Galaxy Research reveals that over $115 million in bitcoin has been stolen through a firmware bug in Coinkite’s Coldcard Mk3 hardware wallets. The flaw, present since version 4.0.1 in March 2021, weakened seedphrase generation by using a pseudo-random number generator instead of the hardware random number generator. Galaxy Research identified at least 15 distinct attackers exploiting this vulnerability and gathered testimony from over 200 victims. Total estimated losses could exceed $130 million. Stolen funds were typically left untouched for 3.5 years on average, and 88% of the pilfered crypto-assets were at least one year old.
Source: Read the original article

