Coldcard Hack Exposes Vulnerability in Bitcoin Hardware Wallets
A bug in Coldcard's software has allowed hackers to steal over $100 million worth of Bitcoin from users' wallets. The Toronto-based company Coinkite warned its users about the vulnerability, advising them to 'move your funds now.'
Coldcard is a hardware wallet that stores seed phrases offline, without needing an internet connection. These seed phrases act as master keys to the Bitcoin-only wallet.
The bug allowed hackers to reconstruct wallet seed phrases, allowing them access to users' bitcoin wallets without physically obtaining the device. As of Monday, Galaxy Research reported three confirmed attack waves and a number of smaller incidents resulting in 1,596 Bitcoin stolen from roughly 7,300 addresses.
Coinkite's CEO Rodolfo Novak acknowledged that the exploited flaw originated in March 2021 and that the company has released firmware updates for affected products. However, experts warn that users should not rely solely on these updates to secure their funds.