Coldcard Wallet Flaw Exposes Millions in Bitcoin
A vulnerability in Coldcard's hardware wallet has been exploited by hackers, resulting in an estimated $89 million theft of Bitcoin.
The issue centers on a programming error that makes recovery phrases predictable enough for advanced attackers to deduce under certain conditions, allowing them to steal funds without touching the wallet.
Coldcard manufacturer Coinkite has released a firmware update to prevent the issue for wallets created going forward, but users who generated their recovery phrase using affected software must create an entirely new one and transfer their Bitcoin into the newly secured wallet.