Hackers stole $38 million in Bitcoin after exploiting a flaw in Coldcard Mk3 hardware wallets, draining 594 BTC from around 500 cold wallets in just 25 minutes.
The attack targeted a vulnerability in certain Coldcard Mk3 devices made by Canadian company Coinkite. Hardware wallets normally generate highly random 24-word recovery phrases, making them practically impossible to guess.
According to CoinDesk, a bug caused some Mk3 devices to skip their randomness chip during seed generation. Instead, the wallets relied on predictable data such as the device's serial number and internal clock, allowing attackers to use AI-powered brute force techniques to recover seed phrases and steal the funds.
Coinkite said the issue affects Mk3 wallets running firmware 4.0.1 (released in March 2021) through version 5.0.3. Newer models, including the Mk4, Q, and Mk5, are not affected.
The company has urged affected users to move their funds to newly generated wallets created on patched or newer devices.
