Galaxy Research has revised upward the amount of funds stolen through the security flaw affecting Coldcard Mk3 hardware wallets, reaching approximately 1083 BTC, worth nearly 70 million dollars at current rates. The number of affected addresses has grown to 1196, compared to around 500 in the initial estimate published on July 31. The attack occurred within a 41-minute window on July 30, and nearly all funds were siphoned before Coinkite’s public alert was issued. The defect impacted devices running firmware versions 4.0.1 to 5.0.3, whose faulty random number generator allowed private keys to be predicted without an additional BIP-39 passphrase. Coinkite maintains its recommendation to migrate immediately to a seed generated on an unaffected device.
Source: Read the original article

