Coinkite discloses COLDCARD flaw tied to about $38 million in BTC theft

The entropy-generation issue affects Mk2 and Mk3 devices and may weaken the security of mnemonic seed phrases created by the affected firmware.

Summary

Coinkite disclosed a serious entropy-generation flaw in COLDCARD firmware for Mk2 and Mk3 hardware wallets, a defect that may lower the security strength of mnemonic seed phrases. PeckShieldAlert said reports have linked the weakness to the theft of about $38 million in BTC, highlighting how flaws in random-number generation can undermine the core security assumptions of hardware wallets.

Terms & Concepts
  • entropy-generation flaw: Weakness in randomness creation process
  • mnemonic seed phrases: Word sequences used to recover wallets
  • hardware wallet: Physical device for offline crypto storage