Coldcard, a bitcoin-only hardware wallet, has recently fallen victim to a data breach resulting in over $100 million US worth of bitcoin being stolen by hackers, as reported by Galaxy Research. The breach exploited a software bug in the wallet, allowing hackers to reconstruct wallet “seed phrases” without physical access to the device.
Coldcard, developed by Toronto-based Coinkite, offers users an additional layer of security by storing seed phrases offline, securely locked inside the physical device, while the actual bitcoins remain on the public blockchain network. These seed phrases act as a master key, enabling users to authorize and sign transactions.
Following the discovery of the vulnerability, Coinkite issued warnings to its users and released firmware updates to address the issue. Despite the ongoing investigation, the perpetrators behind the attacks remain unidentified.
To mitigate the risks posed by the breach, affected users are advised to move their funds to secure addresses and update their device firmware. Additionally, Coinkite has halted the shipment of devices manufactured with the vulnerable firmware and is working with law enforcement agencies to identify and bring the responsible parties to justice.
