Business

Coinkite Coldcard Vulnerability Triggers $89 Million Bitcoin Theft

A critical firmware coding error in the popular hardware wallet allowed hackers to drain over 1,000 bitcoin in under an hour.

On July 30, a swift cyberattack drained 1,196 digital wallets holding more than 1,000 Bitcoin in just 41 minutes.

Security researchers at Galaxy Research uncovered the exploit, linking it to a critical cryptographic vulnerability in Coinkite’s Coldcard, a popular hardware wallet used to store digital assets offline.

Galaxy subsequently identified two additional waves of suspicious blockchain activity, raising total estimated losses to approximately $89 million.

The exploit stems from a coding error in certain Coldcard firmware versions. According to a security advisory from Block’s Bitcoin Engineering and Security team, the bug rendered the wallet’s generated recovery phrases predictable enough to allow automated, remote mathematical attacks.

Coinkite CEO Rodolfo Novak apologized on X, stating that the Toronto-based company takes full accountability for the firmware error. Novak urged users who generated their wallet seeds on the affected devices to immediately migrate their funds to new recovery phrases.

“Updating the firmware does not repair a seed that was generated by affected firmware,” Coinkite warned. Users must generate a new cryptographic seed and pay on-chain transaction fees to transfer assets out of vulnerable addresses, rather than simply patching their physical devices.

The breach is a significant blow to the “self-custody” sector, which markets offline storage as the safest alternative to centralized exchanges like Coinbase or Binance. Coinkite’s rivals have faced similar headwinds; Paris-based Ledger drew sharp backlash in 2023 over a “Ledger Recover” feature that critics argued compromised the privacy of hardware wallets.

Users who bypassed Coldcard’s internal random number generator by using at least 50 physical dice rolls to generate their recovery seeds are unaffected, according to the company.

Bitcoin representation

Jan3 Chief Executive Officer Samson Mow warned on social media that the exploits are ongoing and urged immediate action to secure exposed capital.

Separately, developers of Bitkey—the self-custody wallet backed by Jack Dorsey’s Block Inc.—addressed an unrelated technical issue reported with their own devices. Bitkey developer Clay Garrett said the issue presents “no risk of remote drains or immediate funds loss” and that customers can continue using the devices normally.

Customers seeking official firmware patches and step-by-step migration instructions can access them directly through Coinkite.

Bitcoin on a digital screen

Coinkite is cooperating with private blockchain intelligence firms and law enforcement to assist victims with insurance claims and police reports, though it has not yet provided a final tally of affected users.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button