A security flaw in Coldcard's Mk3 hardware wallet, introduced in firmware version 4.0.0 in March 2021, enabled attackers to steal between $38-70 million worth of bitcoin from hundreds of wallets by exploiting predictable key generation. The vulnerability affected wallets that used the device to generate seed phrases, prompting urgent warnings for users to move funds to newly generated wallets.
A security flaw in Coldcard's Mk3 hardware wallet, introduced in firmware version 4.0.0 in March 2021, enabled attackers to steal between $38-70 million worth of bitcoin from hundreds of wallets by exploiting predictable key generation. The vulnerability affected wallets that used the device to generate seed phrases, prompting urgent warnings for users to move funds to newly generated wallets.