Coldcard Hardware Wallet Breach Results in $88 Million Bitcoin Theft
Canadian cryptocurrency hardware wallet manufacturer Coinkite has destroyed its remaining inventory of Coldcard devices after a firmware vulnerability led to the theft of over $88 million in bitcoin from customers. The breach, linked to a flaw first identified in March 2021, was exploited by attackers to siphon funds from 4,585 wallet addresses, with cybersecurity firm Galaxy Research confirming the loss of at least 1,367.05 BTC (approximately $88.6 million).
Coinkite halted shipments of affected devices and released a patched firmware update to prevent further exploitation. The company urged users with compromised devices to retain them for potential fund recovery efforts, stating that its legal team is coordinating with law enforcement across multiple jurisdictions to identify the perpetrators. However, Coinkite has not indicated whether it will compensate victims.
Blockchain analysis by Chainalysis revealed that the attackers targeted high-value wallets early in the campaign, with two victims alone losing a combined $4 million. The firm noted that the cumulative stolen value reached roughly $30 million within the first 10 minutes, suggesting the attackers had studied victim wallets in advance. Dozens of bitcoin holders have since reported losses on social media.
A Coinkite senior official partially attributed the incident to AI-assisted code reviews, claiming that cybercriminals leveraged the technology to uncover latent vulnerabilities faster than traditional security experts could detect them. The FBI has not commented on whether it is investigating the breach.
Source: https://therecord.media/bitcoin-theft-coldcard-cyberattack
Coinkite Inc. cybersecurity rating report: https://www.rankiteo.com/company/coinkite
"id": "COI1785795951",
"linkid": "coinkite",
"type": "Vulnerability",
"date": "3/2021",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '4,585 wallet addresses '
'(1,367.05 BTC lost)',
'industry': 'Cryptocurrency Hardware Wallets',
'location': 'Canada',
'name': 'Coinkite',
'type': 'Company'}],
'attack_vector': 'Firmware Vulnerability',
'customer_advisories': 'Public advisory to update firmware and report losses.',
'data_breach': {'data_exfiltration': 'Yes (funds siphoned)',
'number_of_records_exposed': '4,585 wallet addresses',
'sensitivity_of_data': 'High (direct access to cryptocurrency '
'funds)',
'type_of_data_compromised': 'Cryptocurrency wallet private '
'keys/access'},
'date_detected': '2021-03',
'description': 'Canadian cryptocurrency hardware wallet manufacturer Coinkite '
'destroyed its remaining inventory of Coldcard devices after a '
'firmware vulnerability led to the theft of over $88 million '
'in bitcoin from customers. The breach, linked to a flaw first '
'identified in March 2021, was exploited by attackers to '
'siphon funds from 4,585 wallet addresses, with cybersecurity '
'firm Galaxy Research confirming the loss of at least 1,367.05 '
'BTC (approximately $88.6 million).',
'impact': {'brand_reputation_impact': "Significant (Coinkite's reputation as "
'a security-focused provider)',
'customer_complaints': 'Dozens reported losses on social media',
'data_compromised': 'Cryptocurrency wallet private keys/access',
'financial_loss': '$88.6 million',
'operational_impact': 'Shipments halted, inventory destroyed',
'payment_information_risk': 'High (cryptocurrency theft)',
'systems_affected': 'Coldcard hardware wallets'},
'initial_access_broker': {'entry_point': 'Firmware vulnerability',
'high_value_targets': 'Yes (two victims lost $4 '
'million combined)',
'reconnaissance_period': 'Likely studied victim '
'wallets in advance '
'(evidenced by early '
'targeting of high-value '
'wallets)'},
'investigation_status': 'Ongoing (law enforcement coordination)',
'lessons_learned': 'AI-assisted code reviews may accelerate vulnerability '
'discovery by attackers; high-value targets require '
'enhanced protection; firmware security requires rigorous '
'testing.',
'motivation': 'Financial Gain',
'post_incident_analysis': {'corrective_actions': 'Patched firmware, destroyed '
'vulnerable inventory, '
'coordinated with law '
'enforcement, and advised '
'users on recovery steps.',
'root_causes': 'Latent firmware vulnerability, '
'potentially exacerbated by '
'AI-assisted code reviews used by '
'attackers to discover flaws faster '
'than traditional security '
'measures.'},
'recommendations': 'Enhance firmware security audits, implement multi-layered '
'security for high-value wallets, improve incident '
'response coordination with law enforcement, and consider '
'victim compensation frameworks.',
'references': [{'source': 'Galaxy Research'},
{'source': 'Chainalysis'},
{'source': 'Social Media Reports'}],
'response': {'communication_strategy': 'Public advisory to users, social '
'media updates',
'containment_measures': 'Halted shipments of affected devices, '
'destroyed remaining inventory',
'incident_response_plan_activated': 'Yes',
'law_enforcement_notified': 'Yes (coordinating with multiple '
'jurisdictions)',
'recovery_measures': 'Urged users to retain compromised devices '
'for potential fund recovery',
'remediation_measures': 'Released patched firmware update',
'third_party_assistance': 'Galaxy Research, Chainalysis'},
'stakeholder_advisories': 'Coinkite advised users to update firmware and '
'retain compromised devices for potential recovery.',
'title': 'Coldcard Hardware Wallet Breach Results in $88 Million Bitcoin '
'Theft',
'type': 'Data Breach, Theft',
'vulnerability_exploited': 'Latent firmware flaw in Coldcard hardware wallets'}