Coldcard $100M Crypto Hack; Attacker Sends 30 BTC to New Address

BTCC


Set as Google Preferred SourceFollow on Google News

TLDR

  • Coinkite plans a technical post-mortem after the Coldcard firmware exploit caused more than $100 million in losses.
  • Lookonchain reported that a wallet linked to the exploit moved 30 BTC worth about $1.94 million.
  • Galaxy Research verified 1,596 BTC stolen from roughly 7,300 addresses across three attack waves.
  • A random number generation flaw weakened wallet seeds created by affected Coldcard firmware.
  • The vulnerability affected wallet seed generation and did not compromise Bitcoin’s underlying network or cryptography.

Coldcard maker Coinkite is preparing a technical post-mortem after a firmware flaw was linked to more than $100 million in Bitcoin losses. The company said the review will be released once it is safe to publish the technical details.

Coinkite told Bloomberg that its privacy-focused design prevents it from independently confirming reports that the attack drained about $130 million in Bitcoin. The company said its immediate priority remains supporting customers affected by the exploit while continuing to provide updates.

Coldcard Hack Linked to Vulnerable Wallet Firmware

The Coldcard hack was linked to a random number generation flaw introduced during a 2021 code migration. The affected firmware used a predictable software random number generator instead of the intended hardware-based source when creating wallet seeds.

Researchers said the weakness affected certain Coldcard models and firmware versions for several years. The flaw reduced the possible seed search space to about 40 bits on Mk2 and Mk3 devices and around 72 bits on later models.

Updating the firmware does not repair a seed that was already created with the vulnerable process. Affected users need to generate a new seed with patched firmware or another trusted environment before transferring their Bitcoin to a new wallet.

Attacker Moves 30 BTC From Coldcard-Linked Wallet

Blockchain monitoring platform Lookonchain reported that a wallet linked to the Coldcard exploit moved 30 BTC, worth about $1.94 million, to a new address. The transfer came as researchers continued tracking Bitcoin associated with the attack.

Image
Source: X


Betpanda


Galaxy Research has verified the theft of 1,596 BTC from about 7,300 addresses across three coordinated attack waves. A broader analysis identified four suspected attack waves involving about 5,294 addresses and 1,815.75 BTC.

Those figures remain estimates based on blockchain transaction patterns. They do not represent individually verified victims or confirmed final losses, leaving the total amount stolen subject to further investigation.

Coinkite Plans Detailed Technical Review

Coinkite said it will continue publishing real-time information through its public blog before releasing a comprehensive technical post-mortem. The company has not independently confirmed the wider estimate of about $130 million in stolen Bitcoin.

The company also said an industry-wide AI-assisted security audit had identified several critical bugs across cryptocurrency software systems. The Coldcard incident has brought renewed attention to wallet seed generation and the security of software used to create private keys.

The reported vulnerability affected specific Coldcard firmware and wallet seed generation rather than Bitcoin’s underlying network or cryptography. The movement of stolen Bitcoin remains visible on the blockchain, allowing researchers to track addresses associated with the attack as the investigation continues.



Source link

BTCC

Be the first to comment

Leave a Reply

Your email address will not be published.


*