Coldcard Hack Exposes Vulnerability in Bitcoin Wallets
A devastating Bitcoin hack has left thousands of investors reeling after thieves made off with an estimated $111 million in stolen funds. The attack, linked to a firmware bug in Coldcard devices, allowed hackers to guess investor seedphrases and drain wallets.
According to Galaxy Research's analysis of victim reports, the median loss was a staggering 1 BTC, with individual victims reporting losses ranging from 0.014 to 58.97 coins. The data revealed that the stolen funds were largely from long-dormant wallets, with a striking 88% of pilfered funds being at least a year old.
The hack began last week Thursday, with thieves making off with $35 million in Bitcoin from wallets. Coinkite, the maker of Coldcard, admitted that a firmware bug starting with version 4.0.1 in March 2021 caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator.
Coinkite and other Bitcoiners urged users to immediately move their funds, but not before hackers continued stealing throughout the weekend. The total losses are expected to exceed $130 million, with Galaxy Research stating that many more coins are being vetted for confirmation.