Coldcard Hack Exposes Vulnerability in Hardware Wallet Security
A recent hack of Coldcard Bitcoin wallets has left investors reeling, with victims reporting a median loss of over one coin. According to an analysis by Galaxy Research's Alex Thorn, which looked at 250 victim reports, the typical stolen coin had sat untouched for 3.5 years, and a striking 88% of pilfered funds were at least a year old.
The hack started with $35 million in Bitcoin stolen from wallets last week Thursday, but Coinkite warns that the number could be much higher. Galaxy Research estimates total losses to likely exceed $130 million, as they continue their research and vetting of confirmed thefts.
Coinkite attributed the hack to a firmware bug in Coldcard Mk3 devices starting with version 4.0.1 in March 2021, which caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator. As a result, hackers were able to essentially guess investor seedphrases.
Since the attack, cautious investors have been moving their coins to other storage solutions, including exchanges. Coinkite has urged Coldcard users to immediately move their funds and update their software, while Galaxy Research is still investigating and confirming losses.