Skip to content

Sam's News — security — 2026-08-02

TL;DR

Security

Coldcard Hardware Wallet Firmware Flaw Enables $70 Million Bitcoin Theft

A firmware flaw in Coinkite's Coldcard Bitcoin hardware wallets allowed an attacker to drain $70.2 million in Bitcoin from dormant single-signature wallets in just 41 minutes.

  • 1,082.65 BTC ($70.2M) stolen from 1,196 addresses in 500 transactions
  • Bug traced to 2021 firmware update using weak software PRNG instead of hardware RNG
  • Affected Mk2, Mk3, Mk4, Mk5 and Q models; entropy as low as 40 bits vs intended 128
  • Emergency patches released July 31, but existing seeds must be migrated, not just updated
  • Seeds made with 50+ dice rolls or a BIP-39 passphrase are unaffected

Sources: The Hacker News Research

Google Chrome to Block New Tab Hijacker Extensions

Google is developing a Chrome security feature that will block policy-installed extensions from hijacking the New Tab page.

Sources: BleepingComputer RSS