A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator.

Bitcoin security experts said the unexplained $38 million wallet drain may involve flawed seed-generation entropy, though the cause and any Coldcard link remain unconfirmed.

A hardware wallet randomness bug turned “impossible to guess” seeds into guessable ones, and $38 million is already gone.

Over $70 million in Bitcoin has been pinched. Coldcard has since urged its users to take precautions.