As CoinDesk reported Sunday (Aug. 2), the vulnerability in a 2021 firmware release for the Coldcard hardware wallet permitted the hackers — or possibly a single hacker — to siphon bitcoin from thousands of wallets in three waves of attacks.
The CoinDesk report cited findings from Galaxy Research, which says that each wave is likely the work of one attacker, though it is not clear whether the same person is behind all three. Losses across the three waves of attacks added up to 1,367 bitcoin from 4,585 addresses, the report added.
An earlier report argued that this exploit stands out from other crypto theft, which normally involves something like the breach of an exchange, or a phishing attack that steals a key. A hardwallet, meanwhile, keeps that key on a device that is never connected to the internet. That means, at least theoretically, that it should be off limits to attackers.
According to CoinDesk, researchers say that a firmware flaw in some Coldcard hardware wallets made seed phrases — made up of a very large number that is supposed to be unguessable — easy to guess, letting attackers reconstruct private keys without ever touching the wallets.
The report also noted that security companies are warning that more wallets could fall victim, as their owners cannot determine for sure if their seeds “were generated on vulnerable firmware.”
Coldcard acknowledged the issue on its website, offering users a detailed explanation of the attack and the steps they could take. The company advised customers migrating to a new key to use “care and calm.”
“Rushing a wallet migration can create a more immediate risk than the issue you are trying to address,” Coldcard said.
The incident is the latest in a series of recent crypto hacks. Last weekend, Singapore stablecoin payments company Triple-A suffered a security breach that impacted its company assets but did not touch customer funds.
Also last weekend, blockchain network WEMIX announced that an attacker had compromised ownership of its WEMIX$ stablecoin, while cryptocurrency wallet SecondFi last month said it would begin winding down following a breach that allowed attackers to steal $2.4 million.