A vulnerability in Coldcard hardware wallets allowed hackers to drain over 500 Bitcoin addresses, stealing 594.48 BTC worth approximately $38.3 million. The flaw, present in the firmware since March 2021, affected all models including Mk2, Mk3, Mk4, Q and Mk5. An error in seed phrase generation reduced the number of possible combinations to a minimum, enabling brute-force attacks within minutes. Developer Peter Todd, previously identified as a potential Satoshi Nakamoto, criticized the lack of independent auditing of hardware wallet code. Only users who added a BIP-39 passphrase during setup remain protected.
Source: Read the original article

