A recent security breach has impacted users of Coldcard, a bitcoin-only hardware wallet known for its security features. Hackers managed to steal over $100 million worth of bitcoin from Coldcard wallets, exploiting a software bug that allowed them to reconstruct users’ “seed phrases.”
The seed phrases are crucial as they serve as the master key to the bitcoin wallet, enabling users to authorize and sign transactions. The breach has resulted in the theft of approximately 1,596 bitcoins from around 7,300 addresses, with the potential for further losses if additional attack waves are confirmed.
Coinkite, the company behind Coldcard, has advised users to move their funds immediately and update their device firmware to protect against further vulnerabilities. The company acknowledged the flaw in its software and emphasized the importance of taking proactive steps to secure cryptocurrency assets.
The stolen bitcoins have not been moved or exchanged yet, indicating that the hackers may be waiting before taking further action. The ongoing investigation involves sharing details with law enforcement agencies and cyber-investigation groups to track down the attackers and prevent future incidents.
Users are urged to be cautious and consider migrating their funds to a secure address or seeking assistance from reputable custodians or exchanges. Coinkite is working on a technical review to address the breach and collaborate with authorities to identify those responsible for the hack.
