Ongoing Attacks on Coinkite’s Coldcard Bitcoin Wallet Result in Significant Stolen Funds
An alarming and continuous cyber attack targeting Coinkite’s Coldcard, a widely used Bitcoin hardware wallet, has resulted in an estimated theft of approximately $89 million, as reported by researchers. This unsettling incident began on July 30, highlighting vulnerabilities within one of the leading hardware wallets in the cryptocurrency sector.
According to findings from Galaxy Research, the attack initiated a torrent of withdrawals that drained an astonishing 1,082.65 Bitcoin—valued at around $70 million—from 1,196 distinct addresses within a swift 41-minute period. The researchers traced the digital currency back to four wallet addresses under the control of the attackers, indicating that the operation was likely automated—a concerning trend that reflects the increasing sophistication of cybercriminal activities within the realm of cryptocurrency.
Following this initial wave, Galaxy Research identified further attacks on August 1, which escalated the total amount of stolen Bitcoin to 1,367, equating to a staggering $88.6 million. The number of victimized addresses had also surged to an alarming 4,385, exposing a wider spectrum of users to potential financial loss. In a critical warning shared through a post on X, formerly known as Twitter, on August 2, Galaxy Research urged Coldcard users to transfer funds from single-signature wallets to safer locations without delay.
Additionally, the research team disclosed that they had reported approximately 600 addresses suspected of harboring funds stolen from Coldcard-generated weak entropy addresses to federal law enforcement, industry compliance organizations, and cross-industry cyber investigators. This action underscores the urgent need for vigilance within the cryptocurrency community as these attacks become increasingly prevalent.
In a related development, a report from Block’s Bitcoin Engineering and Security team, published on the same day as the initial attack, attributed the incident to a firmware vulnerability that has been present since 2021. This exploit stemmed from a defect that occasionally prevented the wallet from using a reliable hardware-based random-number generator (RNG) to create users’ wallet seeds, which are critical for securing funds. Instead, the wallet relied on a fallback generator that was deterministic, leading to insufficient randomness and, therefore, compromised cryptographic security. As a result, attackers could feasibly replicate the keys offline, thereby gaining unauthorized access to victims’ funds.
In response to this ongoing crisis, Coinkite has acted swiftly. The company has released updated firmware for all affected models and urged customers not to generate new wallet seeds on impacted devices until the necessary fixes have been implemented. In their communication, Coinkite emphasized, “Funds controlled by a seed generated on Mk2 or Mk3 version 4.0.1 (March 2021) through 4.1.9 are at risk if the seed was created without at least 50 fair, independent, private dice rolls.” They highlighted that, for wallets not secured by a robust and unique BIP-39 passphrase, the risks are considerably heightened.
Moreover, the company noted that seeds generated on Mk4, Q, and Mk5 models before the release of the fixed firmware are also susceptible to compromise, as they may exhibit only about 72 bits of entropy instead of the requisite 128 bits—another significant security shortfall.
As the situation continues to develop, there are indications that a potential fourth wave of attacks may be in progress. This was alluded to by Alex Thorn, head of firmwide research at Galaxy Research, in a post on X, raising further concerns among the cryptocurrency community and prompting stakeholders to remain alert.
Overall, the incident marks a sobering reminder of the vulnerabilities inherent in cryptocurrency technology and the pressing need for robust security measures. As cybercriminals enhance their tactics, both individuals and companies within the cryptocurrency landscape must prioritize safeguarding their assets against increasingly sophisticated attacks. The ramifications of such breaches extend beyond financial loss; they threaten the broader trust and engagement of users in the evolving cryptocurrency market. As the situation unfolds, stakeholders are urged to stay informed and take proactive steps to protect their investments.
