Critical Software Bug in Hardware Wallet Giant: $70 Million Worth of Bitcoin Stolen in Just 40 Minutes
A critical software bug in Coldcard hardware wallets has resulted in the theft of approximately $70.2 million worth of Bitcoin from 1,196 different addresses.
Coinkite, one of the world’s leading names in cryptocurrency storage solutions, has come under the spotlight due to a serious security vulnerability detected in Coldcard models. On-chain analyses conducted by Galaxy Research confirmed that a total of 1,082.65 Bitcoin (BTC) was seized by cyber attackers due to this exploit.
Critical Security Vulnerability in Coldcard Models
Coinkite officially acknowledged the bug affecting the Mk3, Mk4, Mk5, and Coldcard Q models and issued an urgent warning to its users. It was stated that seed (recovery phrase) phrases created on versions from March 2021 and later are particularly at risk. In the attack that took place on July 30, it was determined that 1,196 addresses were completely drained in just 40 minutes. Once the security barrier was breached, the funds quickly moved under the attackers’ control.
Artificial Intelligence and Cyber Attack Risk
Coinkite CEO Rodolfo Novak took full responsibility, stating that the review processes failed to catch this bug. Highlighting that this vulnerability might have been discovered using artificial intelligence tools, Novak commented on the “sobering reality of the new AI paradigm.” Experts warn that AI-powered code reviews provide attackers with significant speed in identifying security flaws.
Concrete Steps Users Should Take
Users wishing to ensure their security must immediately update their devices to the latest firmware version and generate a completely new seed. It is vital to perform a test transaction with a small amount before moving all funds to the new address. Galaxy Research emphasizes that while the current attack pattern points to a single attacker, future attacks could be carried out in much different ways.