Thousands of accounts were hacked and more than US$100 million (roughly C$140 million) in bitcoin was stolen after a flaw was revealed in security devices sold by a Canada-based company.
The company, Coinkite Inc., sells “cold” bitcoin wallets that use hardware and software to keep the funds offline, which is supposed to be safer from hackers. It is a handheld device, often called a “hardware wallet.”
The company announced late last week that the wallets of some Coldcard device users had been compromised in a hack.
On July 30, Galaxy Research, a digital financial services firm, discovered that within 41 minutes, hackers had drained more than 1,000 bitcoins from more than 1,000 addresses, equal to approximately C$99 million.
By Monday, more than 1,500 tokens from 7,300 addresses had been drained, Galaxy Research reported. The hack came in three confirmed waves in addition to 14 smaller incidents, it said in a social media post.
The first wave was initially observed by engineers at Block, Inc. – another digital financial services firm – which was then corroborated by Galaxy Research based on victim reports. Seventy-three victims reached out for help tracing their Bitcoins, the financial firm said.
However, Galaxy Research warned that the findings were based on a “blockchain analysis,” and it has not verified whether every affected wallet was created using the compromised software.
According to a security advisory by CoinKite, the issue was rooted in a software update released in March 2021. In addition, a report analysis by Block’s engineering team said certain versions of Coldcards may have weakened key features as a result of a coding mistake.
The software bug may have made it easier for sophisticated hackers to be able to swipe Bitcoin in certain situations without ever needing to physically touch the devices, Block said in the report. The company released the report because the attacks may still be occurring.
‘We owe the community better’
Coinkite’s CEO Rodolfo Novak issued an apology in a social media post, saying the company was “heartbroken” and is taking “full accountability for the firmware bug.”
“I’m sorry and I’m devastated,” Novak wrote. “Our team is heartbroken about yesterday’s news.”
In a news release posted Sunday, the company said the team has been reaching out to customers and helping them move funds that were safe to move, since the funds remained as risk. It had also released new software for the affected customers.
“We’ve also been in direct contact with the wider hardware wallet and self-custody community, including other builders, researchers, and people who’ve thought hard about this kind of failure,” Coinkite said.
It said the remaining Coldcard inventory with the vulnerable software had been “destroyed,” and shipments were halted once the software issue was detected.
Although the initial problems were focused on Coldcard devices, the company has since added additional models and software versions to the list of affected products.
“There are real lessons here for us as a company. We owe the community better, and we’re beginning to understand the many ways in which our best efforts and designs could have allowed for this to happen,” the Coinkite said.
