An attacker exploited a critical firmware vulnerability in Coldcard hardware wallets to steal 594 BTC (worth ~$38 million) from about 500 wallets in under 30 minutes. The flaw, introduced in March 2021, caused devices to use predictable, software-based key generation instead of a secure hardware randomizer. Coinkite, the wallet's manufacturer, and Block have warned users of affected models, particularly the Mk3, to move their funds immediately.
Story comments
Loading comments…