Coldcard Hackers Drain Over $89M in 41 Minutes
Security researchers have discovered a software flaw in Coldcard, a handheld device used to store Bitcoin offline. The issue may have allowed hackers to steal nearly $89 million worth of cryptocurrency from over 1,000 digital wallets in just 41 minutes on July 30.
The vulnerability involves a coding mistake that weakened one of the wallet's key security features, allowing sophisticated attackers to figure out recovery phrases and gain access to user funds. Coinkite, the company behind Coldcard, has released a software update to prevent the problem from affecting newly created wallets.
However, users who already created their recovery phrase using affected software are advised to create a brand-new recovery phrase using the updated software and move their Bitcoin into the newly secured wallet. This is because simply installing the update will not repair a seed that was generated by affected firmware.
Coinkite CEO Rodolfo Novak has apologized for the issue, stating that the company is 'heartbroken' and taking 'full accountability.' He urges customers to act immediately and move their funds using the updated best practices.