Odaily Planet Daily reports that Galaxy Research stated on Friday that over 1,000 BTC, valued at approximately $70 million, were transferred from nearly 1,200 addresses, with the transactions believed to be linked to a vulnerability affecting Coldcard hardware wallets.
Previously, on Thursday, Coldcard manufacturer Coinkite issued a warning that there has been a persistent issue with mnemonic phrases generated by the Coldcard Mk3 device. Out of caution, the company advises all users who generated mnemonic phrases using the Mk3 with firmware version 4.0.1 or later, released in March 2021, that their funds may be at risk.
Subsequently, Coinkite expanded the risk advisory to include certain Mk4, Mk5, and Coldcard Q firmware versions, and released emergency firmware updates for all affected models.
Coinkite CEO Rodolfo Novak (also known as NVK) apologized on Friday, stating that the company accepts full responsibility for the firmware vulnerability and acknowledged that its internal review process failed to detect the issue.
Novak also stated that the vulnerability may have been discovered using artificial intelligence, calling the incident a “sobering reality under the new AI paradigm.” He warned that AI-assisted code review could identify potential vulnerabilities faster than experienced security experts, making it easier for attackers to exploit weaknesses in publicly available code.

