What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin

Toronto-based company Coinkite advised its users to 'move your funds now'

If you're a bitcoin user, then you may be familiar with Coldcard — a bitcoin-only hardware wallet that has been the latest target of a data breach.

Hackers reportedly drained more than $100 million US worth of bitcoin from Coldcard hard wallets, according to blockchain intelligence firm Galaxy Research.

Here's what we know about the ongoing hack, who is affected and what you should do to secure your cryptocurrency.

How Coldcard works

Coldcard, created by Toronto-based company Coinkite, is also known as a hardware wallet — but it doesn't actually store any bitcoin for you.

Bitcoin remains on the public blockchain network, but a Coldcard adds an extra layer of security by storing "seed phrases" offline — without ever needing to be connected to the Internet — inside of the physical device.

"Seed phrases" are a sequence of random words, meant to be difficult or impossible to guess, which act as a master key to the bitcoin-only wallet.

The seed phrases, or keys, act as a digital signature that allow a user to authorize and sign transactions, as the owner of the bitcoin.

The wallet is marketed as "cold storage" for long-term bitcoin users who want to keep their keys offline and has been widely praised by users and security experts as one of the most secure places to store bitcoin.

What happened

On Thursday, Coinkite warned its users of a bug in the software that allowed hackers to reconstruct wallet "seed phrases."

That major vulnerability in its software allowed waves of attacks where hackers were able to gain access to users' bitcoin wallets, without ever needing to physically get ahold of the device.

As of Monday, an on-chain analysis by Galaxy Research said that three confirmed attack waves and a number of other "smaller incidents" have resulted in 1,596 bitcoin stolen from roughly 7,300 addresses, it said in a post on X.

If a suspected fourth wave is also verified, the total could jump to some 2,055 bitcoin lost, which is worth roughly $130 million US.

It's unclear who is behind the attacks.

  • Federal government plans to ban crypto ATMs to stop scammers from defrauding Canadians
  • Waterboarding, sexual assault, disguises: Details of terrifying $2M B.C. bitcoin hostage-taking revealed

Rodolfo Novak, the co-founder and CEO of Coinkite, advised anyone who has generated a seed using a Coldcard wallet, to "move your funds now," after releasing firmware updates for affected product, according to an advisory on its website.

"We know an apology doesn't return anyone's funds. We know we'll have to earn back our users' trust," Novak said in a post on X on Friday.

CBC News has reached out to Coinkite but did not immediately hear back.

In an update on Sunday, Coinkite acknowledged that the exploited flaw originated in March 2021, where instead of generating wallet seeds through the intended hardware-backed true random number generator, affected firmware had relied on a deterministic pseudo-random generator. The company said it destroyed remaining inventory manufactured with the vulnerable firmware, and shipment was halted when the vulnerability was confirmed.

Novak warned other developers in his statement, adding that AI is to blame.

"To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike."

How users are affected

All Coldcard users are at risk of their wallet potentially being accessed as a result of this software bug.

Roughly 90 per cent of the stolen bitcoin has not moved, meaning the tokens are still sitting in the same wallets where they were sent after the reported theft, according to Galaxy Research.

That means they have not been further transferred to another wallet, sold or exchanged, according to the firm.

Bitcoin transactions, which are public on the blockchain, can be tracked down and hackers could want to wait before they move the stolen funds.

Details from the ongoing investigation into the hacks, such as attacker and victim addresses, have been shared with U.S. law enforcement agencies, cryptocurrency exchanges and cyber-investigation groups, the research firm said.

"It is essential that we continue to identify additional attacker addresses, especially as new, opportunistic attackers emerge, so that we can report their addresses to authorities," Galaxy Research said.

The attack "exposes the fallacy of your crypto being offline," said Aneirin Flynn, CEO of cybersecurity technology firm FailSafe, in an interview with Bloomberg.

“The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered."

What you should do

Don't keep your bitcoin where it is if you think your wallet may be compromised.

Installing Coldcard's new firmware protects only wallets created after the fix, according to Coinkite, which means that existing seed phrases generated on vulnerable devices remain at risk and should be replaced.

The Canadian security company advised customers to install the latest update for their device.

"Do not generate a new seed on any of these models until the update is installed," Galaxy Research said.

Coinkite added that its investigation is underway and a "formal technical review will be released as soon as possible." But some experts say the harm is already been done.

LISTEN | What's happening with cryptocurrency?:"The workaround for this isn't easy or intuitive to deal with," Brent Arnold, a cybersecurity lawyer and partner and data breach coach with Toronto-based INQ Law, told CBC News on Tuesday.

"And lots of people won't have heard about this until it's too late."

Affected Coldcard users have the option to move their funds elsewhere, to another company that holds the assets on the users' behalf.

"If you are using a Coldcard and unsure whether it's safe, migrate your funds to a safe address at a custodian/exchange or a fresh seed," Galaxy Research said in a post on X.

Coinkite also advised its customers not to dispose of the device if it has been affected.

"It may become essential if funds are recovered. Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible," it said.

With files from Sara Jabakhanji and Anis R. Heydari