Coldcard Security Breach Exposes Weaknesses in Self-Custody
A significant security breach has affected users of Coldcard hardware wallets, leading to the theft of over $83 million in Bitcoin. The vulnerability, which was caused by a firmware flaw, allowed hackers to remotely access and drain wallet funds without requiring physical access to the device.
The bug, which was introduced in 2021 and went unnoticed until this year, affected firmware versions 4.0.1 through 4.1.9. This meant that users who generated recovery seeds during this time period had passwords that were incredibly weak, making them vulnerable to remote cracking.
Coldcard manufacturer Coinkite has since released a firmware update and urged all affected users to regenerate their seeds immediately. The company has also recommended using strong BIP-39 passphrases as an additional layer of protection.