A software vulnerability affecting Coldcard bitcoin hardware wallets has reportedly allowed hackers to steal more than US$100 million in cryptocurrency from thousands of addresses.
Coldcard is produced by Toronto-based Coinkite and is designed to keep bitcoin wallet credentials offline. According to blockchain intelligence firm Galaxy Research, three confirmed waves of attacks resulted in approximately 1,596 bitcoin being stolen from roughly 7,300 addresses. A suspected fourth wave could increase the total loss to about 2,055 bitcoin, valued at roughly US$130 million.
Coinkite said the vulnerability originated in firmware dating back to March 2021. Instead of relying on the intended hardware-based random number generator when creating wallet seeds, affected firmware used a deterministic pseudo-random generator, potentially allowing attackers to reconstruct users’ seed phrases and gain access to their bitcoin.
The company has released firmware updates and advised affected users to move their funds to wallets created with new seed phrases. Coinkite said its investigation remains underway and that information related to attacker and victim addresses has been shared with law enforcement, cryptocurrency exchanges and cyber-investigation organizations.
The post Hackers Steal More Than US$100M in Bitcoin Through Toronto-Made Coldcard Wallets appeared first on Canadian Fraud News Inc. | Fraud related news | Fraud in Canada.
Originally published on Canadian Fraud News.
0 Comments