Bitcoin Hardware Wallet Maker Patches Flaws After $130 Million Exploit
Coinkite, maker of the popular Coldcard hardware wallet, has issued a firmware update following an exploit linked to the theft of $130 million in Bitcoin. The update requires users to contribute their own randomness when generating wallet 'seeds' - the secret codes used to secure and recover cryptocurrency wallets - making it harder for attackers to predict or reproduce them.
The change came after a three-week security review uncovered additional issues beyond the original exploit, all of which have now been addressed in the latest firmware release. While the incident primarily affects cryptocurrency holders, it's a useful reminder for any business using hardware security devices: even specialised, purpose-built security tools can contain flaws, and vendors need to respond quickly when weaknesses are found.
For Australian small businesses that hold or transact in cryptocurrency, or that rely on any hardware-based security devices (such as USB security keys or authentication tokens), this incident highlights the importance of keeping firmware updated and following manufacturer guidance on secure setup, including proper randomness generation where applicable.