Galaxy Research said Friday that more than 1,000 BTC have been moved from nearly 1,200 addresses in transactions believed to be linked to a vulnerability affecting Coldcard hardware wallets, putting the value of the loss at about $70 million. The disclosure followed a warning from Coldcard maker Coinkite, which said mnemonic seeds generated on Coldcard Mk3 devices were affected by a persistent issue. The company initially warned users who created seed phrases on Mk3 devices running firmware version 4.0.1, released in March 2021, or later versions that their funds could be at risk. Coinkite later broadened the scope of the alert to include certain firmware versions for the Mk4, Mk5, and Coldcard Q, and issued emergency firmware updates for all affected models. Coinkite CEO Rodolfo Novak, also known as NVK, apologized on Friday, said the company takes full responsibility for the firmware flaw, and acknowledged that its internal review process failed to catch the issue. Novak also said the bug may have been found with the help of AI.
Galaxy Research said Friday that Bitcoin losses tied to the Coldcard hardware wallet flaw have climbed to about $70 million.
The firm said more than 1,000 BTC were moved from nearly 1,200 addresses, with the transactions believed to be connected to the vulnerability affecting Coldcard devices.
Coinkite widened the warning after the initial alert
Coldcard maker Coinkite had warned on Thursday that mnemonic seeds generated by Coldcard Mk3 devices were affected by a persistent issue.
As a precaution, the company told users that funds may be at risk if they used an Mk3 device and generated a seed phrase with firmware version 4.0.1, released in March 2021, or any later version.
Coinkite later expanded the scope of the warning to cover certain firmware versions for the Mk4, Mk5, and Coldcard Q, and released emergency firmware updates for all affected models.
CEO apologizes and accepts responsibility
Coinkite CEO Rodolfo Novak, also known as NVK, apologized on Friday and said the company takes "full responsibility" for the firmware flaw.
He also said the company’s internal review process failed to catch the problem.
Novak added that the vulnerability may have been discovered with the help of artificial intelligence, calling the episode a "sobering reality under the new AI paradigm."
He warned that AI-assisted code review may spot potential vulnerabilities faster than experienced security experts, while also making it easier for attackers to exploit weaknesses in public code.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.