Coldcard Hackers Drain $110M in Bitcoin from Offline Wallets
Hackers have exploited a software flaw in Coinkite Inc.'s Coldcard devices to steal tens of millions of dollars' worth of Bitcoin. The attack, which began last week, has compromised over $110 million's worth of tokens from roughly 5,000 wallets.
The vulnerability was discovered in the keys that protect users' Bitcoin, and Coinkite has since released a software update to fix the issue. According to Block Inc.'s engineers, the problem arose from how Coinkite implemented the random number generator to form seed phrases used to log in to wallets.
Coldcard devices are considered one of the safest places to store cryptocurrency, as they are isolated from the internet and use 'cold' storage. However, the security flaw has shown that even these secure methods can be compromised with the right tools and expertise.