Canadian company Coinkite, the maker of the Coldcard hardware wallet, disclosed on July 31 a critical vulnerability that allowed attackers to drain approximately 594 BTC, worth roughly $38 million, from nearly 500 wallets in under 30 minutes. The flaw originated from a build configuration error during the integration of Bitcoin Core’s libsecp256k1 library in March 2021, which inadvertently replaced the device’s secure hardware random number generator with a predictable software-based fallback using non-secret chip data. Mk3 devices were particularly affected, retaining only around 40 bits of effective entropy instead of the 128 bits considered the minimum standard by the crypto security community. Coinkite released emergency firmware patches and is urging affected users to generate fresh seeds on updated firmware and migrate their funds immediately.
Source: Read the original article

