Coldcard Hack Exposes Flaw in Self-Custody Security
A $116 million Bitcoin hack has left owners stunned and devastated after it was revealed that the security breach was caused by a flaw in the Coldcard hardware wallet's firmware. Jonathan Goodman, one of the affected users, took to social media to express his shock and disappointment, stating 'I did everything right.'
The attack occurred on July 29, with an attacker making off with approximately $116 million worth of Bitcoin. The breach was attributed to a build setting that disabled the device's dedicated hardware randomness chip, allowing attackers to enumerate seeds generated using the Coldcard firmware version 4.0.0.
Coinkite, the manufacturer of the Coldcard wallet, issued an advisory urging users to migrate their funds immediately. The company acknowledged that the breach was caused by a 'human engineering failure' and vowed to conduct a thorough technical review.
The incident has sparked heated debate within the crypto community, with some experts arguing that open-source firmware is not inherently more secure than closed-source alternatives. Others have pointed out that users were left vulnerable due to their reliance on self-custody solutions.