Lines of code. 1,596 BTC gone

A critical security vulnerability in COLDCARD hardware wallets allowed attackers to drain 1,596 BTC due to a firmware change that weakened random number generation. The flaw, which went unnoticed for five years, highlights the risks of software-based entropy in hardware security.
Why it matters
This incident underscores the importance of rigorous security audits for hardware wallets, which are often considered the gold standard for cryptocurrency storage.
Two files, four lines, five years unnoticed. This is the COLDCARD entropy failure taken apart step by step — what the defect was, how attackers found the wallets, what affected owners should do — and the four checks OneKey runs so the same thing cannot happen here quietly.
Six steps, no jargon. The note beside each one is the precise technical version, for anyone who wants to check the work.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in