Coldcard vulnerability caused over $100 million worth of Bitcoin to be stolen in 2021, with potential vulnerabilities in Zcash
The Coldcard 2021 firmware vulnerability resulted in insufficient randomness in the recovery seed, causing attackers to transfer 1600 to 1800 bitcoins from the affected wallet since July 30th, with a valuation of over $100 million. Coinkite suggests assuming that someone is using AI to review public firmware. Taylor Hornby, a researcher at Shielded Labs, has discovered a vulnerability in Zcash Orchard's blocking pool that began in 2022. During testing, it was found to generate fake ZEC, which the developers have fixed. According to Chainalysis statistics, the average daily number of on chain writes carrying malicious software instructions has increased from 2.06 to 11.1. (Source: Bitcoin.com News)