Coldcard Wallet Vulnerability Leads to $114M Bitcoin Loss

Hackers have exploited a critical vulnerability in Coldcard hardware wallets, resulting in the theft of an estimated $114 million in Bitcoin. The ongoing attacks, which intensified over the weekend, have seen significant amounts of the cryptocurrency drained from user wallets.
The issue stems from a firmware bug in Coldcard Mk3 devices, introduced in version 4.0.1 in March 2021. This flaw caused the seed generation process to revert to a less secure software pseudorandom number generator instead of the intended hardware-based true random number generator. This allowed malicious actors to effectively guess users' seed phrases and gain access to their funds.
Coinkite, the manufacturer of Coldcard, has acknowledged the vulnerability affects all its models. In response, the company has halted shipments of affected products and destroyed remaining inventory produced with the compromised firmware. They have also initiated an internal review, with engineers investigating the incident and reporting findings to federal authorities and a blockchain services provider used by the hackers to move funds. The company expressed deep regret over the financial losses and broken trust experienced by its customers.
This is an AI-assisted summary. Original reporting by Bitcoin Magazine.
Read the originalRelated stories

$70M Bitcoin Stolen Via Sophisticated Phishing Scheme
Millions in Bitcoin were lost from cold wallets through an attack that bypassed device security, highlighting new phishing tactics.

Zcash's Ironwood Pool Sees $80M Inflow on Launch
Zcash's new privacy-focused Ironwood pool attracted approximately $80 million in ZEC deposits on its first day, signaling strong user interest in enhanced

Bitmine Boosts ETH Holdings, Continues Share Buybacks
Crypto miner Bitmine significantly increased its Ethereum holdings and executed a substantial share repurchase, signaling confidence in its strategy.