Coldcard Hackers Strike for Over $112 Million
Galaxy Research has confirmed that hackers stole at least 1,778.84 BTC (approximately $112.7 million) by exploiting vulnerabilities in Coldcard hardware wallets.
The attack began on July 30 and continued until August 6, with the attackers systematically recovering seed phrases generated by vulnerable devices and moving funds to addresses they controlled.
The vulnerability was caused by a software bug introduced in 2021 when Coinkite updated device firmware, changing the cryptographic entropy generation mechanism. The flaw allowed attackers to reproduce private keys generated on vulnerable devices using enough computing resources.
Galaxy Research found that multiple actors exploited the vulnerability at the same time and suggested that owners of vulnerable wallets may have moved funds to new addresses or that most accessible funds have already been stolen, leading to a pause in new attacks.