Coldcard entropy flaw lets hackers steal $89M in BTC from 1,200 wallets in 41 minutes
A predictable recovery phrase vulnerability in Coldcard hardware wallets enabled a highly automated attack, draining $89 million from 1,200+ addresses in under an hour. The flaw, disclosed by Block’s security team, highlights critical supply-chain risks in entropy generation for embedded devices.