A vulnerability in the seed generation process of ColdCard Mk3 Bitcoin wallets has led to the theft of approximately 600 BTC, worth around $38 million at current prices. According to Coinkite, the manufacturer of ColdCard hardware wallets, certain firmware versions (4.0.1 and later, released since March 2021) generated only about 40 bits of entropy instead of the expected secure level, making private keys predictable through brute-force attacks. Mk4, Mk5, and Q devices are also affected with reduced entropy (around 72 bits) before corrected firmwares. Coinkite released versions 5.6.0 for Mk4/Mk5 and 1.5.0Q for Q, which fix the bug but only for new seeds generated after the update.
Source: Read the original article

