Coldcard Hack Exposes Vulnerability in Hardware Wallets, $100M+ Stolen
Coldcard, a Toronto-based company that produces bitcoin-only hardware wallets, has been hacked. The hackers exploited a bug in the software to reconstruct wallet seed phrases, allowing them to drain over $100 million worth of Bitcoin from affected users.
The attack is attributed to a deterministic pseudo-random generator vulnerability that originated in March 2021. Coinkite, the company behind Coldcard, released firmware updates for affected products and advised users to move their funds immediately.
Roughly 90% of the stolen Bitcoin remains in the same wallets where it was sent after the attack, according to Galaxy Research. The research firm warned that hackers could wait before moving the funds, making it difficult for victims to recover their assets.
Experts say that AI-assisted code review can now find latent bugs at a speed that outpaces even seasoned experts. Coinkite's CEO, Rodolfo Novak, acknowledged this reality and advised other developers to assume their firmware is already being read by attackers and defenders alike.