Hacks & Exploits
Over $115 Million Lost in Coldcard Bitcoin Hack, Coinkite Issues Urgent Firmware Update
New findings from Galaxy Research reveal that losses from the Coldcard Bitcoin hack have surpassed $115 million. The research firm reported that over 200 victims have been consulted to gather intelligence on the attackers, with estimates suggesting that total losses could exceed $130 million as the investigation continues.
The hack, which began on July 31, exploited a firmware bug in Coinkite's Coldcard Mk3 devices. This bug caused the seed generation process to revert to a weak software Pseudorandom Number Generator instead of utilizing the hardware's true random number generator, allowing hackers to guess users' seed phrases. Coinkite acknowledged that the bug went unnoticed and its impact grew with each product release.
In response to the breach, Coinkite released a new firmware update on August 20, which requires users to incorporate physical randomness when generating a seed. This process now mandates at least 65 key presses, 50 rolls of a physical die, or 128 coin flips to enhance security. Users still relying on affected firmware must generate a new seed and transfer their funds to ensure safety.
Coinkite has recommended specific firmware versions for different Coldcard models to mitigate risks. The company has urged users to update their devices or move their funds to alternative storage solutions as a precautionary measure against further exploits.
FAQ
What caused the Coldcard Bitcoin hack?
The hack was caused by a firmware bug in Coinkite's Coldcard Mk3 devices that caused the seed generation process to revert to a weak software Pseudorandom Number Generator instead of using the hardware's true random number generator.
How much money has been lost due to the Coldcard hack?
New findings from Galaxy Research indicate that losses from the Coldcard Bitcoin hack have surpassed $115 million, with estimates suggesting that total losses could exceed $130 million as the investigation continues.
What steps has Coinkite taken in response to the hack?
Coinkite released a new firmware update on August 20, which requires users to incorporate physical randomness when generating a seed. This process now mandates at least 65 key presses, 50 rolls of a physical die, or 128 coin flips to enhance security.
What should users do if they are still using the affected firmware?
Users relying on the affected firmware must generate a new seed and transfer their funds to ensure safety. Coinkite has recommended specific firmware versions for different Coldcard models to mitigate risks.
How can users enhance the security of their Coldcard devices?
Users can enhance the security of their Coldcard devices by updating to the latest firmware and following the new seed generation requirements, which include using physical randomness through key presses, dice rolls, or coin flips.