Hackers steal over $114 million in Bitcoin from Coldcard wallets
A large-scale cyber attack is hitting Coldcard hardware wallets, with a loot now estimated at over $114 million in Bitcoin. The latest wave of thefts, which began Sunday evening, saw the transfer of 388.9 Bitcoin, worth approximately $29 million, according to Alex Thorn of Galaxy Research's analysis.
The attack started Thursday with the theft of over $35 million in Bitcoin. Coinkite, the company that produces Coldcard, identified the cause as a firmware bug in Mk3 versions starting from March 2021. The malfunction forced the system to use a software pseudorandom number generator instead of the hardware random number generator, allowing hackers to guess users' seed phrases.
Quick Response
- Over $114 million in Bitcoin has been stolen from Coldcard wallets
- The firmware bug made Mk3 devices vulnerable since 2021
- Coinkite has destroyed remaining inventory and suspended shipments
- Hackers used a blockchain service provider to move the funds
The scale of the attack
The largest transaction recorded during the attack involved 51 Bitcoin, according to Josef Tětek of Trezor. Coinkite later admitted that all Coldcard models were vulnerable, with engineers warning that all associated Bitcoin addresses could be at risk.
Coinkite's response
The company stated Sunday that it is "asking ourselves hard questions about our company," acknowledging the devastating impact of the attack. "The past three days have been among the hardest in our company's history, and for many of you reading this, they have been something far worse," Coinkite said.
The company added that it has destroyed all remaining inventory of Coldcard produced with the vulnerable firmware and has suspended all shipments. Coinkite produces several Bitcoin products, including popular hardware wallets for cold storage.
Block's investigation
Engineers at Block, the payment company, investigated the attack and discovered that hackers used a major blockchain service provider to help move the stolen funds. Block contacted the provider and federal authorities with the results of their investigation.
The firmware vulnerability
The firmware bug caused a critical malfunction in the seed generation process. Instead of using the hardware random number generator, the device resorted to a less secure software pseudorandom number generator. This allowed hackers to guess users' seed phrases and access their funds.
Consequences for users
Coldcard users were advised to immediately transfer their funds. However, the attack had a significant impact on many users, with Coinkite acknowledging that "the money they saved for years is gone, the trust they built for years is broken."
Security measures
Coinkite took immediate measures to contain the situation, including destroying remaining inventory and suspending shipments. However, engineers warned that all Bitcoin addresses associated with Coldcard could be at risk, suggesting that users should take additional precautions to protect their funds.
The importance of firmware security
This attack underscores the critical importance of firmware security in cold storage devices. Hardware random number generators are considered more secure as they are less susceptible to software manipulation. The malfunction in Coldcard's firmware created a vulnerability that hackers exploited to steal millions of dollars in Bitcoin.
Implications for the industry
The attack has important implications for the hardware wallet industry. It highlights the need for strict security protocols and thorough testing to prevent vulnerabilities that can be exploited by hackers. Additionally, it emphasizes the importance of transparency and quick communication with users in case of security breaches.
Legal actions and investigations
Block contacted a major blockchain service provider and federal authorities with the results of their investigation. This suggests that legal actions may be underway to pursue the hackers and recover the stolen funds. Federal authorities may also conduct their own investigations to determine the scope of the attack and identify the perpetrators.
Lessons learned
The attack on Coldcard wallets offers important lessons for cryptocurrency users and the industry as a whole. It underscores the need for robust security, transparent communication, and a rapid response in case of breaches. Additionally, it highlights the importance of using reliable cold storage devices and keeping security measures up-to-date to protect funds from cyber attacks.
The current situation
At the moment, Coinkite is working to resolve the issue and restore user trust. The company has suspended shipments and is asking itself hard questions about its operations. Users are advised to transfer their funds and take additional precautions to protect their assets. The cryptocurrency industry is closely watching the situation, with the expectation that further details about the attack and its implications will emerge.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.