Coldcard Flaw Exposes $38M in BTC to Attackers
A Canadian firm that specializes in air-gapped Bitcoin hardware has announced that an attacker exploited a flaw in key generation on Mk3 devices running firmware version 4.0.1 or later.
The attack, which occurred recently, allowed the attacker to drain 594 BTC (~$38M) from roughly 500 single-signature Coldcard wallets in just 25 minutes.
Fortunately, early analysis suggests that Mk4, Q, and Mk5 models remain unaffected by this vulnerability.
The attacker consolidated 562 BTC into one address that has not moved since the attack.