Nearly 594 BTC, valued at about $38 million, vanished in under half an hour after a critical flaw surfaced in Coldcard hardware wallets' seed generation process. The vulnerability, tied to firmware versions 4.0.0 through 5.0.3, impacted roughly 500 wallets created since March 2021.

Coinkite, the maker of Coldcard, revealed that the issue revolves around insufficient entropy in seed creation. While earlier firmware versions of Mk2 and Mk3 used a true random number generator, firmware 4.0.0 onwards generated seeds with reduced randomness, making them vulnerable to prediction. Later models like Mk4, Q, and Mk5, although using a different design, also only produce seeds with 72 bits of entropy instead of the standard 128 bits, reducing security guarantees.

Users are being urged to transfer their funds immediately, especially if they haven't applied a BIP-39 passphrase, which could mitigate some risk. this firmware problem doesn't affect the hardware itself but the software managing seed creation. The vulnerability highlights the ongoing risks in hardware wallet technology, even those considered highly secure.

Material is for informational purposes and does not constitute financial advice.