Coldcard Wallet Hack Exposes $89 Million Vulnerability
Hackers have stolen nearly $89 million from thousands of cryptocurrency addresses linked to vulnerable Coldcard hardware wallets. The attack occurred in three waves, beginning on July 30, with a first wave draining 1,082.65 BTC from 1,195 addresses in just 41 minutes.
The second wave lasted three hours and 42 minutes and removed another 76.16 BTC from 1,478 addresses, but affected more addresses despite involving significantly less Bitcoin. The third wave drained another 207.73 BTC, bringing the total estimated loss to about $88.6 million.
A flaw in the process used to generate wallet seed phrases was identified as the cause of the vulnerability. Coinkite, the manufacturer of Coldcard wallets, found that a software-based pseudorandom number generator was used instead of the device's hardware random number generator, reducing the unpredictability of some seed phrases.
Affected users have been advised to install the corrected firmware and create a completely new seed phrase before transferring their funds to a new wallet. Coinkite warned that simply updating a Coldcard device does not fix a seed phrase generated using vulnerable firmware.