Coldcard Firmware Flaw Exposes Thousands of BTC Addresses to Theft
A vulnerability in the Coldcard firmware has potentially left thousands of Bitcoin addresses vulnerable to theft. Researchers have linked this bug to suspected thefts totaling $88.6 million across 4,585 blockchain addresses.
The affected firmware generated seeds with reduced entropy, which could allow an attacker to reproduce candidate seeds offline and derive their Bitcoin addresses.
Coldcard owners who created seeds on vulnerable releases should install the patched firmware and generate a new seed. Updating the device does not repair an existing seed.