A fourth wave of attacks targeting Coldcard Bitcoin hardware wallets was detected on Monday, pushing estimated losses to approximately $114 million since July 30. In total, roughly 1,816 BTC have been stolen from more than 5,200 addresses. The vulnerability stems from a firmware bug introduced in March 2021, which routed seed generation to a vulnerable software random number generator instead of the device’s secure hardware generator. Manufacturer Coinkite has released emergency firmware updates for all affected models and halted shipments. The latest wave exploits replace-by-fee functionality, giving victims a brief window to move their funds before the theft confirms.
Source: Read the original article

