Coldcard Hardware Wallet Vulnerability Leads to $130 Million Cryptocurrency Theft
Hackers have stolen approximately $130 million from owners of Coldcard offline hardware cryptocurrency wallets, according to estimates from blockchain security monitoring firms. The thefts stem from a security flaw in how the hardware devices generated seed phrases, enabling attackers to predict secret keys and access funds without reaching the physical devices or online connections.
What Happened
Multiple attackers are actively targeting Bitcoin owners who use Coldcard hardware wallets, which are manufactured by Coinkite. Blockchain research firm Galaxy Research reported that at least a dozen different hackers or hacking groups appear to be involved in the incidents. As of Tuesday, Galaxy Research estimated total stolen funds at around $130 million. Tom Robinson, co-founder and chief scientist of crypto monitoring firm Elliptic, stated that this $130 million estimate is roughly correct.
According to security researchers at Block, the exploit relies on a flaw in how Coldcard wallets generated users’ secret seed phrases. Due to a code vulnerability dating back to 2021, the generated seed phrases were predictable. Hackers were able to brute-force and generate matching seed phrases at scale, allowing them to access the Bitcoins stored on the blockchain without breaking into physical storage.
Key Highlights
- Over $130 million in cryptocurrency has been stolen from Coldcard hardware wallet users.
- Security firms Galaxy Research and Elliptic confirmed the scale of the thefts, identifying multiple active hacking groups.
- Block security researchers found the vulnerability originated from a single line of code added in 2021 that produced predictable seed phrases.
- Attackers brute-forced the predictable phrases to gain key access remotely on the blockchain.
- Coinkite issued a security advisory instructing users to update device firmware and migrate to a new seed phrase immediately.
- According to TRM Labs, more than 200 crypto-related hacks have occurred this year, totaling over $950 million in losses.
Why This Matters
Cold hardware wallets like Coldcard are designed to keep cryptocurrency private keys completely offline, offering a higher level of security than online “hot” wallets like mobile apps, browser extensions, or commercial exchange accounts such as Binance and Coinbase. Because the secret password or seed phrase is stored exclusively offline, users expect protection against remote network attacks. However, because the device software generated predictable keys, attackers were able to recreate access passwords remotely.
The issue impacted users who followed standard security procedures. For example, cryptocurrency owner Jonathan Goodman reported on X that $1.6 million was stolen from his Coldcard wallet despite keeping his device entirely offline and stored in physical safes and safety deposit boxes, attributing the compromise entirely to the 2021 code vulnerability.
What to Watch Next
Coinkite published a security advisory detailing the vulnerability and updated it over the weekend. The manufacturer is urging all Coldcard users to update their devices immediately and migrate their funds to a newly generated seed phrase. Coinkite did not immediately respond to requests for comment regarding the matter.
Frequently Asked Questions
How were hackers able to steal funds from offline wallets?
Hackers exploited a 2021 software flaw in Coldcard devices that caused generated seed phrases to be predictable. By brute-forcing these predictable key patterns, attackers were able to recreate the seed phrases and transfer Bitcoins on the blockchain without accessing the offline hardware.
What steps should Coldcard wallet users take?
Coinkite has advised affected wallet owners to update their hardware devices to the latest firmware and immediately migrate their cryptocurrency to a newly generated seed phrase.
How much cryptocurrency has been lost in this breach?
Galaxy Research estimates total losses at approximately $130 million, an amount confirmed as roughly accurate by monitoring firm Elliptic.
Source: TechCrunch
