Massive Bitcoin Theft from Coldcard Hardware Wallets
Owners of Coldcard hardware cryptocurrency wallets have fallen victim to a significant cyberattack, resulting in the theft of an estimated 1815 bitcoins, valued at approximately $118 million, from thousands of devices. The incident, which began late last week, affected numerous wallets despite hardware solutions traditionally being considered among the most secure options for cryptocurrency storage.
Attack Details and Exploitation Mechanism
According to Galaxy Research, the initial phase of the attack commenced on July 30. Within 41 minutes, attackers managed to siphon 1082.65 bitcoins from 1196 wallets. By August 1, the total amount stolen had reached 1367 bitcoins from 4585 addresses, equating to roughly $88 million at that time. However, more recent estimates indicate the total loss could be as high as $118 million, with 1815 bitcoins confirmed stolen.
The vulnerability stemmed from a critical flaw in Coldcard’s cryptographic algorithm implementation. Instead of utilizing robust hardware-based random number generation—a key security feature—the devices relied on a software implementation. This allowed the attackers to predict the results of the generation process and reconstruct the ‘seed,’ which grants full access to all secrets stored on the wallets.
Once the seed was reconstructed, hackers were able to verify its validity by cross-referencing public data, including Bitcoin transaction histories. With all necessary information at hand, the attackers proceeded to transfer the funds to their own wallets.
Implications for the Cryptocurrency Industry
This incident underscores that even ‘cold’ wallets, designed for offline cryptocurrency storage and widely regarded as highly secure, are not immune to vulnerabilities if their underlying software or cryptographic implementations contain flaws. The Coldcard breach serves as a stark reminder of the critical importance of rigorous auditing for cryptographic implementations and the necessity of true hardware-based random number generation to ensure genuine security in cryptocurrency storage solutions.
This Coldcard news is rough, especially since I’ve been recommending them for years. I always thought their air-gapped approach was solid, and it’s been my go-to for larger stacks. The issue with the software RNG is a huge oversight, making me question how thorough their audits really are. It reminds me why I always generate my own entropy with dice rolls for my main seed phrase just as an extra layer, even with hardware wallets that claim to have robust RNG. For others, always verify your seed phrase on a separate, air-gapped device before sending any significant funds. This really highlights that even the ‘best’ can fail.