Bitcoin Wallets Hit by $70M Hack Exploiting Firmware Bug
Researchers at Galaxy Digital have discovered that hackers exploited a firmware bug in Coldcard Bitcoin wallets, resulting in the theft of approximately $70 million.
The bug, which reduced the randomness in generating secret recovery phrases, allowed rapid theft from individual self-custody addresses within 41 minutes.
Coldcard's maker, Coinkite, has taken responsibility for the issue and released emergency firmware updates to address the problem.
Users are urged to create new recovery phrases and move their funds to secure wallets as soon as possible.