Bitcoin Optech/
Bitcoin Optech Newsletter #416 Recap Podcast
A critical security vulnerability was discovered in COLDCARD hardware wallets, where a firmware bug caused the Random Number Generator (RNG) to use an insecure subspace of only 232 bits (or potentially as low as 40-50 bits for some models), putting single-signature wallets without additional entropy (dice rolls or passphrases) at high risk of theft.
high impactbearishBTC
Read the original report at Bitcoin OptechWhy It Matters
The vulnerability allows attackers to brute-force seed phrases, leading to the immediate theft of funds from affected wallets. This undermines the trust in a prominent hardware wallet used for secure Bitcoin custody.