As cited
Copy frozen at (site build).
vulnerabilities
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
An attacker exploited a firmware flaw in Coldcard hardware wallets to drain 1,196 Bitcoin addresses of approximately 1,082.65 BTC (worth $70.2 million) in 41 minutes on July 30. Galaxy Research traced the theft to a March 2021 firmware integration error that routed seed generation through a deterministic software pseudorandom number generator (PRNG) instead of a cryptographically secure one.
Why it matters: Coldcard users and Bitcoin custodians need to assess whether affected firmware versions were deployed in their deployments and rotate or verify key material, as predictable seed generation compromises the security guarantees of hardware wallet isolation.
- Source published
- First seen by Cybersecurity Tracker