Hardware wallet maker Coldcard released firmware updates patching a critical vulnerability in seed generation affecting Mk3, Mk4, Mk5, and Q models since March 2021. This flaw, linked to a faulty random number generator, made seeds predictable, and hundreds of millions of dollars in Bitcoin have reportedly been stolen. Updating firmware alone is insufficient: users must generate new seeds with the patched version and transfer all Bitcoin to freshly created wallets. Coldcard recommends using at least 50 independent dice rolls or applying a BIP-39 passphrase to strengthen entropy when generating new seeds. This vulnerability remained undetected for over five years in the open-source code, which was publicly available on GitHub.
Source: Read the original article

