Loading...
Please wait while we get things ready for you
Please wait while we get things ready for you
An attacker exploited a randomness bug in Coldcard Mk3 firmware to sweep 594 BTC worth roughly $38 million from about 500 single-signature wallets in just 25 minutes on Friday. The vulnerability — introduced in firmware 4.0.0 back in March 2021 — caused the device to skip its own hardware randomness generator and fall back to predictable software-based key generation seeded from non-secret chip data. Every drained wallet was single-signature and many had been dormant...
Ask AI about this