Coldcard, a bitcoin-specific hardware wallet, has recently fallen victim to a data breach with hackers absconding with over $100 million in bitcoin from Coldcard hard wallets, as reported by Galaxy Research, a blockchain intelligence firm. Coldcard, developed by Coinkite based in Toronto, acts as a hardware wallet but does not store bitcoin; instead, it enhances security by storing “seed phrases” offline within the physical device, disconnected from the Internet, while the bitcoin remains on the public blockchain network.
The “seed phrases” serve as intricate codes allowing users to authorize transactions and sign as the bitcoin owners. Marketed as “cold storage” for long-term bitcoin holders seeking offline key security, Coldcard has been highly acclaimed by both users and security experts as one of the most secure options for bitcoin storage.
The breach was announced by Coinkite on Thursday, revealing a software bug that enabled hackers to reconstruct the wallet “seed phrases.” Subsequently, several attack waves exploited this vulnerability, resulting in the theft of 1,596 bitcoin from approximately 7,300 addresses, with a potential increase to 2,055 bitcoin if a fourth wave is confirmed, translating to around $130 million. The perpetrators behind the attacks remain unidentified.
All Coldcard users face the risk of potential wallet compromise due to this software flaw. Despite the theft, about 90% of the stolen bitcoin remains unmoved in the original wallets, indicating that the tokens have not been transferred, sold, or exchanged further. Ongoing investigations have shared details with U.S. law enforcement, cryptocurrency exchanges, and cyber-investigation groups to track the attackers and safeguard users.
For affected users, it is advisable not to keep compromised bitcoin in their wallets and to install Coldcard’s latest firmware update for post-fix wallets, as existing seed phrases generated on vulnerable devices are still at risk and should be replaced. Coinkite urges customers to update their devices promptly and avoid generating new seeds until the fix is installed. The company’s investigation is ongoing, and a formal technical review is forthcoming.
However, experts warn that rectifying the situation may be challenging for users who may be unaware of the issue until it is too late. Affected Coldcard users are encouraged to transfer their funds to a secure address at a custodian/exchange or generate a fresh seed. Coinkite advises against disposing of affected devices as they may be essential for fund recovery efforts in collaboration with law enforcement agencies.
