Hackers have exploited a software vulnerability in a popular “cold” Bitcoin wallet, widely regarded as one of the safest ways to store cryptocurrency, stealing tens of millions of dollars in an ongoing attack.
Canada-based Coinkite, the maker of Coldcard hardware wallets, alerted users late last week that a flaw affecting the cryptographic keys protecting some Bitcoin wallets had compromised their security.
As of Monday, August 3, attackers had drained about 1,367 Bitcoin, valued at approximately $86 million, from more than 4,500 wallets, according to Galaxy Research.
Coldcard devices are designed to store Bitcoin in offline, or “cold,” wallets, which are considered more secure than internet-connected wallets because they are isolated from online threats.
However, a software flaw in Coldcard devices made the generated “seed phrase,” the sequence of words used to recover and access a cryptocurrency wallet — predictable, according to a report by Block’s engineering team.
“It exposes the fallacy of your crypto being offline,” said Aneirin Flynn, CEO of cybersecurity technology firm Failsafe. “The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.”
For some users, the attacks initially seemed unimaginable. One of the victims, Jonathan Goodman, said he assumed he had not been affected until he checked his wallet and discovered otherwise.
“The moment it loaded I knew I was screwed because I saw red lines for withdrawals,” he told Bloomberg. “Between 9.36 and 9.43 pm on Jul 29, all three of my wallets were completely drained.”
According to Block, the root of the problem was Coinkite’s implementation of the random number generator used to create the wallet recovery, or “seed,” phrases, making them vulnerable to prediction.
