Threat Intelligence Brief
Curated summary with source attribution
Source: cbc.ca
Threat Risk: High
Victim: Coinkite Coldcard users
Incident: Exploitation of a seed generation software bug in Coldcard hardware wallets.
Impact: Theft of approximately 1,596 to 2,055 BTC, valued at over $100 million.
Attacker: Unidentified threat actors
Analysis: A software bug originating in March 2021 allowed attackers to mathematically reconstruct private seed phrases without requiring physical access to the devices. This vulnerability completely undermined the ‘cold storage’ security model by enabling remote access to private keys. Multiple waves of attacks have already targeted thousands of addresses, resulting in massive financial losses.
Recommendations: Immediately migrate funds from affected Coldcard wallets to a fresh, secure seed address.; Apply the latest firmware updates provided by Coinkite to mitigate the vulnerability.; Avoid reusing seed phrases generated on devices produced during the affected period.
Source: CBC News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source