Hackers Exploit Coldcard Wallet Flaw, Stealing Over $130 Million in Crypto
UKPulse Markets Desk
A security vulnerability in Coldcard hardware wallets has allowed hackers to steal more than $130 million in cryptocurrency by exploiting a flaw in how seed phrases were generated.
- Over $130 million has been stolen from Coldcard hardware wallets due to a security vulnerability.
- The flaw allowed hackers to predict and generate users' seed phrases, which are essentially passwords for cryptocurrency.
- Coldcard manufacturer Coinkite has advised users to update their devices and migrate to a new seed phrase.
Hackers have reportedly stolen over $130 million in cryptocurrency by exploiting a security vulnerability in Coldcard offline hardware wallets. Blockchain security firms monitoring the incidents indicate that at least a dozen different hackers are targeting Bitcoin owners using these devices, manufactured by Coinkite.
The vulnerability lies in how Coldcard wallets generated users' seed phrases, which security researchers at Block found to be predictable. This allowed hackers to generate victims' seed phrases without needing direct access to the physical wallets.
Coinkite issued an advisory on Thursday, updated on Saturday, urging users to update their devices and migrate to a new seed phrase to address the flaw.
Why this matters: The hacks highlight a significant security risk for users of supposedly secure offline hardware wallets, which are generally considered one of the safer ways to store cryptocurrency.
What this means for you: If you use a Coldcard hardware wallet, you are advised to update your device and migrate to a new seed phrase.