security
Coldcard Hardware Wallets Face $114 Million Theft Wave Due to Firmware Vulnerability
A firmware flaw in Coldcard hardware wallets has led to a series of thefts, resulting in losses estimated at around $114 million since Thursday. The attacks exploit a vulnerability from a 2021 firmware release, allowing attackers to drain funds from affected wallets.
AS1 NewsSource: thedefiant.io
A new wave of attacks targeting Coldcard hardware wallets has resulted in estimated losses of approximately $114 million since Thursday. The breaches are linked to a firmware bug introduced in 2021, which made seed phrases guessable under certain conditions. Attackers have been able to drain over 1,800 BTC from compromised wallets.
The latest thefts are still pending confirmation, as some transactions remain replaceable in the mempool, providing a narrow window for victims to attempt to recover their coins before the transactions are confirmed and final.
Coldcard, a popular hardware wallet for Bitcoin storage, has not yet issued a public statement regarding the vulnerability or the ongoing attacks. Security experts advise affected users to monitor the mempool for their transactions and act swiftly if they detect suspicious activity.
This incident underscores the importance of firmware updates and security practices in hardware wallet management, especially for long-term Bitcoin holders. The vulnerability's exploitation highlights the risks associated with outdated firmware versions and the need for prompt updates to mitigate potential threats.
The vulnerability has led to significant financial losses for users holding Bitcoin in Coldcard wallets, emphasizing the importance of firmware security in hardware wallets.