source avatarBSCN

Share

Coldcard losses pass $70M as Coinkite expands warning to newer devices The Coldcard (@COLDCARDwallet) exploit has grown far beyond first estimates, with over 1,080 bitcoin:native worth more than $70M drained from nearly 1,200 wallets, per Galaxy Research and engineers at Block. @Coinkite confirmed the cause: a 2021 firmware bug that swapped the hardware random number generator for a weak software fallback, leaving seeds open to brute force. Affected: Mk3 on 4.0.1–4.1.9, Mk4/Mk5 below 5.6.0, and Q below 1.5.0Q, unless generated with 50+ dice rolls. Patches are live, including Mk3 4.2.0 released Friday, but updating alone fixes nothing. Users must generate a new seed and migrate funds. Drains are reportedly still ongoing.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.