A bug introduced in Coldcard's firmware back in March 2021 caused the wallet to generate private keys using predictable data (serial number, clock registers) instead of true randomness. An attacker figured out the pattern and swept 594 BTC (~$38M) from ~500 wallets in under 30 minutes early this morning.
If you created a wallet on Coldcard Mk3 firmware 4.0.1 or later, move your funds now to a freshly generated wallet.
UPDATE: Galaxy research reveals the real number is much bigger than reported: 1,082 BTC ($70.2M) from 1,196 wallets.
EXPLANATION (skip if you don't care):
When you set up a hardware wallet, it creates a secret key using random numbers. Coldcard's bug made those "random" numbers predictable because they were based on non-secret device info anyone could know. It's like a safe that claims to use a random combination, but actually bases it on the safe's serial number printed on the outside. Once you know the pattern, you can calculate the combination for any affected device and empty it remotely, no physical access needed.
Is your hardware wallet actually secure? 👇
🤖 Sponsored by aluy.net, the #1 VPS & RDP provider!
🔔 @Observer • 💬 Join community • 🎁 Weekly Giveaway
