An attacker exploited a flaw in the seed phrase generation of Coldcard Mk3 hardware wallets, stealing approximately 594 BTC worth $38 million from 500 wallets in under 25 minutes. The vulnerability reduced entropy in the random number generator, shrinking the possible combinations from 340 undecillion to just a few billion, making recovery phrases predictable. Users who had protected their funds with a BIP-39 passphrase faced significantly lower risk. Coldcard advised all Mk3 users to migrate their funds immediately to an unaffected device or use a strong BIP-39 passphrase. The broader Bitcoin ecosystem remains intact, as only single-signature hardware wallets were affected, while multisig solutions remained secure.
Source: Read the original article

