The Coldcard hardware wallet exploit is ongoing, with approximately $88.6 million stolen, equivalent to 1,367 BTC, across 4,585 addresses. Galaxy Research identified three waves of thefts, the latest draining 207.73 BTC. The flaw stems from a March 2021 firmware build error that generated seed phrases with insufficient randomness, making private keys guessable. The stolen funds, which had remained dormant for an average of 3.18 years, were transferred to attacker addresses. Many affected users are now moving their Bitcoin back to centralized exchanges like Coinbase or Binance, reversing the usual « not your keys, not your coins » ethos.
Source: Read the original article

