Over $70 million in Bitcoin was stolen after exploiting a flaw in the firmware of Coldcard Mk3 hardware wallets. An engineer at Block revealed that the thief used a paid account at a major blockchain services provider to query source addresses and perform other attack-related activities. This flaw, present since version 4.0.1 from March 2021, caused seed generation to fall back to a weak pseudo-random number generator instead of the secure hardware random number generator, making private keys predictable. Galaxy Digital and Coinkite have advised users to immediately move their funds from single-signature Coldcard addresses to more secure custody solutions.
Source: Read the original article

