Coldcard bitcoin hardware wallet flaw linked to $89M bitcoin theft
Key Points:
- Security researchers have identified a software flaw in Coldcard, a popular bitcoin hardware wallet, that may have enabled attackers to steal nearly $89 million worth of bitcoin from over 1,000 wallets in rapid attacks on July 30.
- The vulnerability involves a coding error that made some recovery phrases predictable, allowing sophisticated attackers to potentially access bitcoin without physical access to the device.
- Coinkite, the maker of Coldcard, released a software update to fix the issue for new wallets but warned that users with affected recovery phrases must create new ones and transfer their funds to secure wallets, as updating firmware alone does not fix compromised seeds.
- Coinkite CEO Rodolfo Novak issued a public apology, urged immediate action from users, and is cooperating with law enforcement and investigators to determine the full scope of the breach and assist affected customers.
- The cryptocurrency industry widely disseminated the warning, with experts advising all Coldcard users to migrate funds immediately; meanwhile, other wallet developers like Bitkey have confirmed no immediate risk from reported issues with their products.