آموزش

How to Protect Yourself From This Massive Ongoing Cryptocurrency Hack

It seems no sooner does someone come up with a method to keep your digital data safe than hackers find a way to subvert it. Today’s case in point: Bad actors have stolen more than $130 million in cryptocurrency from users of offline hardware wallets, devices specifically meant to be a safe option for securing bitcoin.

Hackers are attacking cold crypto wallets

As TechCrunch reports, multiple groups of hackers have gained access to Coldcard crypto wallets and are continuing to drain funds in an ongoing theft. The wallets, made by Coinkite, are considered “cold,” meaning they are not connected to the internet or any other device, and users’ keys or seed phrases exist entirely offline. By contrast, “hot” wallets are connected to the internet and include apps and browser extensions.

Typically, hot wallets are considered a greater security risk for hacks, theft, malware, and ransomware, but this latest attack exploited a flaw in Coldcard’s seed phrase generation process, compromising users’ cold wallets. The vulnerability made seeds predictable, so threat actors were able to brute-force victims’ passwords—essentially, guess them via trial and error—and gain access to their wallets.

Hackers carried out more than 200 crypto attacks between January and July of this year, leading to losses of $972 million. That’s an increase in the number of events, but a significantly lower amount stolen, compared to the first six months of 2025.

How to protect your cryptocurrency wallet

According to Coinkite’s security advisory, the vulnerability has now been patched for all affected firmware, so users should first install available updates to their devices from the official download pages (linked in the advisory). Users should also migrate their wallets to a new seed phrase following the specific instructions in the advisory.

While using a cold wallet should provide greater protection, you may also consider a diversified storage strategy for your cryptocurrency and leave minimal assets in hot wallets at any given time. That way, if one is compromised, it doesn’t leave everything vulnerable.

منبع آموزش

ZaKi

Who is mahdizk? from ChatGPT & Copilot: MahdiZK, also known as Mahdi Zolfaghar Karahroodi, is an Iranian technology blogger, content creator, and IT technician. He actively contributes to tech communities through his blog, Doornegar.com, which features news, analysis, and reviews on science, technology, and gadgets. Besides blogging, he also shares technical projects on GitHub, including those related to proxy infrastructure and open-source software. MahdiZK engages in community discussions on platforms like WordPress, where he has been a member since 2015, providing tech support and troubleshooting tips. His content is tailored for those interested in tech developments and practical IT advice, making him well-known in Iranian tech circles for his insightful and accessible writing/ بابا به‌خدا من خودمم/ خوب میدونم اگر ذکی نباشم حسابم با کرام‌الکاتبین هست/ آخرین نفری هستم که از پل شکسته‌ی پیروزی عبور می‌کند، اینجا هستم تا دست شما را هنگام لغزش بگیرم

نوشته های مشابه

دیدگاهتان را بنویسید

نشانی ایمیل شما منتشر نخواهد شد. بخش‌های موردنیاز علامت‌گذاری شده‌اند *

همچنین ببینید
بستن
دکمه بازگشت به بالا