A firmware entropy bug affecting Coinkite’s Coldcard hardware wallet, present since at least 2021, allowed hackers to guess related private keys and steal over 100 million dollars worth of bitcoin, mostly from single-seed wallet users. According to Nick Neuman, CEO of Casa, 233,000 bitcoins were moved to safety in reaction to this breach. In response, self-custody advocates are now recommending multi-vendor multisig wallets, an approach that requires valid signatures from multiple devices from different manufacturers to authorize a transaction, reducing dependency on any single wallet provider. Providers like Casa, Unchained Capital, Nunchuck and Sparrow Wallet facilitate such setups, while AnchorWatch now offers BTC-denominated bitcoin theft insurance through Lloyd’s of London.
Source: Read the original article

