tags. Second paragraph: "Details of the vulnerability remain sparse, but the attack targeted wallets that had been set up using a specific firmware version. The exploit allowed attackers to extract private keys from the device, giving them full control over the funds. Coldcard, known for its focus on security and open-source code, has not yet confirmed the exact vector, but early analysis points to a flaw in the random number generation process." Translation: "দুর্বলতার বিবরণ এখনও স্পষ্ট নয়, তবে আক্রমণটি নির্দিষ্ট ফার্মওয়্যার সংস্করণ ব্যবহার করে সেটআপ করা ওয়ালেটগুলিকে লক্ষ্য করেছিল। এক্সপ্লয়েটটি আক্রমণকারীদের ডিভাইস থেকে প্রাইভেট কী বের করতে দিয়েছে, যা তাদের তহবিলের উপর সম্পূর্ণ নিয়ন্ত্রণ দিয়েছে। Coldcard, যা নিরাপত্তা এবং ওপেন-সোর্স কোডের উপর মনোযোগের জন্য পরিচিত, এখনও সঠিক ভেক্টর নিশ্চিত করেনি, তবে প্রাথমিক বিশ্লেষণ র্যান্ডম নম্বর জেনারেশন প্রক্রিয়ার একটি ত্রুটি নির্দেশ করে।" Third paragraph: "Within hours of the exploit being confirmed, developers from the Bitcoin community and Coldcard's own team collaborated on a fix. The patch was pushed to the open-source repository, and users were urged to update immediately. The speed of the response highlights the critical role of open-source code in enhancing security — anyone can review, audit, and contribute fixes. But it also means attackers can study the same code for weaknesses." Translation: "এক্সপ্লয়েট নিশ্চিত হওয়ার কয়েক ঘণ্টার মধ্যে, বিটকয়েন সম্প্রদায়ের ডেভেলপাররা এবং Coldcard-এর নিজস্ব দল একটি সমাধানে সহযোগিতা করেছে। প্যাচটি ওপেন-সোর্স রিপোজিটরিতে প্রকাশ করা হয়েছে এবং ব্যবহারকারীদের অবিলম্বে আপডেট করার আহ্বান জানানো হয়েছে। প্রতিক্রিয়ার গতি নিরাপত্তা বৃদ্ধিতে ওপেন-সোর্স কোডের গুরুত্বপূর্ণ ভূমিকা তুলে ধরে — যে কেউ পর্যালোচনা, অডিট এবং ফিক্স অবদান রাখতে পারে। তবে এর অর্থও যে আক্রমণকারীরা দুর্বলতার জন্য একই কোড অধ্যয়ন করতে পারে।" Fourth paragraph: "If you own a Coldcard, update your firmware right now. The patched version closes the vulnerability, but any wallet that was compromised before the update is likely already drained. Coldcard recommends generating new seed phrases on the updated firmware and moving any remaining funds. The exchange that saw the bulk of the stolen BTC has frozen some addresses, but recovery is far from certain."
Coldcard Exploit Drains 1,367 BTC; Open-Source Patch Deployed Within Hours




