A firmware vulnerability in Coinkite’s Coldcard hardware wallets, dating back to March 2021, enabled attackers to steal approximately 1,816 BTC, worth roughly $114 million, from more than 5,200 addresses. The flaw compromised key generation, reducing entropy from the expected 128 bits to as low as 40 bits, making brute-force attacks feasible with modern hardware. Galaxy Research estimates total losses could exceed $130 million as attackers continue sweeping vulnerable wallets. Coinkite has not released an official loss estimate and is conducting a post-mortem analysis. Users who seeded wallets with firmware version 4.0.1 should transfer funds to a device running verified firmware.
Source: Read the original article

