[Photo: Shutterstock]

Galaxy Research said on July 31 local time that nearly 1,200 addresses were compromised in transactions linked to a vulnerability in the Coldcard hardware wallet, with more than 1,000 bitcoin worth $70 million at market value stolen.

According to a report by The Block, manufacturer Coinkite said on July 30 that there was an issue with seeds generated on Coldcard Mk3 devices. Coinkite warned that users who generated seeds with the Mk3 after the release of version 4.0.1 in March 2021 could have their funds at risk. It later expanded the notice to include some Mk4 and Mk5 devices and Coldcard Q firmware versions, and distributed an emergency firmware update for all affected models.

Coinkite CEO Rodolfo Novak (로돌포 노박) issued an apology on July 31, saying he would take responsibility for the firmware defect and acknowledging that the company’s review process failed to catch it. He also raised the possibility that the vulnerability was found using AI, calling it “a cold reality brought by a new AI paradigm.”

Galaxy Research later posted its findings on social media. It said it tracked the flow of funds based on a pattern identified by block engineers and shared by Clay Garrett (클레이 개럿), and found that as of July 30 all 1,082.65 bitcoin, worth about $70.2 million, was drained from 1,196 addresses between 1:10 a.m. and 1:51 a.m.

Coinkite’s notice came after a series of online reports from users that bitcoin held in Coldcard wallets had been stolen. Galaxy Research added that the nature of the vulnerability means any address generated by Coldcard could be targeted in future attacks.

Coinkite instructed users to update their firmware and generate a new seed. It added that users should first test a new wallet with a small transaction before moving all funds, and should keep existing backups until transactions are complete.

Keyword

#Galaxy Research #Coldcard #Coinkite #Bitcoin #The Block
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.