South Korea's Unique Approach Mitigated $130M Coldcard Wallet Hack
The recent Coldcard hardware wallet attack exposed seed phrases to attackers through a flaw in random-number generation, resulting in losses exceeding 1,596 BTC worth $130 million. However, South Korean Bitcoiners appear to have suffered minimal direct losses from the incident.
Coldcard manufacturer Coinkite destroyed remaining batches of vulnerable devices and urged users to generate new seed phrases after the attack. According to independent estimates, around 7,300 addresses may have been affected, with potential losses reaching up to 2,000 BTC when suspected cases are included.
South Korea's relatively low losses were attributed by analyst Koji Higashi to a long-standing habit among Korean Bitcoin users of generating seed phrases independently rather than fully trusting a hardware wallet's built-in randomness. This practice involves simple methods such as rolling dice or flipping coins to generate randomness, and creating BIP39 mnemonics completely offline.
Higashi suggested that the difference in losses between English-speaking and Korean communities may be partly due to how information and recommendations circulate within those communities. He noted that influential Bitcoin personalities in English-speaking communities often have sponsorship arrangements or close relationships with hardware-wallet manufacturers, which can make product recommendations appear more trustworthy than they otherwise would.
The broader lesson from this incident is the importance of verifying information rather than blindly trusting it, including advice from software and hardware vendors. This principle applies not only to software and hardware but also to people and sources recommending them.