Coldcard Wallet Flaw Exposes Up to $75M in Bitcoin.

A critical firmware vulnerability in Coldcard hardware wallets has now been linked to the theft of 1,158.66 BTC (around $75 million) across 2,673 addresses. Researchers say the attacker didn't physically access any devices—they exploited a weakness in wallet seed generation.

The issue stems from a firmware bug introduced in March 2021, where affected wallets generated recovery seeds with significantly weaker randomness. Instead of requiring an impossible-to-crack 128-bit entropy, some Mk3 devices reportedly fell to around 40 bits, allowing an attacker to brute-force private keys offline and identify funded wallets.

If you created a wallet on an affected Mk2, Mk3, Mk4, Mk5, or Q device using vulnerable firmware without adding dice-roll entropy or a strong BIP-39 passphrase, simply updating the firmware is not enough. Users should generate a new wallet with updated firmware and transfer funds immediately, as the original seed remains permanently weak. $BTC

#BTC Price Analysis# #WalletConnect #Macro Insights#