Source: CoinDesk
“The attacker working through Coldcard-generated keys is now emptying wallets worth a few thousand dollars each. Galaxy Research flagged a third wave of sweeps early Sunday, roughly 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning UTC. That is just over a tenth of a bitcoin per victim. … The flaw traces to a March 2021 firmware build that routed seed generation to a predictable software randomiser instead of the chip’s hardware one, leaving a bounded set of possible keys that anyone with the disclosure and enough compute can reproduce offline, without ever touching a device.” (08/02/26)