ELSEIF
Your brief EB
183 stories from 71 feeds 32 clusters Refreshed 10 minutes ago next pull 13:20

DATABASES Signal 126

Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken

WHY IT MATTERS

This demonstrates how a single code change that silently degrades a security-critical component can have catastrophic and irreversible consequences—existing compromised seeds cannot be fixed by a firmware patch, requiring complete wallet migration. Engineers building systems that rely on hardware security features must ensure fallbacks are explicit and detectable rather than silent.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

A code change caused Coldcard firmware to silently fall back from a hardware random number generator to a software-based one, collapsing effective entropy from 128 bits to roughly 40 bits.

02

Attackers exploited the weak entropy to brute-force recovery seeds, stealing approximately $75 million across roughly 2,673 addresses.

03

Patching the firmware does not repair existing seeds; affected users must generate entirely new wallets and migrate their funds.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Slashdot Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken Open ↗