38M BTC Heist Sparks Fears Over Hardware Wallet Security
A recent exploit of Coinkite's Coldcard hardware wallet has left investors concerned about security in the Bitcoin ecosystem. The flaw allowed an attacker to steal a staggering 38 million worth of BTC.
The issue was attributed to a code flaw within Coldcard's firmware, which downgraded their system from a 128-bit to a guessable 40-bit entropy system. This vulnerability could easily be cracked using brute force.
Ledger and Trezor, two prominent Bitcoin hardware wallet providers, immediately distanced themselves from the incident, assuring users that their own wallets were 'not affected' by the flaw.
Trezor explicitly stated that they do not share Coldcard's custom firmware code and therefore are not at risk. Ledger also claimed to use a 256-bit mathematical complexity system, making seed phrases more difficult to crack.