Security researchers at Block discovered that the affected hardware wallets utilized a predictable pattern when generating seed phrases, rendering the devices' offline protection moot. Rather than breaking into physical safes or digital vaults, attackers utilized the flaw to brute-force the keys, effectively manufacturing duplicates of the credentials. The breach has compromised at least a dozen different groups of attackers, according to data from Galaxy Research.
For victims like Jonathan Goodman, who reported a loss of $1.6 million, the theft highlights the precarious nature of hardware security. Despite storing devices in multiple physical safes and never connecting them to the internet, Goodman found his assets drained due to a single line of vulnerable code introduced in 2021. Coinkite, the manufacturer of Coldcard, issued an advisory urging users to update their firmware and migrate to new seed phrases to secure their remaining holdings. This incident adds to a broader trend of crypto-related heists, with over $950 million lost across 200 separate attacks this year.

Comments (0)
No comments yet. Be the first!