Coldcard, a bitcoin-only hardware wallet, has recently faced a data breach resulting in over $100 million US worth of bitcoin being stolen, as per Galaxy Research. Coldcard, created by Coinkite, serves as a hardware wallet that enhances security by storing “seed phrases” offline, providing an additional layer of protection. The stolen funds were a result of a software bug identified by Coinkite, allowing hackers to access users’ bitcoin wallets without physical possession of the device.
The breach has led to the theft of 1,596 bitcoin from around 7,300 addresses, with potential for further losses if additional attacks are confirmed, totaling approximately 2,055 bitcoin worth $130 million US. The culprits behind the attacks remain unidentified. Coinkite has advised affected users to transfer their funds and issued firmware updates to mitigate the vulnerability.
Galaxy Research recommends not keeping compromised bitcoin in the wallet and installing the latest firmware for protection. Existing seed phrases generated on vulnerable devices should be replaced. Coinkite is conducting an investigation, with experts warning of the implications of the breach. Users are encouraged to migrate their funds to secure addresses and hold off on disposing of affected devices, as they may be crucial in potential fund recovery efforts. The incident underscores the importance of ensuring the security of cryptocurrency assets.
