Coldcard Wallet Hackers Drain $130M from 7,300 Devices
A major vulnerability in Coldcard hardware wallets has led to an estimated $130 million in losses from over 7,300 affected devices. The issue stems from a firmware flaw that allows hackers to brute-force guess private keys with low entropy, allowing them to drain BTC balances.
The problem began last week when Coinkite, the manufacturer of Coldcard wallets, discovered the vulnerability and issued an advisory. However, it appears that the threat is still active, with Galaxy Research reporting 15 separate attackers draining BTC from vulnerable wallets.
The hackers are keeping most of their stolen coins, with only 10% having moved so far. Law enforcement departments around the world are investigating the activity. Coinkite has shipped hotfixes for affected models and warned that updating firmware does not repair seed phrases generated by affected firmware.