Hackers reportedly drained more than $100 million US worth of bitcoin from Coldcard hard wallets, according to blockchain intelligence firm Galaxy Research (new window).
Here’s what we know about the ongoing hack, who is affected and what you should do to secure your cryptocurrency.
How Coldcard works
Coldcard (new window), created by Toronto-based company Coinkite, is also known as a hardware wallet — but it doesn’t actually store any bitcoin for you.
Bitcoin remains on the public blockchain network, but a Coldcard adds an extra layer of security by storing seed phrases
offline — without ever needing to be connected to the Internet — inside of the physical device.
Seed phrases
are a sequence of random words, meant to be difficult or impossible to guess, which act as a master key to the bitcoin-only wallet.
Two different types of bitcoin-only hardware wallets that are featured on Coldcard’s website, which were created by Toronto-based company Coinkite.
Photo: Coldcard.com
The seed phrases, or keys, act as a digital signature that allow a user to authorize and sign transactions, as the owner of the bitcoin.
The wallet is marketed as cold storage
for long-term bitcoin users who want to keep their keys offline and has been widely praised (new window) by users and security experts as one of the most secure (new window) places to store bitcoin.
What happened
On Thursday, Coinkite warned (new window) its users of a bug in the software that allowed hackers to reconstruct wallet seed phrases.
That major vulnerability in its software allowed waves of attacks where hackers were able to gain access to users’ bitcoin wallets, without ever needing to physically get ahold of the device.
As of Monday, an on-chain analysis by Galaxy Research said that three confirmed attack waves and a number of other smaller incidents
have resulted in 1,596 bitcoin stolen from roughly 7,300 addresses, it said in a post on X (new window).
If a suspected fourth wave is also verified, the total could jump to some 2,055 bitcoin lost, which is worth roughly $130 million US.
It’s unclear who is behind the attacks.
Rodolfo Novak, the co-founder and CEO of Coinkite, advised anyone who has generated a seed using a Coldcard wallet, to move your funds now,
after releasing firmware updates for affected product, according to an advisory on its website (new window).
We know an apology doesn’t return anyone’s funds. We know we’ll have to earn back our users’ trust,
Novak said in a post on X on Friday.
CBC News has reached out to Coinkite but did not immediately hear back.
In an update on Sunday (new window), Coinkite acknowledged that the exploited flaw originated in March 2021, where instead of generating wallet seeds through the intended hardware-backed true random number generator, affected firmware had relied on a deterministic pseudo-random generator. The company said it destroyed remaining inventory manufactured with the vulnerable firmware, and shipment was halted when the vulnerability was confirmed.
Novak warned other developers in his statement, adding that AI is to blame.
To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it’s already being read by attackers and defenders alike.
How users are affected
All Coldcard users are at risk of their wallet potentially being accessed as a result of this software bug.
Roughly 90 per cent of the stolen bitcoin has not moved, meaning the tokens are still sitting in the same wallets where they were sent after the reported theft, according to Galaxy Research.
That means they have not been further transferred to another wallet, sold or exchanged, according to the firm.
Bitcoin transactions, which are public on the blockchain, can be tracked down and hackers could want to wait before they move the stolen funds.
Details from the ongoing investigation into the hacks, such as attacker and victim addresses, have been shared with U.S. law enforcement agencies, cryptocurrency exchanges and cyber-investigation groups, the research firm said.
It is essential that we continue to identify additional attacker addresses, especially as new, opportunistic attackers emerge, so that we can report their addresses to authorities,
Galaxy Research said.
The attack exposes the fallacy of your crypto being offline,
said Aneirin Flynn, CEO of cybersecurity technology firm FailSafe, in an interview with Bloomberg (new window).
The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.
What you should do
Don’t keep your bitcoin where it is if you think your wallet may be compromised.
Installing Coldcard’s new firmware protects only wallets created after the fix, according to Coinkite, which means that existing seed phrases generated on vulnerable devices remain at risk and should be replaced.
The Canadian security company advised customers to install the latest update for their device.
Do not generate a new seed on any of these models until the update is installed,
Galaxy Research said.
Coinkite added that its investigation is underway and a formal technical review will be released as soon as possible.
But some experts say the harm is already been done.
LISTEN | What’s happening with cryptocurrency? (new window)
The workaround for this isn’t easy or intuitive to deal with,
Brent Arnold, a cybersecurity lawyer and partner and data breach coach with Toronto-based INQ Law, told CBC News on Tuesday.
And lots of people won’t have heard about this until it’s too late.
Affected Coldcard users have the option to move their funds elsewhere, to another company that holds the assets on the users’ behalf.
If you are using a Coldcard and unsure whether it’s safe, migrate your funds to a safe address at a custodian/exchange or a fresh seed,
Galaxy Research (new window) said in a post on X.
Coinkite also advised its customers not to dispose of the device if it has been affected.
It may become essential if funds are recovered. Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible,
it said.
With files from Sara Jabakhanji and Anis R. Heydari
Click Here For The Original Source
