Coldcard Exploit Drains $83 Million in Bitcoin; Raises Questions About Self-Custody

Coldcard Exploit Drains $83 Million in Bitcoin; Raises Questions About Self-Custody

An ongoing vulnerability within the Coldcard hardware wallet has resulted in the theft of over 1,300 Bitcoin, valued at approximately $83 million. The affected cryptocurrency was drained from thousands of addresses following a flaw introduced in the device’s seed-generation process during 2021. This incident is generating substantial scrutiny regarding self-custody practices and the feasibility of relying solely on verification processes.

Last week, on Monday (date unspecified), the Coldcard exploit came to light. Subsequent reports over the weekend identified a potential fourth wave of thefts related to the vulnerability. Investigations are ongoing into the extent of the damage and the methods employed by those responsible for the attack.

Jameson Lopp, Bitcoin security researcher and co-founder of Casa, has been central to analysing the ramifications of the Coldcard exploit. Speaking with The Block, Lopp emphasised the limitations of the “don’t trust, verify” mantra, stating that “verification of complex software and hardware is simply not feasible for 99.9% of the population.” Zach Herbert, founder and CEO of Foundation – the creator of the Coldcard – reportedly echoed this sentiment, suggesting the incident represents a turning point in the viability of self-custody.

Rodolfo Novak, CEO of CoinKite, took responsibility for a firmware bug within their product. He attributed the issue to accelerated vulnerability discovery driven by advancements in artificial intelligence, describing it as “a sober reality of the new AI paradigm.” CoinKite’s role highlights the potential impact of automated code review processes on security software.

Alex Thorn, Head of Research at Galaxy Digital, has reported that waves of thefts stemming from the Coldcard exploit are likely. This sentiment further underscores the severity and scale of the problem. Galaxy Digital’s research focus is observing these developments closely.

The compromised wallets were accessed through a process enabling attackers to brute-force affected devices without requiring physical possession of the hardware. Analysts estimate that up to 99.9% of users may be unable to realistically implement this “don’t trust, verify” approach effectively, according to Lopp.

As of Sunday, approximately 1,300 BTC have been drained. Investigations suggest a possible fourth wave of related thefts could occur. The vulnerability represents a significant challenge for the broader cryptocurrency ecosystem, specifically highlighting weaknesses within self-custody solutions and prompting discussion about enhanced security protocols.


Written by Daniel Brooks
Security Desk

Share