Coldcard Users Warned of Vulnerability That Allowed Hackers to Drain Funds
Coldcard users may have been affected by a vulnerability that allowed hackers to generate seeds and drain funds from wallets. Coinkite, the company behind Coldcard, released a security advisory on July 30th and recommended that users update their firmware and create new seed phrases.
The vulnerability was caused by the use of fewer random number candidates than expected to generate seed phrases, which made it possible for hackers to guess private keys. Coinkite reported that some users had already lost funds due to this issue and urged others to take action quickly.
Galaxy Research, a firm that analyzes blockchain data, has been tracking the situation and estimates that at least 4 waves of attacks have occurred, with the fourth wave still ongoing. According to their analysis, over 1,756 BTC has been lost due to this vulnerability.