COLDCARD Wallets Compromised by Critical Entropy Flaw
A critical entropy flaw in COLDCARD hardware wallets has put hundreds of devices at risk. The bug, which affects wallet models Mk3 running firmware version 4.0.1 or later, can be exploited to steal BTC.
According to Coinkite, the company behind COLDCARD, users are encouraged to create new seeds and move funds as soon as they perform firmware software updates.
The flaw was discovered after approximately 594 BTC worth nearly $40 million was stolen from wallets possibly associated with the weakness. Coinkite has released emergency firmware updates for current-generation devices, including version 5.6.0 for Mk4 and Mk5 models and version 1.5.0Q for the Q device.
The company admits that threat actors may have exploited state-of-the-art artificial intelligence tools to uncover vulnerabilities that older methods of review didn't catch. Coinkite has conducted a thorough audit of its own code base with one of the most popular AI models in the industry and still found the error.