cross-posted from: https://lemmy.world/post/50129024

A serious firmware flaw in COLDCARD hardware wallets has shaken the Bitcoin community after researchers linked it to large-scale wallet thefts. The issue affects seed generation, where some firmware versions produced recovery phrases with significantly lower entropy than intended. That makes the 24-word seed phrase far more predictable, allowing attackers to brute-force private keys in cases where users relied solely on the generated seed. Reports indicate hundreds of wallets have already been drained, with approximately 594 BTC stolen.