Hackers steal over $130 million by exploiting bug in offline hardware wallets
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain monitoring firms.
Hackers are engaged in a significant theft of cryptocurrency from offline hardware wallets, according to blockchain security firms tracking the incidents. At least a dozen hackers are reportedly targeting Bitcoin owners who use the Coldcard hardware crypto wallet, developed by Coinkite. The extent of the theft remains unclear, with multiple hacking groups suspected, as per Galaxy Research.
As of Tuesday, the research firm reported the hackers had stolen approximately $130 million. Tom Robinson, co-founder and chief scientist of crypto monitoring firm Elliptic, confirmed the estimate's accuracy. This marks the latest attempt to pilfer substantial amounts of people's cryptocurrency, with over 200 hacks targeting cryptocurrency companies this year, resulting in losses exceeding $950 million.
The ongoing attacks against Coldcard wallet owners are particularly intriguing, as the purpose of such devices is to provide a secure method for storing cryptocurrency. By storing the secret key, or seed phrase, in a Coldcard wallet, which is disconnected from the internet, Bitcoin owners aim to enhance security. However, hackers discovered a flaw in how Coldcard wallets generated users' seed phrases, making them predictable.
Armed with this knowledge, the hackers could brute-force and generate the victims' seed phrases without needing to breach the secure hardware. The hackers essentially developed a method to scale their key generation, effectively "cutting keys at scale." One victim, Jonathan Goodman, who reported losing $1.6 million from their Coldcard wallet, expressed frustration, stating that despite taking all necessary precautions, the vulnerability in the hardware created the seed phrase was the cause.
Coinkite issued an advisory on Thursday, updated on Saturday, warning users of the flaw, urging them to update their devices, and then migrate to a new seed phrase. As of the time of this report, Coinkite had not provided further comment.
Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.