top of page

Coldcard hardware wallet vulnerability: Hackers steal over $130 million in cryptocurrency

Storing cryptocurrency on offline devices (hardware wallets) has long been considered a top-tier security practice. However, a critical security vulnerability recently left many Coldcard wallet users completely drained of their assets, with total losses exceeding $130 million.

Attack vector on offline storage devices

Unlike online hot wallets (such as mobile apps, browser extensions, or accounts on exchanges like Binance and Coinbase), the Coldcard hardware wallet, produced by Coinkite, operates completely isolated from the internet. This device allows Bitcoin owners to store private keys or seed phrases - essentially offline password sequences used to manage assets on the blockchain.

However, security experts at Block discovered a flaw in Coldcard's seed phrase generation process that made these password sequences predictable. Identifying the underlying pattern, hackers only needed to use brute-force methods (automated trial-and-error software) to generate seed phrases matching those of victims. Knowing how the keys were generated meant attackers could effectively "forge master keys en masse" without needing to tamper with or physically access the actual devices.

Scale of damage and the threat actors behind it

According to reports from research firm Galaxy Research, the stolen amount is estimated at around $130 million. Tom Robinson, co-founder and chief scientist at monitoring firm Elliptic, also confirmed to TechCrunch that this figure closely reflects reality.

Analyses show that there is not a single perpetrator; currently, at least 12 different hackers or threat groups are exploiting this vulnerability to target Coldcard users. Notably, data from analytics firm TRM Labs reveals that since the beginning of the year, the cryptocurrency market has recorded over 200 cyberattacks, with total damages exceeding $950 million.

Helpless victims despite following all security rules

This incident has left users completely powerless. Jonathan Goodman, a victim who lost $1.6 million, shared on the social media platform X that he had followed every security instruction to the letter: he never shared his seed phrase, the device was never connected to the internet, and it remained sealed inside multiple safes.

Despite this, all physical protection measures proved useless. The root cause stems from a buggy line of code written in 2021 within the hardware responsible for initial seed phrase generation.

Urgent update recommendation from the manufacturer

Given the severity of the situation, Coinkite issued a security advisory warning users on Thursday and provided further updates on Saturday. The manufacturer strongly urges all Coldcard owners to immediately upgrade their firmware and transfer all assets to an entirely new seed phrase.

coldcard-devices
The manufacturer urges all customers owning Coldcard devices to immediately perform a firmware upgrade and transfer all assets to an entirely new seed phrase

This incident serves as a stark reminder that even the most robust offline storage solutions can carry inherent risks stemming from initial code flaws. Coldcard users must act quickly according to the manufacturer's instructions to safeguard their assets.

Reference:

Hackers steal over $130M by exploiting bug in offline hardware wallets - TechCrunch

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page