Coldcard Wallet Bug Steals $70 Million from Bitcoin Holders
Researchers at Galaxy Digital have identified an exploit in the popular Bitcoin wallet Coldcard that has resulted in over $70 million being stolen from users. The attack was made possible by a firmware bug that reduced the randomness of how the wallet generates its secret recovery phrase.
The majority of the funds were stolen within less than an hour, and the researchers noted that the vast majority of the affected addresses are those with smaller balances, between 1-50 BTC in value. This suggests that individual self-custody holders were disproportionately affected by the attack.
CoinKite, the company behind Coldcard, has taken full accountability for the firmware bug and has apologized to affected users. The company has released emergency firmware updates to address the issue, but warns that a firmware update alone will not secure existing seeds - users must generate an entirely new recovery phrase on the fixed firmware and migrate their BTC.