Coldcard hardware wallet flaw sees more than 1,367 BTC (~$89 million) drained across thousands of wallets

"Coldcard" in boxy red typeColdcard logo (attribution)
Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered more than 1,367 BTC (~$89 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets.

An estimated 1,367 BTC (~$89 million) and counting has been drained in the two days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Subsequent attacks have seen funds moved to around 600 attacker wallets, according to Galaxy Research, although the number of unique attackers is not clear at this point, and attackers regularly use multiple wallets to make tracing stolen funds more challenging.

Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built".

42DAO's Balance Coin algorithmic stablecoin crashes after $912,000 theft

Balance Coin, a small algorithmic stablecoin built on BNB Chain, lost its dollar peg and crashed to fractions of a cent after an attacker successfully exploited a flaw in its pricing logic. The attacker was able to trick the system into accepting an incorrectly low bitcoin price, which they then used to drain multiple vaults used by the project's lending protocol.

The attacker ultimately profited by about $912,000, consisting of funds stolen from 42DAO, the entity that runs the Balance protocol.

Wanchain bridge on Cardano exploited for more than $9 million

An attacker exploited the Wanchain bridge, stealing 515 million NIGHT tokens that had been bridged from Cardano to BNB. The NIGHT token belongs to Midnight, a privacy-focused blockchain linked to Cardano. The stolen tokens were priced at $9 million to $10 million at the time of the theft, although the massive outflow of tokens briefly caused the NIGHT token price to drop by about 43%.

Allbridge exploited for $1.66 million

The Allbridge blockchain bridge was exploited for $1.66 million in a flash loan attack. The attacker took advantage of a flaw in the project's logic that reprices assets against one another, after discovering that the same would happen even when borrowing an asset against collateral denominated in the same token. They were able to manipulate the project's internal pricing logic so that the asset's actual price diverged away from reality, pocketing $1.66 million in proceeds.

Across Protocol exploited for $3.35 million

The Solana deployment of the Across bridge was hacked for around $3.35 million. According to Across, the stolen funds belonged to Risk Labs, the foundation supporting the project, rather than users of the bridge.

Ostium loses at least $24 million to oracle exploit

Decentralized perpetual futures exchange Ostium was drained of at least $24 million after an attacker manipulated its oracle system — a system that pulls in off-chain price data. After the attacker apparently gained access to the private key used to sign oracle messages, they were able to submit future-dated oracle reports that tricked the system into thinking trades were profitable.

The attacker siphoned at least $24 million USDC from the protocol, which they quickly swapped into ETH and laundered via Tornado Cash.

Bonzo Lend exploited for $9 million in oracle attack

The Hedera-based decentralized lending platform Bozno Lend was exploited for just over $9 million after an attacker took advantage of a flaw in the project's oracle system. The attacker was able to deposit tokens worth only a few dollars, then manipulate the project's oracle to reflect a dramatically higher price. They then borrowed $6.63 million in USDC and 34.5 million wrapped HBAR (~$2.4 million).

Bonzo has announced they will reimburse users affected by the exploit, with support from the Hedera Foundation.

Summer Finance exploited for $6 million, shuts down

Summer Finance, a defi platform that provides "institutional defi vault infrastructure", was exploited for $6 million in an apparent flash loan attack. The attacker used a flash loan to deposit $64.8 million and then withdraw $70.9 million, taking advantage of a price manipulation bug that allowed them to withdraw more than they deposited.

Shortly after the exploit, Summer Finance announced it had "no viable path forward other than to wind down operations". They added, "a meaningful portion of the team's own capital was held in the affected vaults, removing the runway we needed to rebuild."

Dutch Knaken crypto platform collapses with $8 million in customer funds missing

The Dutch cryptocurrency platform Knaken (not to be confused with the American Kraken platform) abruptly went offline in early June, leaving roughly 30,000 customers unable to access their funds. The company was unable to secure a license under the EU's MiCA regulations, which it said forced them to shut down. Though they claimed to be winding down the company in an orderly fashion, they reportedly stopped paying customer withdrawals, and asked customers to stop filing claims.

Dutch prosecutors asked courts to declare the platform bankrupt and install a court-appointed trustee to oversee the process of extracting assets from the company to return to customers, who are missing around €7 million (~$8 million). The request was approved. The country's Fiscal Information and Investigation Service has also opened a criminal investigation into the platform.

Polymarket customers lose $2.97 million, company blames third-party vendor

Polymarket customers have lost around $2.97 million to an attacker who then swapped stolen Polymarket USD (pUSD) to ETH.

Polymarket, a crypto-based prediction markets platform, quickly made an announcement to claim that a third-party vendor had been compromised to allow an attacker to inject a malicious script into the website frontend. Polymarket has said it will refund affected customers.

No JavaScript? That's cool too! Check out the Web 1.0 version of the site to see more entries.