Coldcard Wallets Exposed: Critical Vulnerability Exploited for $70M in BTC
A critical software vulnerability in Coldcard wallets has been exploited, resulting in the theft of 1,082.65 BTC (~$70 million) from 1,196 addresses within 41 minutes.
The flaw, located in the pseudo-random entropy generator of the firmware, dated back to March 2021 and was not patched until July 30.
Coinkite issued a strict warning to users, stating that updating the firmware is not enough to sanitize the recovery phrase, and instead instructed affected users to generate a new mnemonic on an updated device and transfer their assets.
Binance's founder Changpeng Zhao warned about the importance of diversifying physical wallets, saying 'nothing is 100% safe' and advising investors to spread their funds across multiple manufacturers and architectures.