Coldcard Wallet Hack Exposes Thousands of Users to Bitcoin Theft
Security researchers have discovered a software flaw in Coldcard, a popular Bitcoin storage device, that may have allowed attackers to steal up to $89 million from over 1,200 digital wallets. The issue involves a coding mistake in certain versions of Coldcard that made some recovery phrases predictable, potentially allowing hackers to access users' Bitcoin without physically touching the wallet.
The vulnerability was first reported by Forbes and was later confirmed by Block's Bitcoin Engineering and Security team. Coinkite, the Canadian company behind Coldcard, released a software update to prevent new wallets from being affected but warned that installing this update will not protect existing users who created their recovery phrase using the vulnerable software.
Coinkite is urging these users to create a brand-new recovery phrase and move their Bitcoin into the newly secured wallet. The company's CEO, Rodolfo Novak, apologized for the issue and took 'full accountability' for the firmware bug. He also warned that customers who created their recovery phrase using at least 50 private dice rolls are not affected by this specific flaw alone.