At the root, an entropy generation flaw in Coldcard devices, introduced in March 2021. Coinkite itself puts effective entropy at about 40 bits on the most exposed models. It should have been 128. The attacker never touched a single device. Everything was recomputed offline.
· 10 Views