Coinkite Bug Exposes Millions in Bitcoin to Hackers
A critical bug in Coinkite's Bitcoin hardware wallets has been discovered, allowing hackers to steal over $70 million worth of cryptocurrency. The vulnerability, which affects Coldcard MK3 devices with firmware versions 4.0.1 through 4.1.9, was identified as a specific line of code in the firmware that generated secure private keys.
Industry experts believe that AI was used in the breach, and the hack may be just the beginning, with other wallet providers likely to be probed for vulnerabilities.
The Coinkite advisory has been updated to advise users to upgrade their device firmware, but even after updating, users who generated 12- or 24-word seeds without using user-generated dice rolls or a BIP 39 extra passphrase are still at risk.