Galaxy Research: Bitcoin losses related to Coldcard vulnerability rise to $70 million
Galaxy Research said on Friday that over 1,000 BTC, worth approximately $70 million, were moved from nearly 1,200 addresses, with the transactions believed to be linked to a vulnerability affecting Coldcard hardware wallets.
Earlier, Coinkite, the manufacturer of Coldcard, issued a warning on Thursday about an ongoing issue with seed phrases generated by Coldcard Mk3 devices. As a precaution, the company reminded all users who generated seed phrases on Mk3 devices with firmware version 4.0.1, released in March 2021, or later, that their funds may be at risk.
Subsequently, Coinkite expanded the scope of its risk advisory to include certain Mk4, Mk5, and Coldcard Q firmware versions, and released urgent firmware updates for all affected models.
Coinkite CEO Rodolfo Novak (also known as NVK) apologized on Friday and said the company takes "full responsibility" for the firmware vulnerability, acknowledging that internal review processes failed to detect the issue.
Novak also stated that the vulnerability may have been discovered with the help of artificial intelligence, noting that the incident reflects a "sobering reality in the new AI paradigm." He warned that AI-assisted code review could identify potential vulnerabilities faster than even experienced security experts, while also making it easier for attackers to exploit weaknesses in publicly available code.
