← BACK TO FEED
TAG

hardware wallets2 articles

Coldcard's Firmware Bug Let an Attacker Drain $70 Million in Bitcoin in Under an Hour

A firmware bug in Coldcard hardware wallets, introduced in March 2021, routed seed generation to a weak software pseudorandom number generator instead of the device's hardware RNG, resulting in significantly reduced entropy and predictable wallet seeds. On July 30, an attacker exploited this vulnerability to drain 1,082.65 BTC (~$70.2 million) from 1,196 addresses in just 41 minutes. Coinkite released emergency firmware on July 31, but existing seeds remain compromised, and affected users must generate a new seed on patched firmware and transfer their funds.

2 Aug 2026

OkoBot Malware Serves Fake Recovery Pages Inside Real Ledger and Trezor Apps

OkoBot is a Windows malware framework active since April 2025 that targets hardware wallet users through a module called SeedHunter, which injects fake recovery phrase prompts directly into legitimate Ledger and Trezor desktop applications rather than replacing them. The malware is delivered via ClickFix lures or trojanized software on GitHub, establishing persistent access through reverse SSH tunnels, patched RDP components, and a scheduled task called "Apple Sync," before deploying over 20 surveillance and theft modules. Kaspersky's research identified hundreds of victims across 25+ countries, but attribution remains unclear beyond soft indicators suggesting Russian-speaking threat actors.

17 Jul 2026