Coldcard Hack Blows Past $89M — Now Nearing $110M as Wave 4 Hits

fiverr
Ledger


A security flaw in one of the cryptocurrency industry’s most trusted hardware wallets, Coldcard, has escalated into a fast-moving, multi-day theft, with losses now approaching $110 million in bitcoin — and a new wave of attacks reportedly underway as this report was published.

The incident is now among the largest known losses tied to a hardware wallet vulnerability, and it continues to grow in real time, raising fresh questions about whether offline crypto storage can protect users when the software responsible for creating wallet keys fails.

Losses Climb Past $89M as a Fourth Wave Hits Live

Galaxy Research detected the first wave of suspicious transactions on July 30, when attackers moved more than 1,000 bitcoin from nearly 1,200 wallets in under an hour.

Sponsored

bybit

Crypto Prediction Markets

18+ · Gambling involves risk. Play responsibly.

Three subsequent waves have followed. By Monday, more than 1,755 BTC — worth roughly $110 million — had been drained from approximately 5,000 wallets, according to Galaxy Research.

The attack is not over. Galaxy Research’s head of research, Alex Thorn, warned late Sunday that hackers may be launching a fourth coordinated attack, with a fresh wave pilfering 388.93 BTC — worth $24.53 million — from 462 addresses across 218 transactions

Thorn measured the sweep rate during this wave at roughly 45 times the pre-incident baseline, describing it as the fingerprint of an automated pipeline working through a pre-computed list of vulnerable keys against the live mempool

A Firmware Error Undermined Wallet Security

According to a security advisory from Block’s Bitcoin Engineering and Security team, a firmware bug affected how Coldcard generated wallet recovery phrases. 

A coding error caused some devices to use a weaker software-based random number generator instead of the device’s built-in hardware randomness system. Because the fallback method relied on predictable device information and timing data rather than secure random values, attackers could potentially reconstruct affected wallet seeds. 

Older Coldcard Wallets Are the Main Target

The flaw was introduced in a March 2021 firmware release and affected certain Coldcard Mk3 versions, including firmware versions 4.0.1 through 4.1.9, as well as earlier releases.

Coinkite released emergency firmware to prevent the issue from affecting newly generated wallets, but has warned the update does not repair seeds already created on vulnerable firmware.

The weakened recovery phrases could, under certain circumstances, be predictable enough for sophisticated attackers to reconstruct without physically accessing the device. 

Coinkite noted that wallets set up using at least 50 private dice rolls for manual entropy generation bypass this flaw and are not affected.

Coldcard Tells Users to Move Their Bitcoin

Coinkite CEO Rodolfo Novak publicly apologized after the company confirmed the vulnerability, saying the company was “heartbroken” and taking responsibility for the failure.

The company said it disclosed the issue because attackers may still be targeting vulnerable wallets.

Because the flaw affects the recovery phrase rather than the physical Coldcard device itself, updating the hardware alone will not protect affected users. 

Coinkite is urging customers to install the latest emergency firmware update, create a new recovery phrase only after the update is complete, and move their bitcoin to a newly generated wallet address. 

Restoring an old recovery phrase on another device will not resolve the vulnerability.

Why This Matters

The Coldcard vulnerability affected the wallet creation process itself, potentially allowing attackers to access bitcoin without ever obtaining the physical device. The incident highlights a fundamental risk in cryptocurrency security: even devices designed to keep assets offline depend on software that must generate and protect access keys correctly.

Discover DailyCoin’s popular crypto news right now:
Ripple’s XRP Chain Logged 1 Million AI-Agent Payments
Why the Next Payments Battle Will Be Fought Above the Rails

DailyCoin’s Vibe Check: Which way are you leaning towards after reading this article?





Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*