A vulnerability in Coldcard hardware wallet firmware has been disclosed. A random number generation flaw reduced seed entropy to approximately 40 bits for Mk2 and Mk3 models, and approximately 72 bits for Mk4, Mk5 and Q models. Galaxy Research estimates approximately 1,367 BTC at risk across 4,585 addresses. Following the disclosure, 77,402 BTC were moved as a precaution. Affected users must either update their firmware or generate a new seed using at least 50 fair, independent and private dice rolls.
Source: Read the original article

