predictable 'seed phrase' used to access wallets, which is generated by the device's software. This flaw allowed hackers to systematically recalculate and drain user wallets.
The attack has been ongoing since July 29th, with over $86 million in losses reported from more than 4,500 affected wallets. A report from Galaxy Research found that roughly 1,367 tokens were drained during this period. Coldcard devices are considered one of the safest places to store Bitcoin due to their isolation from the internet.
Cybersecurity experts have weighed in on the implications of the attack, with some arguing that self-custody does not remove risk. Aneirin Flynn, CEO of Failsafe, stated, 'It exposes the fallacy of your crypto being offline.' The incident has also raised concerns about the complexity and security of cryptocurrency storage solutions.