A firmware flaw in Coldcard hardware wallets exposed approximately $130 million in Bitcoin losses affecting more than 7,700 addresses. The defect diverted random-number generation from the STM32 hardware module to MicroPython’s deterministic Yasmarang fallback, producing predictable seeds on Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9. Coinkite advises affected users to generate new seeds and transfer funds, as the vulnerability cannot be patched retroactively and has existed since 2021. Founder Rodolfo Novak issued a public apology and is offering assistance with police reports and insurance claims. TRM Labs found that infrastructure and operational compromise accounted for roughly 76% of crypto hack value in H1 2026, while CertiK identified wallet compromise as the costliest attack category at over $444 million across 33 incidents.
Source: Read the original article

