vulnerability
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
Critical
Summary
A flaw in Coldcard hardware wallets, manufactured by Coinkite, was exploited to steal $70 million in Bitcoin within 41 minutes. The vulnerability stems from a deterministic PRNG used during seed generation, allowing an attacker to reconstruct Bitcoin addresses from a known seed. Coinkite released emergency firmware to mitigate the issue, urging users with exposed seeds to generate new ones and migrate their funds. The attack was linked to a similar weak PRNG flaw discovered in other wallets, resulting in millions of dollars in losses.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
