The Coldcard incident is a good reminder that “offline” doesn’t automatically mean secure.

The devices didn’t need to be physically accessed. A firmware bug weakened the randomness used to generate some wallet seeds, which may have allowed attackers to reconstruct them offline.

Coinkite says updating the firmware alone does not repair an affected seed. A completely new seed has to be generated after updating.

Researchers now estimate that as much as 1,816 BTC, around $114M, may have been swept from more than 5,200 addresses. The newest estimate is still based on on-chain pattern matching, so I wouldn’t treat the exact total as final yet.

The part that sticks with me is that a wallet can remain fully air-gapped and still fail if the secret was weak from day one.

submitted by /u/Actual-Ad2198 [link] [comments]r/CryptoCurrencyRead More

You might also be interested in reading Bitcoin price rebound to $75K? Analysts split as $71K support looms.