Researchers believe a COLDCARD firmware vulnerability tied to flawed random number generation may have enabled attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets. Galaxy Research and Chainalysis say the thefts were likely automated, with attackers targeting high-value wallets before Coinkite disclosed the flaw. #COLDCARD #Coinkite #GalaxyResearch #Chainalysis
Keypoints
- Attackers may have exploited a COLDCARD firmware RNG flaw to steal Bitcoin from affected wallets.
- Galaxy Research estimated total losses at 1,367 BTC, or about $88.6 million.
- The thefts used identical fees and no change output, suggesting an automated sweeping tool.
- Block traced the issue to a MicroPython deterministic fallback instead of the hardware RNG.
- Coinkite released fixed firmware and advised users to migrate funds to newly generated seeds.