Loading market data...

and subtitle.

and subtitle.
and

And

. The title and subtitle. We'll produce JSON. Let's craft: Title: "Coldcard Hack Losses Top $115M as Galaxy Research Tracks 15 Attackers" Slug: "coldcard-hack-losses-top-115m-galaxy-research-15-attackers" Subtitle: "A firmware bug dating to 2021 let attackers guess seedphrases on Coinkite's Coldcard Mk3." Content: Lead paragraph: More than $115 million in bitcoin has been stolen from users of Coinkite's Coldcard hardware wallet since July 31, according to Galaxy Research. The firm says it has spoken with over 200 victims and estimates at least 15 separate attackers exploited a firmware bug that made seedphrases guessable. Then H2: "A bug that went unnoticed for years" Paragraph: The root cause is a flaw in the Coldcard Mk3's firmware, starting with version 4.0.1 in March 2021. Coinkite said seed generation could fall back to a weak software pseudorandom number generator instead of the hardware true random number generator, leaving the seedphrases open to guessing. The company said the bug "silently went unnoticed" and its potential impact grew with every release of its products. H2: "Who's behind the thefts" Galaxy Research has been tracking the attackers. The firm believes at least 15 different actors were independently working the same weakness. The stolen coins tend to be old ones: earlier research found the typical pilfered bitcoin had sat untouched for 3.5 years, and 88% of funds taken were at least a year old. That points to attackers scanning for wallets that were created long ago and forgotten. H2: "Coinkite's response" Shortly after the first hack, Coinkite urged users to update their software or move their funds off the hardware wallet. The company hasn't disclosed how many devices are affected, but the bug's reach grew with each firmware release, meaning a lot of users could be at risk. Galaxy Research says total losses could exceed $130 million, though the $115 million figure is based on the price of bitcoin at the time the coins were taken. H2: "What's next" Galaxy Research continues to interview victims and gather intelligence on the attackers. Whether any of the stolen funds can be recovered remains an open question. So does the question of liability: Coinkite acknowledged the bug but hasn't said whether it will offer compensation. For now, the advice is the same as it was in July — move your funds off the device or update the firmware. That's about 400 words? Let's count. We'll aim for 500-600. We can expand a bit. We need to ensure no AI tics. We have "That points to attackers scanning..." which is fine. We have "remains an open question" - that's okay, but not "it remains to be seen". We can change that to "What's still unclear is whether..." but we have that. We'll write more naturally. Let's produce final JSON. Check word count: We'll count roughly. We'll write paragraphs. We'll produce content string with HTML. We'll also set readability wordCount to actual count. We'll calculate after writing. Let's write the content. We'll write: Lead: More than $115 million in bitcoin has been stolen from users of Coinkite's Coldcard hardware wallet since July 31, according to Galaxy Research. The firm says it has spoken with over 200 victims and estimates at least 15 separate attackers exploited a firmware bug that made seedphrases guessable. That's two sentences. Good. H2: A bug that went unnoticed for years Paragraph: The root cause is a flaw in the Coldcard Mk3's firmware, starting with version 4.0.1 in March 2021. Coinkite said seed generation could fall back to a weak software pseudorandom number generator instead of the hardware true random number generator, leaving seedphrases open to guessing. The company said the bug "silently went unnoticed" and its potential impact grew with every release of its products. H2: Who's behind the thefts Galaxy Research has been tracking the attackers. The firm believes at least 15 different actors were independently working the same weakness. The stolen coins tend to be old ones: earlier research found the typical pilfered bitcoin had sat untouched for 3.5 years, and 88% of funds taken were at least a year old. That points to attackers scanning for wallets created long ago and forgotten. H2: Coinkite's response Shortly after the first hack, Coinkite urged users to update their software or move funds off the hardware wallet. The company hasn't disclosed how many devices are affected, but the bug's reach grew with each firmware release, meaning a lot of users could be at risk. Galaxy Research says total losses could exceed $130 million, though the $115 million figure is based on the price of bitcoin at the time the coins were taken. H2: What's next Galaxy Research continues to interview victims and gather intelligence on the attackers. Whether any of the stolen funds can be recovered remains an open question. So does the question of liability: Coinkite acknowledged the bug but hasn't said whether it will offer compensation. For now, the advice is the same as it was in July — move your funds off the device or update the firmware. That's about 300 words. We need 450-700. We can expand a bit more. Add more detail about the research, maybe mention that Galaxy Research has been speaking with victims to support them and gather intelligence. We already have that. We can add a sentence about the timeline: The first hack was reported on July 31, and Coinkite's warning came shortly after. We can also add that the bug affected Mk3 devices specifically. We can also mention that the attackers likely used the bug to guess seedphrases, meaning they didn't need physical access. We can add a paragraph under "Who's behind the thefts" about how the attackers operated. But we don't have specifics. We can say "The attackers were able to guess seedphrases, which means they didn't need physical access to the devices." That is implied but not in facts. We have "allowing attackers to guess seedphrases" so we can say that. We can also add a note about the age of the funds: "The fact that the stolen coins were so old suggests the attackers targeted wallets that had been inactive for years, possibly because they were less likely to be monitored." That's an inference but grounded in the fact. We already have that. We can also add a sentence about the scale: "Galaxy Research's estimate of 15 attackers suggests this wasn't a single group but a wider exploitation." That's fine. We can also mention that Coinkite said the bug's impact grew with every release, meaning newer versions might have also been affected? Actually the bug started in 4.0.1, and every release after that might have had it. We can say "The bug's reach grew with each firmware release, meaning even users who updated could still be vulnerable if they updated to a version that contained the flaw." That might be too much inference. We'll stick to facts. Let's write a more complete version. We'll also ensure we don't use any prohibited phrases. We'll produce the content. We'll set wordCount to maybe 500-600. We'll count. Let's write the content string. I'll write it as a single string with HTML tags. We'll also set meta description and keywords. Focus keyword: "Coldcard hack" or "Coldcard firmware bug". Let's do. Now we need to output JSON. We'll write the title, slug, subtitle, content, meta. Make sure slug is url-friendly: lowercase, hyphens. Title: "Coldcard Hack Losses Top $115M, Galaxy Research Tracks 15 Attackers" Subtitle: "A firmware bug dating to 2021 let attackers guess seedphrases on Coinkite's Coldcard Mk3." Content: I'll write the HTML. Let's craft the full content with more detail. I'll add a sentence about the timeline: "The first thefts were reported on July 31, and Coinkite issued its warning shortly after." That's from facts. Also add that Galaxy Research has been supporting victims and gathering intelligence. Already. We'll write:

More than $115 million in bitcoin has been stolen from users of Coinkite's Coldcard hardware wallet since July 31, according to Galaxy Research. The firm says it has spoken with over 200 victims and estimates at least 15 separate attackers exploited a firmware bug that made seedphrases guessable.

A bug that went unnoticed for years

The root cause is a flaw in the Coldcard Mk3's firmware, starting with version 4.0.1 in March 2021. Coinkite said seed generation could fall back to a weak software pseudorandom number generator instead of the hardware true random number generator, leaving seedphrases open to guessing. The company said the bug "silently went unnoticed" and its potential impact grew with every release of its products.

Who's behind the thefts

Galaxy Research has been tracking the attackers. The firm believes at least 15 different actors were independently working the same weakness. The stolen coins tend to be old ones: earlier research found the typical pilfered bitcoin had sat untouched for 3.5 years, and 88% of funds taken were at least a year old. That points to attackers scanning for wallets created long ago and forgotten.

Coinkite's response

Shortly after the first hack, Coinkite urged users to update their software or move funds off the hardware wallet. The company hasn't disclosed how many devices are affected, but the bug's reach grew with each firmware release, meaning a lot of users could be at risk. Galaxy Research says total losses could exceed $130 million, though the $115 million figure is based on the price of bitcoin at the time the coins were taken.

Galaxy Research continues to interview victims and gather intelligence on the attackers. Whether any of the stolen funds can be recovered remains an open question. So does the question of liability: Coinkite acknowledged the bug but hasn't said whether it will offer compensation. For now, the advice is the same as it was in July — move your funds off the device or update the firmware.