A critical firmware vulnerability in Coinkite's Coldcard hardware wallets has led to the theft of approximately $70 million in Bitcoin from 1,196 addresses. The flaw, introduced in March 2021, bypassed hardware-based randomness in favor of a predictable software generator, allowing attackers to reconstruct private keys offline. Coinkite released emergency firmware updates, but users must generate entirely new seeds to secure their funds. The incident has reignited debates over self-custody, with Binance co-founder Changpeng Zhao warning that no hardware wallet is completely safe.
Story comments
Loading comments…