19.1 C
Egypt
Saturday, August 29, 2026
HomeLocal NewsFinanceColdcard Data Breach: $100M Bitcoin Theft Shock

Coldcard Data Breach: $100M Bitcoin Theft Shock

Date:

Related stories

“Indigenous-led Opera ‘Empire of Wild’ Transforms Folklore”

In Cherie Dimaline's novel "Empire of Wild," a trio...

“Saskatoon Man Faces Charges for Synagogue Vandalism”

A man hailing from Dundurn, Saskatchewan, is currently facing...

Summer McIntosh Claims Runner-Up Spot in Women’s 200m Freestyle at Pan Pacs

Toronto's Summer McIntosh started her race lineup at the...

“Canadian Armed Forces Accelerate Unmanned Systems Exploration”

The Canadian Armed Forces conducted a comprehensive assessment of...

“The Tragically Hip Guitarist Reflects on 10-Year Farewell”

A decade has passed since The Tragically Hip's farewell...

If you’re someone who uses bitcoin, you might have heard of Coldcard, a hardware wallet exclusively for bitcoin that recently fell victim to a data breach.

Galaxy Research, a blockchain intelligence firm, reported that hackers managed to siphon off over $100 million US worth of bitcoin from Coldcard hardware wallets.

Here’s an overview of the ongoing breach, its impact on users, and steps to safeguard your cryptocurrency.

Understanding Coldcard

Coldcard, developed by Coinkite, a Toronto-based company, is a type of hardware wallet that does not store your bitcoin directly. Instead, it enhances security by storing “seed phrases” offline within the physical device, disconnected from the internet.

These seed phrases, acting as master keys, are a series of random words that are challenging to guess, enabling users to authorize and sign transactions as the rightful owner of the bitcoin.

Two types of Bitcoin wallets are displayed on a website.
Two different bitcoin-only hardware wallets showcased on Coldcard’s website, designed by Coinkite, a Toronto-based company. (Coldcard.com)

Marketed as “cold storage,” Coldcard is favored by long-term bitcoin users seeking to keep their keys offline, earning accolades from both users and security experts for its top-notch security features.

The Incident

Coinkite issued a warning to its users about a software bug on Thursday, allowing hackers to reconstruct wallet seed phrases. Exploiting this critical vulnerability, hackers launched multiple attacks, gaining unauthorized access to users’ bitcoin wallets without physical access to the device.

As per Galaxy Research’s on-chain analysis, three confirmed attack waves and several smaller incidents led to the theft of 1,596 bitcoin from approximately 7,300 addresses. Should a fourth wave be confirmed, the total losses could reach around 2,055 bitcoin, valued at about $130 million US. The perpetrators behind these attacks remain unidentified.

Rodolfo Novak, Coinkite’s co-founder and CEO, urged users who generated a seed using a Coldcard wallet to transfer their funds immediately, following the release of firmware updates for affected products, as stated in an advisory on their website.

In an update on Sunday, Coinkite acknowledged that the software flaw emerged in March 2021. The affected firmware, instead of using a hardware-backed true random number generator, relied on a deterministic pseudo-random generator. Coinkite ceased the distribution of devices with the vulnerable firmware and destroyed remaining inventory upon confirming the vulnerability.

Novak cautioned other developers in a statement, attributing the issue to AI and emphasizing the need for heightened vigilance.

User Impact

All Coldcard users face potential risks due to the software bug

Latest stories