Hackers exploited a software flaw in Coldcard Bitcoin wallets, causing significant financial losses. This vulnerability affected the security keys used to protect user cryptocurrency holdings. Millions of dollars have been siphoned from thousands of compromised wallets globally. The flaw involved a predictable seed phrase generation mechanism within the devices. Coinkite has released updated firmware to address the ongoing security breach.

Coinkite said it’s likely that an attacker used AI to review previous versions of its open source firmware to uncover a vulnerability.

Coinkite disclosed a Coldcard firmware flaw dating to 2021 that let an attacker drain 594 BTC worth $38M from nearly 500 wallets in under 30

Over $70 million in Bitcoin has been pinched. Coldcard has since urged its users to take precautions.