Coldcard, a leading manufacturer of Bitcoin hardware wallets, has issued an urgent advisory for users to move their funds after a critical security flaw led to the theft of approximately $116 million in Bitcoin from thousands of wallets. The breach, which unfolded over four waves of attacks, exposed a vulnerability in how the devices generated recovery seed phrases, enabling attackers to predict and exploit the phrases to drain wallets.
Immediate action required
Coldcard, owned by Canada-based Coinkite, confirmed that the flaw stemmed from a 2021 software update that altered the randomness used to generate seed phrases. The company stated in an advisory that updating firmware does not repair seeds generated by affected versions, and users must generate a new seed and migrate funds to a secured wallet. Galaxy Research estimates that 1,816 Bitcoin were stolen from over 5,200 addresses in the attack, with losses continuing to rise as of Monday.
How the attack unfolded
The theft occurred in four distinct waves, with the latest wave targeting Coldcard users on Sunday. Blockchain analysis firm Galaxy Research reported that the stolen funds were moved in batches rather than streamed, suggesting an organized effort. The vulnerability allowed attackers to reverse-engineer the predictable seed phrases generated by affected Coldcard devices, gaining unauthorized access to wallets without physical interaction with the hardware.
Company response and user guidance
Coinkite issued an open letter advising users who generated a wallet seed on Coldcard devices after the 2021 update to move their funds immediately. The company emphasized that the flaw did not compromise the hardware itself but rather the software process used to create recovery phrases. Users are instructed to generate a new seed using updated software and transfer their Bitcoin to a newly secured wallet to prevent further losses.
Broader implications for cryptocurrency security
The breach has raised concerns about the reliability of hardware wallets, which are widely regarded as one of the safest methods for storing cryptocurrency due to their offline design. Cybersecurity experts noted that the incident underscores the risks of software flaws in even the most secure storage solutions. Aneirin Flynn, CEO of cybersecurity firm Failsafe, remarked that the attack exposes the fallacy of assuming offline devices are impervious to exploitation.
What users should do now
Coldcard users who generated a wallet seed after the 2021 software update are urged to:
- Generate a new seed phrase using updated firmware.
- Transfer all funds to a newly created wallet.
- Verify the security of the new wallet before proceeding with transactions.
Coinkite has not yet attributed the attack to any specific actor, and investigations into the perpetrators remain ongoing. The company continues to work with affected users to mitigate losses and prevent further incidents.