Coldcard Hack Exposes Vulnerability in 'Most Secure' Bitcoin Storage
A vulnerability in Coldcard devices has led to a significant Bitcoin heist, with hackers exploiting a software flaw to steal around $100 million worth of BTC. The bug was found in the seed phrase generator, which is meant to be an unguessable string of words acting as the master key to users' private keys.
Coldcard devices were considered one of the most secure ways to store Bitcoin, but this breach has shattered that illusion. According to Coinkite, the Toronto-based company behind Coldcard, hackers could reverse-engineer seed phrases without needing to access the physical device itself.
A user who claimed to have lost $1.6 million in the breach stated that their Coldcard was stored in a safety deposit box and never connected to the internet, but the vulnerability proved fatal despite these precautions.