Block disclosed two critical vulnerabilities in multiple generations of Coldcard hardware wallets (Mk2, Mk3, Mk4, Q and Mk5). For Mk2 and Mk3 devices, a coding error caused wallet generation to rely on predictable values instead of sufficient hardware-generated randomness. On Mk4, Q and Mk5 models, a flaw reduced the additional entropy to just 32 bits. The total amount potentially stolen amounts to 1,082.59 BTC according to Block’s preliminary analysis. Block recommends affected users to move their funds as soon as possible.
Source: Read the original article

