594 $BTC gone in 25 minutes. Around 500 single-sig wallets emptied. Coldcard seeds generated since March 2021 were the common thread. If you made your seed on an Mk3 with firmware 4.0.1 or later, or on an Mk4, Q or Mk5 before the new fixes, the device skipped its own hardware randomness. It fell back to something far weaker, closer to 40 bits on the older models. That is not "impossible to guess." That is searchable. I keep staring at the screen on the Q in this photo. "Don't Trust. Verify." That line is the whole point of Coldcard. People bought these specifically so they would never have to trust a random number generator inside a closed box. They air-gapped, they wrote the words on metal, they never typed the seed into a computer, they sat on the coins for years. And the one thing they could not verify, the quality of the entropy the device claimed to produce, quietly failed for five and a half years. That is the part most posts are skating past. This was not a phishing link. Not a supply-chain implant. Not a user who reused a seed or clicked a bad QR. These were the people who followed the highest standard the community has pushed for a decade. The device itself told them the seed was strong. The open-source code sat in public the entire time. Coinkite even ran AI over it weeks earlier and the model missed the bug. Someone else ran AI and did not miss it. The quiet lesson is that "open source + air gap" is no longer enough on its own. When AI can read every commit faster than any human review team, a five-year-old build-flag mistake becomes a time bomb. The people who added a BIP-39 passphrase or rolled their own dice entropy or used multisig across different devices are the ones still holding their coins. Everyone else is learning the hard way that "set and forget" is a myth. If your seed is potentially affected, do not just update the firmware. That does not fix an already-weak seed. Generate a brand new one on the patched version, verify the backup, send a tiny test, then move the rest. Slowly. Carefully. This one hurts because it hit Bitcoin believers who did everything right. That is exactly why it matters.
Crypto Yield ProShare

Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.