AI-Powered Hackers Expose Critical Vulnerability in Open-Source Wallets
Coinkite, a well-known hardware wallet manufacturer, has revealed a critical bug in its Bitcoin wallets. The vulnerability affects users who generated 12- or 24-word seeds without using user-generated dice rolls or an extra BIP 39 passphrase on their Coldcard MK3 devices with firmware versions 4.0.1 to 4.1.9.
The issue was discovered after a hack that started being discussed on social media on July 30th, and it's believed that over $70 million in BTC has been stolen so far. Industry experts think AI was used in the breach, and Coinkite has published a guide and advisory on how to secure funds.
NVK, one of the co-founders of Coldcard, emphasized that updating the firmware doesn't mean private keys generated before are now secure. Users need to create a new wallet and send their funds onchain to secure them.