The entropy-generation issue affects Mk2 and Mk3 devices and may weaken the security of mnemonic seed phrases created by the affected firmware.
Coinkite disclosed a serious entropy-generation flaw in COLDCARD firmware for Mk2 and Mk3 hardware wallets, a defect that may lower the security strength of mnemonic seed phrases. PeckShieldAlert said reports have linked the weakness to the theft of about $38 million in BTC, highlighting how flaws in random-number generation can undermine the core security assumptions of hardware wallets.