SShortSingh.
Back to feed

COLDCARD Firmware RNG Flaw Linked to Suspected $88.6M Bitcoin Theft

0
·1 views

A vulnerability in COLDCARD hardware wallet firmware has been linked to the suspected theft of approximately 1,367 BTC, worth around $88.6 million, observed between July 30 and August 1, 2026. A conditional branching error in affected firmware versions caused wallet seed generation to rely on a predictable or severely limited random number generator instead of the hardware RNG. This allowed potential attackers to enumerate seed candidates offline and verify them against public Bitcoin blockchain addresses, then derive private keys and sweep funds without ever physically accessing the devices. Affected models include COLDCARD Mk2, Mk3 running firmware 4.0.0–4.1.9, and Mk4, Mk5, and Q devices below their respective patched versions. While cryptographic confirmation of exploitation has not been officially established, the theft transactions displayed automated characteristics including fixed fees, no change outputs, and rapid high-value targeting.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingHacker News ·

Apple Engineer Claims He Was Fired for Refusing to Share Customer Device IDs with AT&T

A former Apple engineer has alleged that he was terminated after he refused to send customer device identifiers to AT&T. The engineer contends that complying with the request would have compromised customer privacy, prompting his refusal. Apple has not publicly responded to the claims. The case raises questions about data-sharing practices between Apple and its carrier partners and the treatment of employees who raise privacy concerns.

0
ProgrammingDEV Community ·

How to Format IEEE Conference Paper References Correctly and Avoid Common Errors

Proper citation formatting is a critical but often overlooked requirement for researchers submitting papers to IEEE conferences. The IEEE reference style follows strict rules covering author names, paper titles, conference names, locations, dates, and page numbers, all arranged in a specific order. Errors in formatting can result in desk rejection, reputational damage, or questions about academic integrity. Graduate students and early-career researchers frequently lose time manually correcting references, adding stress to an already demanding publication process. A systematic understanding of IEEE citation rules — including sentence-case titles, abbreviated author initials, and italicized conference names — is considered essential for credibility in computer science and engineering fields.

0
ProgrammingDEV Community ·

Open-Source Tool Lets AI Assistants Analyze Videos Locally via MCP Protocol

A developer has released claude-real-video (version 0.8.0), an open-source MIT-licensed tool that enables AI clients like Claude Desktop and Cursor to process and analyze videos entirely on a user's local machine. The tool extracts scene-aware keyframes and timestamped transcripts from video URLs or local files, using scene detection to reduce redundant frames — cutting a 58-second clip from 58 sampled frames down to 26 meaningful ones. Since version 0.8.0, it ships as a Model Context Protocol (MCP) server, making it compatible with any MCP-supporting client via a simple installation and configuration step. Transcription is powered by OpenAI's Whisper model, while processed analyses are cached locally to speed up repeated queries on the same video. The project has garnered approximately 1,900 GitHub stars and has been verified end-to-end on Claude Code.

COLDCARD Firmware RNG Flaw Linked to Suspected $88.6M Bitcoin Theft · ShortSingh