Coldcard firmware bug linked to 1,367 BTC stolen from 4,500 addresses since July 30
A flaw in Coldcard firmware 4.0.1 introduced in March 2021 reduced seed entropy to about 72 bits on Mk2 and Mk3 devices, enabling coordinated attacks from July 30 that drained about 1,367 BTC worth around $89 million from over 4,500 addresses. Coinkite issued patched firmware on July 31, but users must move funds to new seeds to remain safe.