|
Coldcard RNG flaw
A Coldcard RNG flaw may have exposed predictable wallet seeds linked to $88.6 million in suspected Bitcoin thefts across 4,585 addresses.
https://www.esecurityplanet.com/threats/news-coldcard-rng-flaw-bitcoin-theft/
It wasnt so long ago IDA Pro key system had the same 32 bit seed RNG flaw. But that mistake didnt cause a massive heist and was far less costly. In this case it looks like they of course knew to use a hardware RNG but due to a prepeocessor variable being defined but not 0 in a patch they pushed, it led to a fallback that was catastrophic.
|