Coldcard Flaw Exposes Users to Theft: Multiple Attacks Linked to Firmware Issue
Coldcard Bitcoin Wallet Flaw Exposes Users to Theft
A recent attack wave targeting Coldcard users has moved an estimated 448.7 Bitcoin from over 700 suspected victim addresses, according to Galaxy Research.
This is the fourth wave of attacks linked to a firmware flaw that was introduced in March 2021 during a change to the cryptographic library used by Coinkite, the company behind Coldcard.
The issue occurred when the update accidentally routed seed creation to a weaker software-based random number generator instead of the device's intended hardware generator.
Coldcard has halted shipments and released fixed firmware for affected models, but users must still generate new seeds and move their funds to avoid being affected by this flaw.