Coinkite's Coldcard Security Flaw Exposes Millions in Bitcoin
Coldcard security flaw has led to millions of dollars in Bitcoin losses.
The Canadian company Coinkite, manufacturer of Coldcard wallets, acknowledged a vulnerability in certain versions of its firmware. The issue was found in the process of generating seed phrases, which are sequences of words used as backups for the wallet and allow access to funds in case of loss or malfunction.
The problem arose because some versions of the firmware generated these phrases using an insufficient source of randomness, making certain keys more predictable than they should be. Attackers allegedly exploited this circumstance to reconstruct seed phrases of some users and transfer the stored bitcoins directly to their wallets.
Coinkite has informed affected customers to help them move funds that were still secure and guide them on recovery options. The company has also released a software update to prevent new wallets from generating seed phrases with the problem, but warns that installing it does not automatically protect those who had already created a wallet using a vulnerable version.