Hackers steal $130m from ‘secure’ offline crypto wallets – Claril Noticias

A coordinated series of cyberattacks has enabled hackers to steal more than $130 million (£100 million) from offline Coldcard hardware wallets, exploiting a critical firmware vulnerability that left supposedly secure private keys exposed.

A Multi-Million Dollar Security Breach

At least a dozen distinct hacking entities are currently targeting Bitcoin investors who safeguard their assets using Coldcard hardware wallets, manufactured by Coinkite. While the precise identities behind these digital thefts remain unknown, evidence suggests that multiple independent groups are actively exploiting the vulnerability, according to Galaxy Research.

The research firm confirmed that losses have climbed to approximately $130 million. Tom Robinson, co-founder and chief scientist of blockchain analytics firm Elliptic, validated this estimate, confirming that the figure is substantially accurate.

The Rising Tide of Crypto Heists

This incident represents the latest in a relentless wave of high-value cryptocurrency thefts. So far this year, according to blockchain intelligence firm TRM Labs, the industry has suffered more than 200 targeted hacks against cryptocurrency firms, culminating in total losses exceeding $950 million.

Why Offline ‘Cold’ Storage Failed

The ongoing campaign against Coldcard users is particularly alarming because hardware wallets are widely marketed as the gold standard of digital asset security. In theory, storing assets offline is meant to eliminate the risk of remote digital exploitation entirely.

Typically, Bitcoin owners secure their private keys or “seed phrases”—the cryptographic passwords to their funds—on a physical Coldcard device that never connects to the internet. While the Bitcoin itself remains on the public blockchain, the key required to authorise transactions resides strictly offline. This offline setup defines a “cold” wallet, distinguishing it from “hot” wallets, which are connected to the internet via mobile apps, web browser extensions, or accounts on centralised exchanges like Binance and Coinbase.

The Flaw: Predictable Seed Phrases

However, security researchers have discovered that the offline barrier was bypassed due to a fundamental flaw in how Coldcard devices generated these crucial seed phrases. The system generated highly predictable phrases, according to security analysts at Block. By identifying this pattern, attackers did not need to physically compromise the devices; they simply used brute-force computational power to replicate the victims’ private keys.

By mastering the underlying generation pattern, the hackers bypassed the need to breach any physical safes. Instead, they effectively developed a method to manufacture duplicate keys at an industrial scale.

‘I Did Everything Right’: A Victim’s Story

The devastating impact of the exploit is clear in the accounts of affected users. Jonathan Goodman, a victim who reported losing $1.6 million from his Coldcard wallet, shared his frustration publicly. “Perhaps the hardest part about this is that I did everything right,” Goodman wrote on X. He explained that he had never shared his seed phrase, kept his devices entirely disconnected from the internet, and stored his backups across multiple physical safes and safety deposit boxes.

“None of it mattered,” Goodman added. “All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability.”

Coinkite’s Urgent Call to Action

In an official security advisory, Coinkite alerted users to the critical vulnerability. The manufacturer has strongly urged all customers to update their device firmware immediately and migrate their funds to entirely new, securely generated seed phrases.

Coinkite did not immediately respond to requests for comment regarding the ongoing thefts.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *