Coldcard Owners Hit by $114M Bitcoin Heist
A vulnerability in the firmware of certain Coldcard devices has allowed an attacker to steal over $114 million worth of Bitcoin since last week. Coinkite, a firm that verifies transactions, has advised users to immediately migrate their funds.
The exploit takes advantage of a flaw in the seed generation process, which can be deduced externally if not enough randomness is used when creating the key. This allows an attacker to recreate the key and empty the wallet without ever laying a finger on the hardware.
Owners of affected devices are advised to create a new seed and transfer their funds as soon as possible. The vulnerability persists until the owner takes action, and exposure is limited to specific models and firmware builds.