Hackers continue to drain Coldcard Bitcoin wallets, with the total amount stolen now estimated at over $114 million. A fourth wave of attacks likely began Sunday evening, moving 388.9 bitcoins worth over $29 million in new transactions. The breach was caused by a firmware bug in Coldcard Mk3 devices starting with version 4.0.1 in March 2021, which caused seed generation to fall back to a weak software pseudo-random number generator instead of the hardware true random number generator, allowing hackers to guess investor seedphrases. Coinkite acknowledged that all its models were vulnerable, destroyed remaining inventory manufactured with the faulty firmware, and halted product shipments. Engineers at Block investigated the hack and reported that the hackers used a major blockchain services provider to move the stolen funds.
Source: Read the original article

