A firmware bug in Coldcard Mk3 devices drained approximately 1,082 BTC, worth roughly $70 million, from nearly 1,200 wallets in just 41 minutes. The flaw originated from the random number generation process used to create recovery seeds, compromising private keys since March 2021. Coinkite, the Toronto-based manufacturer, released a patch (version 4.2.0) and advises affected users to generate new seeds on patched hardware before transferring their funds. CZ, Binance’s founder, recommended diversifying funds across multiple wallets, while acknowledging that this approach increases management complexity. The Mk4, Q, and Mk5 models are not affected by this vulnerability.
Source: Read the original article

