Coldcard Hack Exposes Flaw in Cryptocurrency Storage Solutions
A devastating cyberattack has rocked the cryptocurrency community, resulting in the theft of over $116 million from Bitcoin owners who use Coldcard devices for secure storage. Since Thursday, four waves of thefts have affected more than 5,200 individual addresses, with hackers moving approximately 1,816 Bitcoin off those wallets. The attack highlights a critical flaw in Coldcard's process that allows attackers to guess recovery phrases and unlock real wallets.
The vulnerability is rooted in a 2021 software update that changed the way Coldcard generated its recovery phrase, a series of random words that provide a means of regenerating the dozens of characters that make up a Bitcoin address. The devices stopped using strong, unpredictable randomness to generate phrases, instead taking a shortcut process that follows patterns.
Coinkite, the Canadian technology firm behind Coldcard, has strongly advised users who generated a wallet seed on these devices to move their funds as soon as possible. This advice comes as the price of Bitcoin and Ethereum contained less than a 1% drop since Thursday.