Coldcard Hackers Drain Millions in Predictable Bitcoin Heist
Hackers have compromised thousands of Coldcard devices, allowing them to drain tens of millions of dollars in Bitcoin from over 4,500 wallets.
The attack targets a security flaw in the software that generates seed phrases for these 'cold' wallets, which are considered some of the safest places to store cryptocurrency.
According to Galaxy Research, roughly $86 million (S$110 million) has been drained from affected wallets since late last week. The losses climbed rapidly over the weekend, with reports placing the total at around $38 million on July 31.
The vulnerability was discovered in how Coinkite implemented the random-number generator when producing seed phrases, according to Block's engineering team. This resulted in keys being generated using deterministic values such as device serial numbers, making it possible for attackers to recalculate and drain user wallets.