Security researchers have revealed that a flaw in the Coldcard hardware wallet, a popular device used by cryptocurrency investors to store bitcoin offline, enabled attackers to steal approximately $70 million worth of bitcoin from nearly 1,200 wallets in just 41 minutes on July 30, according to Galaxy Research and Forbes [1]. Subsequent analysis identified two additional waves of suspicious activity, raising the estimated losses to nearly $89 million [1]. The vulnerability stemmed from a coding mistake in certain versions of Coldcard, which weakened a key security feature and made some recovery phrases predictable enough for sophisticated attackers to exploit without needing physical access to the device [1].
Block's Bitcoin Engineering and Security team issued a security advisory, explaining that the software bug could allow attackers to deduce recovery phrases under certain circumstances, potentially enabling them to steal bitcoin remotely [1]. The company released its findings because it believes the attacks are ongoing, although researchers are still investigating the precise exploitation methods [1].
Coinkite, the Canadian manufacturer of Coldcard, responded by releasing a software update to prevent the vulnerability from affecting newly created wallets [1]. However, the company emphasized that simply updating the firmware does not protect wallets whose recovery phrases were generated with the affected software. Users are advised to generate a new recovery phrase using the updated software and migrate their bitcoin to a new wallet [1]. Coinkite also warned that transferring the same recovery phrase to another wallet does not resolve the issue, as the weakness is tied to the recovery phrase itself [1].
Coinkite CEO Rodolfo Novak publicly apologized for the incident on X, expressing that the company was "heartbroken" and taking "full accountability for the firmware bug" [1].
CONCLUSION
The Coldcard wallet vulnerability has resulted in significant bitcoin losses, prompting urgent action from both the manufacturer and affected users. The incident highlights the critical importance of secure recovery phrase generation and swift response to software flaws in cryptocurrency hardware. Market sentiment is negative, and the impact is high due to the scale of losses and ongoing security concerns.
