Bitcoin Optech/
Bitcoin Optech Newsletter #416
A severe vulnerability in COLDCARD Mk3 and some Mk4, Mk5, and Q devices caused wallets to be generated with insufficient entropy, leading to thefts exceeding 1,000 BTC. Additionally, two DoS vulnerabilities were fixed in Core Lightning, and a zero-knowledge proof of reserves prototype (zkPoH) was introduced.
high impactbearishBTC
Read the original report at Bitcoin OptechWhy It Matters
The COLDCARD vulnerability allows for the theft of funds due to predictable seed generation, while the Core Lightning bugs could have allowed attackers to crash nodes via memory exhaustion.