Coinkite, manufacturer of the popular Coldcard Bitcoin hardware wallet, has confirmed a firmware vulnerability affecting Mk3, Mk4, Mk5, and Q models, allowing attackers to guess private keys of wallets whose seeds were generated with insufficient entropy. The flaw caused the hardware’s true random number generator to be bypassed, producing seeds with only 40 bits of entropy instead of the intended 128 bits, making them predictable enough for brute-force attacks. Approximately 1,082.65 BTC, worth over $70 million, has been drained from around 1,196 addresses, with 594.5 BTC worth $35.7 million moved on Thursday. Bitcoin developers are urging affected users to immediately move their funds to new wallets.
Source: Read the original article

