A critical flaw in the Coldcard hardware wallet allowed attackers to steal millions in digital assets from users without ever touching the physical device. The vulnerability stemmed from a 2021 firmware change that replaced the secure 128-bit entropy random generator with a weaker software-based alternative producing only about 40 bits of entropy, making seed recovery feasible through brute force attacks.
Researchers tracking the incident over the weekend identified approximately 1,158 BTC stolen from 2,673 addresses. While Coldcard has released a firmware patch, seeds generated before the fix remain compromised. Users with affected wallets should immediately create a new hardware wallet and transfer all funds to secure storage.

