Coldcard Hack Nears $110M as Wave 4 Hits Bitcoin Wallets
A security flaw in Coldcard's firmware has led to a multi-day theft, with losses nearing $110 million in bitcoin. The incident is one of the largest known losses tied to a hardware wallet vulnerability and highlights a fundamental risk in cryptocurrency security.
The attack began on July 30, when attackers moved over 1,000 BTC from nearly 1,200 wallets in under an hour. Since then, three subsequent waves have followed, with the latest wave pilfering $24.53 million from 462 addresses across 218 transactions.
Galaxy Research's head of research, Alex Thorn, warned that hackers may be launching a fourth coordinated attack, citing a 'fingerprint' of an automated pipeline working through a pre-computed list of vulnerable keys against the live mempool.
The vulnerability was introduced in a March 2021 firmware release and affects certain Coldcard Mk3 versions. Coinkite released emergency firmware to prevent the issue from affecting newly generated wallets, but has warned that the update does not repair seeds already created on vulnerable firmware.