Coldcard Bitcoin Wallet Hacked, $89 Million Stolen from Users
The popular Bitcoin hardware wallet, Coldcard, has become the target of cyberattackers exploiting a firmware vulnerability dating back to 2021. Approximately $89 million worth of Bitcoin has been stolen, and the attack is reportedly ongoing.
What Happened
The cryptocurrency world has been shaken by a large-scale cyberattack targeting hardware wallets, considered one of the most secure methods of storage. Coinkite's Coldcard, a Bitcoin-only hardware wallet known for its security-focused design, is at the center of a wave of attacks that began on July 30 and is reportedly still ongoing. According to researchers, attackers have exploited a vulnerability to steal an estimated $89 million worth of Bitcoin from users' accounts so far.
Analysis by cybersecurity and blockchain analytics firm Galaxy Research revealed that the initial wave of the attack occurred on July 30 within a very short timeframe. In just 41 minutes, a total of 1,082.65 Bitcoin (approximately $70 million at the time) was stolen from 1196 different addresses. The funds were traced to four main addresses controlled by the attackers. Galaxy Research stated that the speed and coordination of the transaction suggest the attack was carried out using automated software.
However, the attack did not stop there. With second and third waves detected on August 1, the total stolen amount rose to 1367 Bitcoin (approximately $88.6 million). The number of affected addresses increased to 4385. This situation highlights the widespread nature of the vulnerability and the organized approach of the attackers. On August 2, Galaxy Research issued a warning to users via a post on X (formerly Twitter): "The Coldcard exploit is ongoing. Move Coldcard single-sig funds to safe locations immediately." The firm also announced that they had reported approximately 600 addresses believed to be holding stolen funds to federal investigators, industry compliance firms, and cross-industry cyber investigators.
What Was Stolen
This attack directly targeted the digital assets themselves, rather than user data or personal information. The assets stolen by the attackers consist entirely of Bitcoin. According to reports from blockchain analysis firms, the breakdown of the stolen funds is as follows:
- First Wave (July 30): 1,082.65 Bitcoin (approx. $70 million) from 1196 addresses.
- Second and Third Waves (August 1): The total stolen amount reached 1367 Bitcoin (approx. $88.6 million).
- Total Affected Addresses: The number of unique Bitcoin addresses affected after the attack waves was identified as 4385.
It is believed that the attackers consolidated the stolen funds into four main addresses they control and are attempting to obscure their tracks by breaking them into smaller amounts. The decentralized nature of cryptocurrencies makes recovering such stolen funds extremely difficult. However, analytics firms and authorities are working to blacklist these addresses to prevent them from being cashed out on exchanges.
How Did the Attack Happen
The root cause of the attack lies in a critical vulnerability in the firmware (the device's operating system) of Coldcard hardware wallets, dating back to 2021. According to a report published by Block's Bitcoin Engineering and Security team on July 30, the issue stems from the wallet's key generation mechanism.
Under normal circumstances, a hardware wallet like Coldcard is supposed to use a hardware-based random-number generator (RNG) when creating a wallet "seed" (master key or recovery phrase) for users. This hardware generates completely random and unpredictable numbers by using unforeseeable physical processes (like electronic noise). These numbers ensure that the wallet keys are cryptographically secure.
However, due to the discovered vulnerability, the wallet sometimes reverted to a fallback generator that was "deterministic" in nature instead of using the hardware-based RNG. A deterministic generator always produces the same sequence of numbers given the same starting conditions. This means the numbers generated are "not random enough." In cryptography, a lack of randomness is a fatal flaw. By analyzing the workings of this deterministic generator, attackers were able to reproduce the private keys offline, without direct access to the device. This allowed them to gain access to thousands of users' wallets and transfer the funds to their own addresses.
Who Is Affected
The attack affected users of specific Coldcard models who created their wallet keys (seed) while a vulnerable firmware version was installed. According to Coinkite's statement, the affected models are the Mk2 and Mk3. If a user owns one of these models and set up their wallet during the period when the vulnerable firmware was active, their funds are at risk.
The warning from Galaxy Research specifically highlighted "Coldcard single-sig" funds. "Single-sig," or single-signature, refers to the standard wallet structure where only one private key is required to authorize a Bitcoin transaction. This is the most common type of usage. There is no clear information on whether users with more complex security setups, such as multi-signature (multi-sig), were affected by this vulnerability.
What You Can Do
If you are a Coldcard user, you need to take immediate action to secure your funds. The recommendations from researchers and the manufacturer, Coinkite, are very clear:
- Do Not Create New Wallets: Do not create a new wallet (seed) on an affected model until you have updated the firmware. Otherwise, your new wallet will also be vulnerable.
- Update Your Firmware: Coinkite has released updated firmware versions for all affected models (Mk2, Mk3) and release tracks that patch the security vulnerability. Update your device to the latest version immediately.
- Move Your Funds: This is the most critical step. You must move all your Bitcoin from a wallet created on a vulnerable device to a new, secure wallet. This new wallet should be created on an updated Coldcard or on a completely different, trusted hardware/software wallet. This process involves a standard Bitcoin transaction, sending the funds from your old wallet to a new address. Galaxy Research emphasizes that this should be done "immediately."
What the Company Says
Coinkite, the manufacturer of Coldcard, acted swiftly after the vulnerability was disclosed. The company announced that it has released patched firmware updates for all affected models and release tracks. In a statement to its customers, Coinkite issued a strong warning not to generate new keys (seeds) on affected models until they have installed the update.
The company confirmed that the security flaw originated in 2021 and stated that they have taken all necessary steps to ensure user security. Coinkite is providing detailed instructions on its website and official communication channels on how to update the firmware and secure funds. This incident once again demonstrates how vital firmware updates are, even for hardware wallets considered to be the most secure.
Source
https://www.infosecurity-magazine.com/news/coldcard-users-lose-89m-bitcoin/
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.