Back to News
Bitcoin Optech/

Bitcoin Optech Newsletter #416

A severe vulnerability in COLDCARD Mk3 and some Mk4, Mk5, and Q devices causes wallets to be generated with insufficient entropy, leading to theft of over 1,000 BTC. Additionally, two DoS vulnerabilities were fixed in Core Lightning, and a zero-knowledge proof of reserves prototype (zkPoH) was introduced.

high impactbearishBTC
Why It Matters

The COLDCARD vulnerability allows for the theft of funds due to predictable seed generation, which is actively being exploited, while the Core Lightning bugs could have allowed attackers to crash nodes via memory exhaustion.