Hackers Drain $110M from Coinkite Coldcard Wallets
A security flaw in Coinkite Inc.'s Coldcard devices has allowed hackers to drain tens of millions of dollars from Bitcoin wallets. The attack, which began last week, has seen over $110 million stolen from around 5,000 wallets.
The Coldcard is a type of 'cold' wallet, designed to be isolated from the internet and considered one of the safest places to store cryptocurrency. However, a flaw in the device's software meant that the generated seed phrase, used to access the wallet, was predictable.
Aneirin Flynn, CEO of cybersecurity firm Failsafe, said 'the device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.'
The attack has highlighted the risks of self-custody, which moves the risk to the user rather than removing it. Ari Redbord, global head of policy at TRM Labs, said 'coldcard shows that self-custody moves the risk, it does not remove it.'