An ongoing cybersecurity incident involving a popular Bitcoin wallet has resulted in the theft of an estimated $89 million, as per researchers’ findings.
Coinkite’s Coldcard, a Bitcoin-only hardware wallet, fell victim to an attack on July 30. Galaxy Research closely monitored the initial assault, which saw 1,082.65 Bitcoin (equivalent to $70 million) siphoned from 1,196 addresses within a 41-minute timeframe. The investigators traced the stolen funds to four addresses controlled by the attackers, suggesting that the attack was likely automated.
Subsequent waves of attacks occurred on August 1, resulting in a total of 1,367 Bitcoin ($88.6 million) being stolen from 4,385 victim addresses. In response to the ongoing exploit, Galaxy Research issued a warning on X (formerly Twitter) on August 2, advising Coldcard users to transfer their single-sig funds to secure locations immediately.
The research team has identified and reported approximately 600 addresses believed to be held by hackers who obtained funds from Coldcard-generated weak entropy addresses to relevant authorities, compliance firms, and cyber investigators across industries.
According to a report from Block’s Bitcoin Engineering and Security team on July 30, the attack exploited a firmware vulnerability dating back to 2021. The bug allowed the wallet to occasionally bypass a hardware-based random-number generator (RNG) when generating users’ wallet seeds, relying instead on a deterministic fallback generator. This flaw made it possible for attackers to replicate the keys offline, compromising the security of the wallet.
Taking swift action, Coinkite has released updated firmware for all affected Coldcard models and advised customers not to generate new seeds on vulnerable models until the fix is installed. The company warned that funds controlled by seeds generated on specific versions are at risk if they lack sufficient entropy and are not protected by a strong passphrase.
Coinkite’s efforts to mitigate the impact of the attack may have thwarted further theft, but Galaxy Research’s head of firmwide research, Alex Thorn, hinted at the possibility of a fourth wave of attacks currently underway.
Stay informed and take proactive measures to secure your digital assets in light of evolving cyber threats like the Coldcard exploit.
