How a bug in Coldcard’s code went unnoticed for years, leading to $100 million in hacked funds

A security vulnerability in Coldcard hardware wallets has led to the theft of approximately $100 million in Bitcoin from thousands of users. The flaw existed in the seed phrase generation process, undermining the security premise of offline cold storage.
The hardware wallet holding his keys, a Coldcard, had never been connected to the internet. He kept it stored in a safe deposit box. The seed phrase, which he’d never shared with anyone, was stored in a second safe deposit box. But on July 29, Goodman said, every wallet he had was emptied, every last satoshi stolen. The Toronto entrepreneur reported losing 18.25 bitcoin, worth just over $1.17 million at the time of the attack.
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in