Coldcard Security Failure Allows Thieves to Steal Bitcoin
A critical security failure has been discovered in certain Coldcard hardware wallets, allowing thieves to steal Bitcoin from affected users. The issue, which affects seeds generated on specific firmware versions, results in low-entropy seeds that are not visually distinguishable from secure ones.
According to the manufacturer's advisory, approximately 594 BTC has been stolen from roughly 500 affected wallets. The problem is confined to Coldcard devices running firmware versions 4.0.1 through 4.1.9 on Mk2 and Mk3 models, as well as before standard firmware version 5.6.0 on Mk4 and Mk5 models.
BTCX, a leading Bitcoin company in Europe, has issued guidance for affected users to move their funds to a new, securely generated wallet immediately. The company emphasizes that the Bitcoin protocol itself remains intact and that this incident is a result of a single provider's failure to meet standards.