Hackers Steal Over $100 Million from Coldcard Bitcoin Wallets
Hackers have stolen more than $100 million worth of bitcoins from Coldcard hardware wallets, which are designed for offline cryptocurrency storage. The suspected cause was an error in generating secret phrases for accessing funds.
This was reported by CBC, citing the results of an analysis of bitcoin network transactions and data from cybersecurity experts.
One of the largest waves of thefts occurred on July 30. According to Galaxy Research estimates, in less than 41 minutes, the attackers withdrew over a thousand bitcoins from 1,196 wallets. Researchers later identified additional suspicious transactions.
Estimates of the total damage continue to change as transactions are examined. Some researchers have counted about 1,755 bitcoins stolen from several thousand wallets. The value of these assets at the time of the attacks exceeded $100 million.
Coldcard is a hardware wallet by the Canadian company Coinkite. The device stores private keys separately from internet-connected computers and smartphones, so this storage method is considered more secure than keeping cryptocurrency on an exchange or in a regular software wallet.
However, in this case, the attackers seemingly did not need physical access to the devices. Researchers discovered an error in certain versions of the Coldcard software that could reduce randomness when generating a seed phrase—a set of words that allows access to a wallet to be restored.
Due to insufficient randomness, some of these phrases could have become predictable. Once an attacker obtains a seed phrase, they can independently restore the wallet and transfer the bitcoins it holds, even without the physical device.
The manufacturer acknowledged the error and issued an update. However, simply installing the new software version will not protect wallets whose secret phrases were already created using the vulnerable firmware.
Coldcard owners are advised to install the latest software, generate a completely new seed phrase, and transfer their funds to the new wallet. Importing an old phrase into another device does not eliminate the threat, as the vulnerability is tied to the phrase itself, not the specific hardware wallet.
The company continues to assess the scope of the incident and is collaborating with blockchain analysis specialists and law enforcement authorities. The final number of affected wallets and the exact amount of stolen funds have not yet been confirmed.