Hackers exploited a security flaw in Coldcard hardware Bitcoin wallet software to steal over 1,367 BTC, worth more than $72 million, from at least 4,585 addresses. The vulnerability, present since March 2021, weakened the devices’ random number generator, reducing seed phrase entropy from 128 to 72 bits, which allowed attackers to guess private keys through brute force. Manufacturer Coinkite confirmed that Mk3, Mk4, Mk5, and Q models were all affected and released an emergency patch. Galaxy Research estimates total losses at over $85 million, with the largest hacker wallet holding 562 BTC.
Source: Read the original article

