Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach
Bitcoin Magazine Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach Over a thousand bitcoins are believed to have been stolen so far in a hack that started to be discussed on social media in the afternoon of July 30th.
Coinkite, one of the most reputable hardware wallet manufacturers, was revealed to have a critical bug in the way it generated secure private keys for its Bitcoin hardware wallets. Industry experts believe AI was used in the breach.
Coldcard MK3 devices with firmware version 4.0.1 (March 2021) through 4.1.9 are the worst affected.
12- or 24-word seeds generated by the device that did not include user-generated dice rolls or a BIP 39 extra passphrase are vulnerable. Users who fit this category, who have bitcoins in an MK3 Coldcard and did not use the dice roll feature for extra entropy or the extra passphrase, should consider themselves at risk and move their coins as soon as possible from the wallets.
This page shows the RSS-provided summary/preview. Full publisher content remains available at the original source.