Hardware wallet manufacturer Coinkite disclosed that a build error in its Coldcard devices allowed attackers to guess the private keys of roughly 500 users, resulting in the theft of 594 BTC, worth approximately $38 million. A flaw in the firmware caused seed generation to use a software fallback instead of the secure hardware random number generator, drastically reducing the key search space. Coinkite believes an attacker used AI to review its open-source firmware code and uncover this weakness. The published fixes do not repair seeds already created with vulnerable versions, and every current model is affected. The stolen funds were consolidated into a single address within 25 minutes.
Source: Read the original article

