A serious security breach has compromised Coldcard, a popular Bitcoin hardware wallet, leading to an estimated theft of $89 million. The attack was first identified on July 30 and has affected thousands of users worldwide. Galaxy Research reported that the initial attack drained over 1,082 Bitcoin, valued at $70 million, from 1,196 addresses in less than an hour. The stolen funds were traced to four addresses controlled by the attackers, suggesting an automated process was used.

Further analysis revealed additional waves of attacks on August 1, increasing the total stolen to 1,367 Bitcoin, approximately $88.6 million, affecting 4,385 addresses. Galaxy Research has advised users to move their funds from Coldcard wallets to safer locations immediately. They have also reported nearly 600 addresses believed to be holding stolen funds to federal investigators and cyber investigators across the industry.

The breach originated from a firmware vulnerability in the Coldcard wallet. This flaw, dating back to 2021, involved the wallet's failure to consistently use a hardware-based random-number generator for creating wallet seeds. Instead, it occasionally defaulted to a less secure, deterministic generator. This allowed attackers to reproduce wallet keys offline, compromising the security of the funds.

Coinkite, the company behind Coldcard, has released updated firmware for all affected models and urged users to update their devices promptly. They advised against generating new seeds on affected models until the fix is applied. The vulnerability impacts wallets using Mk2 or Mk3 version 4.0.1 through 4.1.9, unless protected by a strong, unique BIP-39 passphrase. Additionally, seeds generated on Mk4, Q, and Mk5 versions before the firmware update have reduced security due to lower entropy levels.