Coldcard Hack Exposes Vulnerability in Hardware Wallet Security
A major security breach has hit the Coldcard hardware wallet, allowing hackers to drain over $100 million worth of Bitcoin from affected users. The vulnerability, which was first introduced in March 2021, allowed attackers to reconstruct wallet seed phrases, granting them access to user funds.
Coinkite, the Toronto-based company behind the Coldcard, has acknowledged the flaw and released firmware updates to address the issue. However, experts warn that existing seed phrases generated on vulnerable devices remain at risk and should be replaced.
Roughly 90% of the stolen Bitcoin remains in the same wallets where it was sent after the reported theft, according to Galaxy Research. This means that hackers could wait before moving the funds, making it essential for affected users to take action to secure their cryptocurrency.