What's Happening?
An ongoing cyberattack on Coinkite's Coldcard Bitcoin wallet has resulted in the theft of approximately $89 million. The attack began on July 30, with Galaxy Research tracking the initial wave that drained 1,082.65 Bitcoin, valued at $70 million, from
1,196 addresses within 41 minutes. The funds were traced to four attacker-controlled addresses, suggesting the activity was automated. Subsequent waves on August 1 increased the total stolen to 1,367 Bitcoin, affecting 4,385 addresses. The attack exploits a firmware vulnerability from 2021, where the wallet's random-number generator failed, allowing attackers to reproduce wallet keys offline. Coinkite has released updated firmware to address the issue and advised users to move funds to secure locations.
Why It's Important?
This incident highlights significant vulnerabilities in cryptocurrency security, particularly in hardware wallets, which are often considered more secure than software alternatives. The breach underscores the importance of robust security measures and regular updates to prevent exploitation. The financial impact is substantial, affecting thousands of users and potentially shaking confidence in cryptocurrency security. It also raises concerns about the adequacy of current security protocols in protecting digital assets, prompting a reevaluation of security practices across the industry.
What's Next?
Coinkite has urged users to update their firmware and avoid generating new seeds on affected models until the fix is applied. The company is working with federal investigators and industry compliance firms to track and recover stolen funds. The incident may lead to increased scrutiny and regulatory pressure on cryptocurrency security standards, potentially influencing future developments in digital asset protection.











