$BTC #coldcard漏洞被盗594枚btc #Coldcard
First the conclusion: this is not that the Bitcoin protocol was broken, nor that a hacker remotely took control of an offline hardware wallet.
What was truly compromised was an earlier layer: part of the Coldcard firmware, when “generating a mnemonic,” didn’t route the expected hardware true random number into the correct code path, but instead ended up using a predictable software pseudo-random number generator. It still looks like random 12/24 words, but in reality the candidate space has been compressed by multiple orders of magnitude.
In other words, the private keys of affected users may have been in an enumerable range from the very first day they were created. Keeping the device offline afterward, signing with an SD card, or even swapping in a new piece of hardware and restoring the same seed phrase cannot fix the problem.