For individuals using bitcoin, Coldcard, a bitcoin-only hardware wallet, has recently experienced a data breach resulting in hackers siphoning over $100 million US worth of bitcoin from Coldcard hard wallets, as per Galaxy Research, a blockchain intelligence firm.
An ongoing investigation is shedding light on this hack, the affected parties, and the necessary steps to safeguard your cryptocurrency.
Understanding Coldcard’s Functionality
Coldcard, developed by Coinkite, a Toronto-based company, serves as a hardware wallet that does not store bitcoin directly. Instead, it enhances security by storing “seed phrases” offline within the physical device, disconnected from the Internet, while the actual bitcoin remains on the public blockchain network.
The “seed phrases” are complex sequences of random words functioning as a master key for the bitcoin-only wallet, enabling users to authorize and sign transactions as the bitcoin owner.
Often marketed as a secure long-term storage solution for bitcoin holders aiming to keep their keys offline, Coldcard has garnered praise from users and security experts for its robust security features.
Incident Overview
Coinkite issued a warning to users regarding a software bug that allowed hackers to reconstruct wallet “seed phrases,” leading to unauthorized access to users’ bitcoin wallets without physical possession of the device.
Galaxy Research reported that the breach resulted in 1,596 bitcoin stolen from approximately 7,300 addresses through three confirmed attack waves and additional smaller incidents. In case a fourth wave is confirmed, the total loss could reach around 2,055 bitcoin, equivalent to roughly $130 million US.
The attackers’ identities remain undisclosed.
Coinkite’s CEO, Rodolfo Novak, advised Coldcard users to transfer their funds immediately if they generated a seed using an affected device, following the release of firmware updates to address the issue.
Novak acknowledged the flaw’s origin in March 2021, involving the use of a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator for generating wallet seeds.
User Impact
All Coldcard users face potential risks due to the software vulnerability, with about 90% of the stolen bitcoin remaining inactive in the same wallets since the theft, as per Galaxy Research.
Investigative details, including attacker and victim addresses, have been shared with U.S. law enforcement agencies, cryptocurrency exchanges, and cyber-investigation groups by Galaxy Research to track down the perpetrators.
Experts emphasize the importance of taking immediate action if users suspect their wallets are compromised, emphasizing the installation of updated firmware and replacement of vulnerable seed phrases.
Recommended Actions
Users are advised not to keep their bitcoin in compromised wallets and to install the latest Coldcard firmware for protection. Existing seed phrases generated on vulnerable devices should be replaced, and users are urged not to generate new seeds until the update is implemented.
Coinkite is conducting an investigation with plans to release a formal technical review soon, although the impact of the breach has already been felt.
Affected users have the option to transfer their funds to secure addresses at custodians or exchanges, as suggested by Galaxy Research.
Coinkite recommends retaining affected devices in case funds are recovered, with legal cooperation across jurisdictions to identify the responsible parties.
