None
EN
Coldcard Hack Update: At Least 15 Attackers Exploited Wallet Flaw
['Danielle Du Toit', 'Danielle Du Toit Is A Crypto Security', 'Investigations Journalist Covering Digital-Asset Crime', 'Protocol Exploits', 'Scams', 'Enforcement Actions', 'Consumer Protection. With An Honours Degree In Criminology', 'She Examines How Crypto Attacks Happen', 'How Stolen Funds Move', 'How Regulators']
Coinpaper
At least 15 different attackers have exploited the hardware wallet vulnerability, according to Galaxy Digital head of research Alex Thorn, after new victim reports revealed previously unidentified thefts.
Researchers may therefore be unable to identify some thefts unless victims disclose their wallet addresses and transactions.
Coldcard Bug Weakened Wallet Seed GenerationThe vulnerability affected the process used by some Coldcard devices to generate .
A firmware integration error reportedly caused affected wallets to rely on a deterministic pseudorandom number generator instead of the intended hardware-based random-number generator.
Merely importing an affected recovery phrase into another device does not resolve the underlying weakness.