Hackers steal over $130 million by exploiting bug in offline hardware wallets

← Back to the feed

Hackers steal over $130 million by exploiting bug in offline hardware wallets

TechCrunch · 3 hours ago

Hackers have stolen more than $130 million in Bitcoin by exploiting a flaw in Coldcard, an offline "cold" hardware wallet made by Coinkite that was widely regarded as one of the safest ways to store cryptocurrency. Blockchain security researchers believe at least a dozen different hackers, likely in more than one group, are behind the ongoing thefts, which are notable because Coldcard devices are never connected to the internet, meaning victims followed standard security practice yet were still robbed.

Researchers at Block found that Coldcard's flaw lay in how it generated users' seed phrases, making them predictable and allowing attackers to brute-force the keys rather than needing to physically access any device. Galaxy Research put the losses at roughly $130 million as of Tuesday, a figure crypto monitoring firm Elliptic said was broadly accurate; one victim, Jonathan Goodman, said he lost $1.6 million despite storing his seed phrase offline in safes, tracing the fault to a vulnerable line of code dating from 2021. Coinkite issued an advisory urging users to update their devices and migrate to new seed phrases, and this incident adds to over 200 crypto hacks totalling more than $950 million in losses so far this year, according to TRM Labs.

  • Hackers exploited a Coldcard wallet flaw to steal over $130 million
  • Predictable seed-phrase generation let attackers brute-force offline wallets
  • Coinkite urges users to update devices and migrate to new seed phrases

Business Crypto Cybersecurity Technology

Read the full article at the source →