Coldcard Wallet Flaw Exposes Users to $89M in Potential Losses
A security flaw in the Coldcard wallet has potentially drained nearly $89 million from over 1,200 digital wallets in just 41 minutes. According to researchers at Galaxy Research, hackers exploited a coding mistake in certain versions of the wallet, allowing them to steal bitcoin without ever physically touching the device.
The issue involves a hardware wallet used by many cryptocurrency investors to store their bitcoin offline instead of leaving it on an exchange. Block's Bitcoin Engineering and Security team published a security advisory stating that the software bug may have weakened one of the wallet's key security features, making recovery phrases predictable enough for sophisticated attackers to figure them out.
Coinkite, the company behind Coldcard, has since released a software update to prevent the problem from affecting newly created wallets. However, the company warned that simply installing the update will not protect people who already created a recovery phrase using the affected software.
Coinkite CEO Rodolfo Novak apologized for the issue and urged customers to create a brand-new recovery phrase using the updated software and move their bitcoin into the newly secured wallet. The company is still working to determine exactly how many people may have been affected and plans to publish a detailed explanation of what went wrong after its investigation is complete.