Galaxy Research: Bitcoin losses related to Coldcard vulnerability rise to $70 million
Odaily News - Galaxy Research said on Friday that more than 1,000 BTC were transferred out of nearly 1,200 addresses, with a value of approximately $70 million, and the related transactions are believed to be linked to a vulnerability affecting Coldcard hardware wallets.
Previously, Coldcard manufacturer Coinkite issued a warning on Thursday about an ongoing issue with seed phrases generated by Coldcard Mk3 devices. As a precaution, the company reminded all users who generated seed phrases using Mk3 devices with firmware version 4.0.1, released in March 2021, or later versions, that their funds may be at risk.
Subsequently, Coinkite expanded its risk warning to include some Mk4, Mk5, and Coldcard Q firmware versions, and released urgent firmware updates for all affected models.
Coinkite CEO Rodolfo Novak (also known as NVK) apologized on Friday and said the company assumes "full responsibility" for the firmware vulnerability, acknowledging that internal review processes failed to identify the issue.
Novak also said the vulnerability may have been discovered with the help of artificial intelligence, noting that this incident reflects a "sobering reality under the new AI paradigm." He warned that AI-assisted code review could identify potential vulnerabilities faster than experienced security experts, while also making it easier for attackers to exploit weaknesses in public code.
