Total Losses From Coldcard Hack Top $100 Million as White Hat Hacker Drains Vulnerable Wallets

Coldcard hack losses

Key highlights:

  • The Coldcard hack is still ongoing, with over $100 million worth of Bitcoin stolen from unsuspecting users
  • Some white-hat hackers are reportedly now draining vulnerable BTC from before malicious hackers can get to the funds
  • The identity of the hackers remains in question, with experts befuddled by the sophistication in planning and the carelessness in discretion

Four days after the first thefts of

A critical firmware flaw in Coldcard Bitcoin hardware wallets allowed hackers to steal BTC from unsuspecting users. An initial postmortem confirmed that the vulnerability originated from a March 2021 firmware error that weakened seed phrase randomness, allowing attackers to reconstruct private keys offline without touching physical devices.

Since the incident, Coldcard maker Coinkite has halted shipments and destroyed remaining inventory. While the Canadian-based company rolled out emergency firmware patches, it noted that patches do not fix already compromised seeds, sparking a frenzy by users to move their bitcoins.

Emerging reports indicate a lawsuit against Coinkite is on the way, with affected parties leaning away from a traditional class action.

“The thinking is that assembling approximately 10-30 claimants may provide a more focused and efficient path than pursuing class certification,” said Thomas Braziel, founder of 117 Capital.

White hat begins draining affected wallets

According to an X post, a white hat security operation has started sweeping funds from vulnerable Coldcard wallets to secure them before malicious hackers can drain them. The white hat hackers are leaning on the same offline key-reconstruction flaw used by bad actors to move Bitcoin at risk to secure custody.

Security researchers and white hat groups are actively racing against the exploiters to protect funds as efforts to contact several Coldcard users proved abortive. Bitcoin enthusiasts circulated a warning that users should not destroy compromised Coldcard wallets, noting that it will be key in the recovery process

“If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records,” said one expert.

Amid the race to secure users’ assets, opinion is split over the identity of the hackers. One demographic argues that the Coldcard attack was state-backed, citing the use of professional tooling to plan the attack in clear phases. However, consolidating over 600 BTC in one address and using “a KYC’d service provider” suggested amateurs at work.

Source:: Total Losses From Coldcard Hack Top $100 Million as White Hat Hacker Drains Vulnerable Wallets