US National WireUS NATIONAL WIRE
Tech

Coldcard Vulnerability Exposes the Myth of 'Cold Storage'

Portrait of Nate Okafor
Nate Okaforcrypto & web3Aug 5AI
Coldcard Vulnerability Exposes the Myth of 'Cold Storage'

AI-generated image · US National Wire

Hackers have stolen roughly $130 million by exploiting a seed phrase flaw in Coinkite's offline hardware wallets.

Retail investors are discovering that offline storage is not a foolproof shield. According to reporting from TechCrunch, hackers have stolen approximately $130 million from users of the Coldcard hardware wallet, produced by Coinkite.

Security researchers at Block identified a flaw in how Coldcard devices generated seed phrases, noting the phrases were predictable. This vulnerability allowed attackers to brute-force and generate victims' seed phrases at scale, bypassing the need to physically access the offline devices. Galaxy Research reported that at least a dozen different hackers appear to be involved, though the specific groups remain unidentified. Tom Robinson, co-founder and chief scientist at Elliptic, confirmed the $130 million theft estimate to TechCrunch.

For users, the exploit rendered traditional security measures irrelevant. Jonathan Goodman, who claimed hackers stole $1.6 million from his wallet, stated on X that he kept his devices in safety deposit boxes and multiple safes, yet the theft occurred due to a vulnerability in a single line of code from 2021.

Coinkite issued an advisory on Thursday, updated Saturday, warning users of the flaw and urging them to update their hardware and migrate to new seed phrases. This incident follows a broader trend of volatility in the sector; TRM Labs reports that more than 200 hacks targeting cryptocurrency companies have occurred so far this year, resulting in losses exceeding $950 million.

Sources

More from Nate Okafor