Skip to content

130 Million Dollars Taken From Wallets That Were Never Online: One Line of Code From 2021 Made the Keys Predictable

1 min read
Share
130 Million Dollars Taken From Wallets That Were Never Online: One Line of Code From 2021 Made the Keys Predictable

The entire argument for hardware crypto wallets rests on one promise: the key never touches the internet, so nobody can take it from you. That promise has just collapsed. At least a dozen different hackers are draining the accounts of bitcoin owners using Coldcard, the device made by the Canadian firm Coinkite, and have so far taken around 130 million dollars (about 120 million euros).

The figure comes from Galaxy Research, and Tom Robinson, co-founder and chief scientist at the crypto-tracking firm Elliptic, confirmed the estimate is approximately correct. This year alone, according to TRM Labs, there have been over 200 hacks on crypto companies with total losses above 950 million dollars. The difference is that this time it was not exchanges and apps that fell, but precisely the devices that were supposed to be the last line of defence.

The mechanism is painfully simple. Coldcard generated seed phrases - the passwords that unlock the cryptocurrency - in a predictable way. Security researchers at Block found the flaw, and the hackers found it earlier. Once you know how a device makes keys, you do not have to break into the safe. You make the keys yourself, in bulk, for everyone at once.

Jonathan Goodman, who says 1.6 million dollars was stolen from him, wrote on X what explains the whole story better than any technical report: „The hardest part of all this is that I did everything right. I never told anyone my seed phrase. My devices were never connected to the internet. Everything was in multiple safes and bank vaults.” And then: „None of it mattered. Just because the hardware that created the phrase had one line of code from 2021 with a vulnerability.”

Coinkite published a warning on Thursday, updated it on Saturday and told users to upgrade their devices and move to a new seed phrase. It did not respond to a request for comment.

So what remains of the idea of full control over your own money? Keep it on an exchange and you rely on the exchange. Keep it offline and you rely on some programmer in 2021 not having made a mistake in one line. The responsibility moved, but it did not disappear - it just became invisible, which is far worse. The question is not whether hardware wallets are safer than exchanges. The question is why anyone should have to be a security auditor to hold their own money.