Hackers have stolen 1,367 bitcoin, worth about $86 million, from 4,585 Coldcard cold wallets made by the company Coinkite, according to reports circulating in the cryptocurrency market.

Cold wallets are physical devices that store the seed words needed to access a user's bitcoin, which itself remains recorded on the blockchain. The words are normally only accessible when the device is connected to a computer, which is why cold storage has been considered one of the safest methods for holding crypto assets.
How the flaw worked
Attackers exploited a weakness in Coinkite's algorithms. A software error in some Coldcard versions disabled the devices' random number generator, so the device instead created seed words from predictable data such as its serial number and clock information. That narrowed the possible keys to about 4 billion combinations, a range attackers could work through.
Attackers generated these possible seed words on their own computers and checked which blockchain addresses they matched. That allowed them to locate the correct addresses and withdraw funds without ever touching the wallets themselves.

The Coldcard Mk2, Mk4, Mk5 and Coldcard Q models are reported to be affected by the flawed key generation. There is currently nothing users can do, and any wallet whose seed words are found by attackers will be emptied. Coinkite has not yet said how it will compensate affected users.

