Coldcard Attack Widens: 15 Hackers Drain $130M in Bitcoin

fiverr
Coinbase


  • Galaxy Research identified 15 attackers targeting vulnerable Coldcard wallets.
  • Estimated losses have surpassed $130 million in Bitcoin from over 7,300 wallets.
  • The threat remains active, according to Coinkite’s latest warning.

The Coldcard wallet attack has escalated after Galaxy Research identified 15 separate attackers exploiting a firmware vulnerability that weakened private key generation on affected hardware wallets

The ongoing attack has drained an estimated $130 million in Bitcoin from more than 7,300 wallets, with further losses expected as the vulnerability remains publicly known.

Sponsored

Crypto Prediction Markets

Binance

18+ · Gambling involves risk. Play responsibly.

Because the vulnerability is public knowledge, any hacker with sufficient technical skill can join the ongoing theft. 

Why Are Hackers Still Targeting Coldcard Wallets?

The Coldcard wallet attack continues as vulnerable wallet addresses remain visible on Bitcoin’s public blockchain, allowing attackers to identify affected wallets and attempt to recover private keys through brute-force methods.

Galaxy Research reported that dozens of victims have already contacted the firm, while the total number of affected users could be significantly higher. Some long-term Bitcoin holders may not yet realize their wallets were exposed.

The vulnerability was linked to Coldcard firmware that redirected wallet seed generation through MicroPython’s software fallback instead of a true random number generator. The weaker process produced seed phrases with significantly reduced entropy.

Coinkite, the company behind Coldcard hardware wallets, estimated that seeds generated on Coldcard Mk2 and Mk3 devices contained about 40 bits of entropy, compared with the company’s 128-bit target. 

Coldcard Mk4 devices reportedly generated seeds with about 72 bits of entropy, which remained below the expected security level.

Coinkite co-founder Rodolfo Novak apologized for the bug on X on July 31, writing that the company takes “full accountability for the firmware bug.” Coinkite has since released hotfixes across every affected model and release track. 

The company repeated its warning on Tuesday that “the threat is still active,” urging Coldcard users to move funds to newly generated, unaffected wallets.

As of the time of writing, the identity of the hacker(s) has not been publicly verified.

Why This Matters

The Coldcard wallet attack remains active because vulnerable wallets can still be identified on-chain, allowing additional attackers to target exposed funds. Users who generated seeds on affected firmware versions may face continued risk until they migrate their Bitcoin to newly generated wallets.

Delve into DailyCoin’s popular crypto scoops right now:
Crypto Search Interest Has Collapsed, but XRP Ownership’s Still Rising
BlackRock Tokenizes $311B Money Market Fund Range in Europe

DailyCoin’s Vibe Check: Which way are you leaning towards after reading this article?





Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*