Galaxy Research: Bitcoin losses related to the Coldcard vulnerability rise to $70 million
Odaily Planet Daily News Galaxy Research said on Friday that more than 1,000 BTC were transferred out of nearly 1,200 addresses, worth about $70 million, and the related transactions are believed to be linked to a vulnerability affecting Coldcard hardware wallets.
Previously, Coldcard manufacturer Coinkite issued a warning on Thursday that there was an ongoing issue with the mnemonic seeds generated by Coldcard Mk3 devices. As a precaution, the company reminded all users who generated mnemonic seeds on Mk3 devices with firmware version 4.0.1 released in March 2021 or later that their funds could be at risk.
Subsequently, Coinkite expanded the scope of the risk warning to include some Mk4, Mk5, and Coldcard Q firmware versions, and issued an emergency firmware update for all affected models.
Coinkite CEO Rodolfo Novak (also known as NVK) apologized on Friday and said the company assumes "full responsibility" for the firmware vulnerability, acknowledging that internal review processes failed to identify the issue.
Novak also said the vulnerability may have been discovered with the help of artificial intelligence, noting that the incident reflects a "sobering reality in the new AI paradigm." He warned that AI-assisted code review could identify potential vulnerabilities faster than experienced security experts, and also made it easier for attackers to exploit weaknesses in public code.
