Cybercriminals Steal More Than $130 Million in Cryptocurrency Through Vulnerability in Offline Wallets

According to experts and blockchain security companies, massive cryptocurrency thefts have recently been detected from one of the offline hardware wallets previously considered among the safest. Hackers exploited a security flaw in Coldcard devices manufactured by Coinkite and managed to steal at least $130 million worth of digital assets. The incident has caused a major stir in the cybersecurity world, as offline wallets have long been regarded as the most reliable way to store crypto assets. TechCrunch.com reports on it.
Research firm Galaxy Research reported that the digital heist may have been carried out by several independent cybergroups rather than a single group, and their identities remain unknown. Tom Robinson, co-founder of cryptocurrency-tracking company Elliptic, confirmed to TechCrunch that the total amount stolen was approximately $130 million. According to TRM Labs, more than 200 hacking attacks have been carried out against cryptocurrency companies since the beginning of this year, with total losses exceeding $950 million.
Where Did the Main Protection System of Offline Wallets Fail?
The main advantage of hardware wallets such as Coldcard is that they operate without an internet connection. Bitcoin holders keep their private keys, or seed phrases representing their passwords, completely offline. This process is known as cold storage, a method designed to provide greater security than “hot” wallets in conventional online or exchange accounts. Although the coins on the main blockchain remain in place, access to them should be secured solely by the secret password stored on the offline device.However, researchers at Block Security found that hackers had discovered a vulnerability in the process used by Coldcard wallets to generate users’ seed phrases. It turned out that these keys were not sufficiently random and could be predicted in advance. After determining the rules used to generate the codes, the cybercriminals were able to calculate victims’ secret words through brute force, or systematic mathematical guessing. Experts said that instead of breaking into the safe, the hackers had found a way to mass-produce its key.
One of the affected users, Jonathan Goodman, wrote on his X social media page that he had lost $1.6 million and had followed all security rules strictly. He said he had never shared his secret words with anyone, his devices had never been connected to the internet, and all his data was stored in safes. According to him, none of this helped because a single-line vulnerability introduced into the device’s software in 2021 put the entire system at risk.























Comments 0
…