Key facts
- Hackers are exploiting a vulnerability in Coldcard hardware wallets, allowing them to guess predictable seed phrases.
- Over $130 million in Bitcoin has been stolen from affected Coldcard users.
- The exploit affects specific Coldcard Mk3, Mk4, Mk5, and Q devices with certain firmware versions.
- Coldcard manufacturer Coinkite has issued an advisory urging users to update devices and migrate funds.
- Trezor and Foundation have warned of increased phishing attempts targeting hardware wallet owners.
- Wallets created using the dice-roll option on affected devices are considered safe.
Hackers are exploiting a vulnerability in Coldcard hardware wallets, allowing them to guess predictable seed phrases and steal over $130 million in Bitcoin. The flaw, dormant in firmware since 2021, affects specific Coldcard Mk3, Mk4, Mk5, and Q devices with certain firmware versions. Wallets created using the dice-roll option are considered safe.
Coinkite, the manufacturer of Coldcard, has issued an advisory urging users to update their devices and migrate their funds to newly generated seed phrases. Blockchain security firms, including Galaxy Research and Elliptic, have confirmed multiple waves of thefts, with estimates of total losses reaching $130 million. One affected user, Jonathan Goodman, reported losing $1.6 million despite taking precautions.
Hardware wallet firms Trezor and Foundation have also warned of an increase in phishing attempts targeting users, leveraging the concern surrounding the Coldcard exploit to trick individuals into revealing recovery phrases or downloading malicious software.
