Coldcard, a bitcoin-exclusive hardware wallet, has fallen victim to a recent data breach resulting in over $100 million US worth of bitcoin being stolen from the devices. The breach, disclosed by blockchain intelligence firm Galaxy Research, has raised concerns about the security of cryptocurrency holdings. Coldcard, developed by Coinkite in Toronto, operates as a hardware wallet, safeguarding “seed phrases” offline to enhance security for bitcoin users.
The breach was attributed to a software bug detected by Coinkite, allowing hackers to reconstruct wallet seed phrases and gain unauthorized access to users’ bitcoin wallets. As per Galaxy Research’s analysis, approximately 1,596 bitcoin from around 7,300 addresses have been stolen, with the possibility of more funds being lost as further investigation unfolds.
Coinkite has issued firmware updates to address the vulnerability, urging users to transfer their funds to secure locations promptly. The company emphasized the importance of installing the latest firmware and refraining from generating new seed phrases until the fix is in place. In response to the breach, U.S. law enforcement agencies, cryptocurrency exchanges, and cyber-investigation groups have been notified to track down the attackers and prevent further exploitation of the compromised wallets.
Experts have highlighted the significance of taking immediate action if users suspect their wallets may have been compromised. Coldcard users are advised to move their funds to alternative secure platforms and refrain from disposing of the affected devices, as they may be crucial in recovering lost assets. Coinkite continues its investigation into the breach, with plans to release a detailed technical review in the near future.
