Bitcoin Wallet Vulnerability Leads to $144 Million Crypto Heist | Information Age

Major Security Breach in Coldcard Bitcoin Wallets Leads to $144 Million Theft: Ongoing Attacks Confirmed

Title: Major Security Flaw in Coldcard Wallets Leads to $144 Million Bitcoin Heist

In a shocking revelation, a significant security vulnerability in the Coldcard Bitcoin hardware wallet has reportedly facilitated the theft of over $144 million from approximately 7,300 wallets. The ongoing attacks have raised alarms within the cryptocurrency community, as researchers warn that the situation is far from resolved.

Coldcard, a physical device designed to securely store private Bitcoin keys offline, was believed to be a bastion of security for cryptocurrency holders. However, hackers have exploited a critical flaw that allowed them to siphon more than 1,596 Bitcoin from users. The initial wave of thefts occurred within a mere 41-minute window on July 30, as identified by researchers at Galaxy Digital, a financial services firm.

The amount stolen has escalated dramatically, jumping from an initial estimate of $98 million to a staggering $144 million. “The attack is ONGOING,” Galaxy researchers stated, highlighting the urgency of the situation.

Coinkite, the Canadian company behind Coldcard, expressed deep regret over the incident. In a statement to Information Age, they acknowledged the distress caused to their users and emphasized their commitment to security. CEO Rodolfo Novak took to social media platform X to apologize, stating, “I’m sorry and I’m devastated. Our team is heartbroken.”

How the Hackers Exploited the Vulnerability

The root cause of the breach was detailed in an advisory from Block, a fintech company founded by Jack Dorsey. Experts identified a misconfiguration in Coldcard devices that led to the bypassing of their hardware randomness generator, a crucial component for secure key generation. Instead of utilizing Coldcard’s advanced randomness feature, affected devices defaulted to a less secure, software-based random number generator. This flaw allowed attackers to infer outputs and siphon funds without needing physical access to the devices.

Notably, this vulnerability was detected as early as March 2021, raising questions about the oversight in addressing such a critical issue.

Urgent Action Required for Coldcard Users

Bitcoin security experts at WizardSardine have advised Coldcard users to take immediate action. If a user’s key was generated on a Coldcard device, they may be at risk. Although a firmware update has been rolled out, it does not automatically secure the funds already at risk. “Thousands of Bitcoins have already been drained, and this is only the beginning,” WizardSardine warned.

Coinkite has destroyed its remaining inventory of devices manufactured with the vulnerable firmware but has encouraged users to retain their affected devices for potential recovery of lost funds. In the meantime, Novak has urged users to transfer their funds to safer wallets.

The Ongoing Theft and Consolidation of Stolen Funds

According to Galaxy Digital, the stolen Bitcoin is currently consolidated in four blockchain addresses, with the initial heist representing about $98 million. Researchers noted that the transactions were executed in coordinated batches, primarily affecting individual users rather than institutions or exchanges.

As of Tuesday, Galaxy reported that the thefts are still occurring, with additional waves of attacks surfacing. Alex Thorn, head of firmwide research at Galaxy, is investigating a potential fourth wave, which could further increase the total damages to approximately $181 million.

Coldcard has committed to working closely with affected customers and is expected to release a comprehensive technical postmortem in the coming days. “The last three days have been some of the hardest in this company’s history,” the company stated. “We owe the community better, and we’re beginning to understand the many ways in which our best efforts and designs could have allowed for this to happen.”

As the cryptocurrency community grapples with this unprecedented breach, the incident serves as a stark reminder of the vulnerabilities that can exist even in the most trusted security products. Users are urged to remain vigilant and proactive in safeguarding their digital assets.

Disclaimer

This article was not written or endorsed by the site’s editorial author.
It is provided for informational and entertainment purposes only, and may be lightly edited for factual clarity or accuracy when necessary.