Galaxy Digital analyzed a security flaw in Coldcard hardware wallets caused by a firmware defect introduced in March 2021. This vulnerability, linked to the random number generator, allowed attackers to steal between 1,596 and 1,719 BTC, with estimated losses between $100M and $111M. At least 15 distinct hackers targeted approximately 7,300 addresses, and a suspected fourth wave of attacks was identified in early August with roughly 389 additional BTC. Victims had followed all recommended security practices, yet the flaw originated from the firmware itself. Affected users must update their firmware and transfer all funds to new addresses generated on patched devices.
Source: Read the original article

