Coldcard wallet attack drains at least $70M in Bitcoin from 1,200 addresses: report

1 hour ago 1

Owners of a popular bitcoin storage device are being urged to protect their cryptocurrency after security researchers said a software flaw may have allowed attackers to steal roughly $70 million worth of bitcoin in less than an hour.

Forbes first reported the attacks, which researchers at Galaxy Research say drained more than 1,000 bitcoin from 1,196 digital wallets in just 41 minutes on July 30.

Galaxy later identified two additional suspected waves of suspicious activity, bringing the estimated losses to nearly $89 million.

CRASHSTEALER MAC MALWARE STEALS PASSWORDS AND WALLETS

The firm cautioned that its findings are based on blockchain analysis and that it has not confirmed every affected wallet was created using the vulnerable software.

The issue involves Coldcard, a handheld device many cryptocurrency investors use to store bitcoin offline instead of leaving it on a cryptocurrency exchange. Often called a "hardware wallet," the device is designed to keep hackers from accessing a user's bitcoin over the internet.

According to a security advisory from Block's Bitcoin Engineering and Security team, a coding mistake in certain versions of Coldcard may have weakened one of the wallet's key security features.

PAIDWORK BREACH EXPOSES 23M USER RECORDS

Block said the software bug may have made some of those recovery phrases predictable enough for sophisticated attackers to figure them out under certain circumstances, potentially allowing them to steal bitcoin without ever physically touching the wallet.

The company said it released its findings because it believes the attacks are still happening, though researchers cautioned they are continuing to study exactly how the vulnerability is being exploited.

Canadian company Coinkite, which makes Coldcard, has since released a software update to prevent the problem from affecting newly created wallets.

KARR BLUETOOTH FLAW EXPOSES 2.2M CARS TO THEFT RISK

However, the company warned that simply installing the update will not protect people who already created a recovery phrase using the affected software.

Instead, Coinkite is urging those users to create a brand-new recovery phrase using the updated software and move their bitcoin into the newly secured wallet.

"Updating the firmware does not repair a seed that was generated by affected firmware," the company said in a security advisory. "A new seed must be generated and the funds migrated to the new wallet."

Coinkite also warned that moving the same recovery phrase into another wallet does not solve the problem because the weakness follows the recovery phrase itself, not the physical device.

Coinkite CEO Rodolfo Novak issued a public apology on X, saying the company was "heartbroken" and taking "full accountability for the firmware bug."

"I'm sorry and I'm devastated," Novak wrote. "Our team is heartbroken about yesterday's news."

Novak urged customers to act immediately.

"If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further," he wrote.

He also asked the public to help spread the warning.

"If you know anyone who owns a Coldcard, please make sure they see this," Novak wrote. "Some affected users may not be watching social media right now, and every hour matters."

Novak said Coinkite is still working to determine exactly how many people may have been affected and plans to publish a detailed explanation of what went wrong after its investigation is complete.

"We do not have full attribution or scope of the issue yet, and we won't speculate until our full technical evaluation is complete," Novak wrote.

The company said it will also help affected customers who want to file police reports or insurance claims and is cooperating with blockchain investigators and law enforcement agencies.

The warning quickly spread across the cryptocurrency industry.

"If you're using a COLDCARD, any version firmware or MK, migrate your funds immediately," Jan3 CEO Samson Mow wrote on X. "If you know someone who is, let them know ASAP... Attacks are ongoing so do it quickly."

While the initial warning focused on older Coldcard devices, Coinkite has since expanded the list of affected products to include additional models and software versions.

The company also said customers who created their recovery phrase using at least 50 private dice rolls are not affected by this specific flaw alone. However, Coinkite recommends that anyone who is unsure how their wallet was set up create a new recovery phrase and move their funds as a precaution.

Block emphasized that none of its own products or customers are affected by the vulnerability. The company said it published its findings after working with anonymous security researchers and receiving reports from Coldcard users.

Separately, developers of Jack Dorsey's Bitkey wallet said they are investigating a different reported issue involving their product but are not advising customers to stop using the wallet.

"Our recommendation is to continue to use your Bitkey normally," Bitkey developer Clay Garrett wrote on X.

Garrett said the reported issue would require "exceptional circumstances" to exploit and would not give an attacker enough information to steal customers' funds.

"Our assessment is this presents no risk of remote drains or immediate funds loss," Garrett wrote.

FOX Business reached out to Coinkite, Galaxy Research, Block, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the Royal Canadian Mounted Police (RCMP), the Canadian Centre for Cyber Security and Chainalysis for comment but did not immediately receive a response.

Read Entire Article