Hackers drain 1,596 bitcoin from Coldcard wallets in ongoing attack

Galaxy Research traces the theft to a March 2021 firmware bug that let attackers rebuild wallet keys

Hackers drain 1,596 bitcoin from Coldcard wallets in ongoing attack

Hackers drained at least 1,596 bitcoin, worth more than US$100m, from roughly 7,300 addresses tied to Coldcard hardware wallets, in an ongoing attack that struck the very investors who took the most care to protect their holdings.  

Galaxy Research said on X the victims had chosen self-custody, keeping their private keys offline instead of leaving them with an exchange or another third party.

Within minutes, the Financial Post reported, at least 1,600 bitcoin worth about $140m vanished from customers of Toronto-based Coinkite Inc., maker of the Coldcard "cold" wallet. 

Cold wallets are considered among the industry's most trusted tools for securing digital assets because they stay off the internet and, in theory, cannot be breached remotely. 

This attack cut at that premise.  

A bug let hackers reconstruct the "seed phrases" that unlock a wallet from afar, so they never needed the physical device.  

The flaw traces to a March 2021 software update, Coinkite said in its advisory, in which affected firmware fell back on a predictable key-generation method rather than the intended hardware-based one, CBC News reported. 

"The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered," Aneirin Flynn, chief executive of cybersecurity firm FailSafe, said in an interview with Bloomberg, arguing the case exposes the limits of keeping crypto offline

Galaxy Research first corroborated the opening wave, flagged by engineers at Block Inc., using victim reports.  

On July 30 it watched hackers empty more than 1,000 bitcoin, about $99m, from more than 1,000 addresses in 41 minutes.  

By Monday the firm counted three confirmed waves plus 14 smaller incidents, and flagged a suspected fourth that, if verified, would lift the total to 2,055 bitcoin, or about US$130m. 

Galaxy cautioned that its tally rests on blockchain analysis and that it has not confirmed every affected wallet used the compromised software. 

Roughly 90 percent of the stolen coins remain unmoved, Galaxy Research said, and it has passed attacker and victim addresses to US federal law enforcement, exchanges and cyber-investigation groups.  

The attack is ongoing, the firm warned. 

Rodolfo Novak, co-founder and chief executive of Coinkite, apologized on X on Friday and took "full accountability for the firmware bug."  

"We know an apology doesn't return anyone's funds. We know we'll have to earn back our users' trust," he wrote.  

Per its Sunday update, the company shipped a fix, destroyed remaining inventory built with the vulnerable software and halted shipments.  

The fix protects only wallets created afterward, so seeds generated on vulnerable devices still need replacing. 

The roughly $140m loss barely cracks the top 20 crypto thefts by dollar value, Alex Thorn, head of research at Galaxy Digital, told the Financial Post, but the nature of the attack makes it stand out because it hit careful holders.  

He said Coinkite's failure to catch the bug pointed to sloppy coding and inadequate review. 

The breach may slow adoption among newcomers, said Jarret Vaughan, an adjunct professor at the UBC Sauder School of Business.  

He told the Financial Post the bitcoin community tends to learn from such failures, and that holders are already leaving the product, "moving away from it immediately" even without "one of those vulnerabilities." 

Galaxy Research urged unsure Coldcard holders to move funds "to a safe address at a custodian/exchange or a fresh seed."  

Coinkite said a formal technical review will follow as soon as possible. 

LATEST NEWS