Coldcard Wallets Drained of Over $130 Million in Four Waves
The Coldcard exploit is one of the most significant hacks in recent memory. On July 30, individual Bitcoin holders using Coldcard noticed that their wallets were inexplicably drained. Among them was author Jonathan Goodman, who lost $1.6 million in BTC to the exploit.
Galaxy Research detected suspicious transaction waves in a 41-minute window, hours before Coinkite issued its first advisory regarding the exploit. The vulnerability impacted several models, including the Mk2, Mk3, Mk4, Mk5, and Q. However, Coinkite products built on separate codebases, including Tapsigner, Opendime, and Satscard, were unaffected.
The first wave was detected on July 30, when a hacker or hackers began targeting Bitcoin held in Coldcard hardware wallets. The hackers drained 500 wallets in a 25-minute window during the first wave, siphoning around $38 million to a new address.
The exploit's nature is highly unusual - it wasn't stolen through an elaborate social engineering scheme or the usual phishing or exchange attacks that we usually see. It was a bug that sat undetected for five years, until someone, somehow, discovered it and used it to blindside Coldcard wallet users.