Turns out that the “most secure” place to store your Bitcoin wasn’t so secure after all.
What happened: Hackers exploited a software flaw in Coldcard devices, a Bitcoin storage wallet, to steal around US$100 million worth of Bitcoin.
Coinkite, the Toronto-based company that makes Coldcard, notified its users last week of a bug in the software that generates the “seed phrase” — a random string of words, meant to be impossible to predict, that acts as the master key to a user's Bitcoin.
The bug allowed hackers to reverse-engineer the seed phrases needed to steal users’ private keys and gain access to their Bitcoin (all without touching the physical device).
Why it matters: Because Coldcards never needed to connect to the internet, they were thought to be among the most secure ways to store Bitcoin. That illusion has now been shattered, and it’s a costly lesson that even Bitcoin holders who take security relatively seriously are still vulnerable.
One user who claimed to have lost $1.6 million of Bitcoin in the breach said his Coldcard was stored in a safety deposit box and never touched the internet, but that “none of it mattered” because of “one line in their code from 2021 that had a vulnerability.”
Zoom out: While this attack has not yet been connected to AI, the number of crypto hacks has jumped this year, and the spread of tools that make launching cyberattacks much easier raises some obvious questions about how secure digital assets will be in the future.—TS




