A critical flaw in Coldcard hardware signer firmware redirected seed generation to a weak software PRNG instead of the hardware entropy source, collapsing effective entropy to around 40 bits on some models. Attackers have already drained 4,585 addresses, causing nearly $90 million in losses according to Galaxy Research, with the attack ongoing as of this article. The defect existed in publicly readable firmware since March 2021, and Coinkite had switched away from free-software licensing two years earlier. The Coldcard case illustrates that no licensing model protects against AI-assisted audits: all distributed code is or will be readable, and security must now rest on development discipline rather than code secrecy.
Source: Read the original article

