Coldcard's RNG Bug Has Reportedly Compromised More Than 1,750 BTC
A five-year-old firmware flaw in Coinkite's Coldcard hardware wallets has let attackers reconstruct Bitcoin private keys entirely offline, and the toll keeps climbing. Coinkite confirmed the bug traces back to a March 2021 firmware error, and Galaxy Research has estimated that the vector has led to +1,750 BTC (well over $100M) drained from ~5,000 addresses across multiple attack waves since July 30th.