At least 15 different attackers have exploited the hardware wallet vulnerability, according to Galaxy Digital head of research Alex Thorn, after new victim reports revealed previously unidentified thefts. Researchers may therefore be unable to identify some thefts unless victims disclose their wallet addresses and transactions. Coldcard Bug Weakened Wallet Seed GenerationThe vulnerability affected the process used by some Coldcard devices to generate . A firmware integration error reportedly caused affected wallets to rely on a deterministic pseudorandom number generator instead of the intended hardware-based random-number generator. Merely importing an affected recovery phrase into another device does not resolve the underlying weakness.