A vulnerability in Coldcard hardware wallet key generation has been linked to the theft of 584 Bitcoin ($38 million) from 500 users in a coordinated 25-minute attack. The flaw affected how wallet seeds were generated in certain firmware versions, according to security researchers. Manufacturer Coinkite and parent company Block are investigating the scope and exploitability of the issue.
Why it matters: This incident exposes critical risks in cryptocurrency hardware wallet security—the very infrastructure millions rely on to protect digital assets—and raises questions about firmware update protocols and vulnerability disclosure in the crypto industry.