Coinkite disclosed a Coldcard firmware flaw dating to 2021 that let an attacker drain 594 BTC worth $38M from nearly 500 wallets in under 30

Coinkite warns Coldcard Mk3 users that firmware versions 4.0.1 to 5.0.3 may have a random number generator flaw compromising wallet seeds.

Bitcoin security experts said the unexplained $38 million wallet drain may involve flawed seed-generation entropy, though the cause and any Coldcard link remain unconfirmed.