TechCrunch reports attackers rebuilt wallet seed phrases remotely, draining funds without ever physically accessing the offline devices.
Fortune reports the thefts came in several waves after Coinkite disclosed the flaw in late July, affecting more than 5,200 bitcoin addresses.
The failure was in one vendor's key-generation code, not in Bitcoin's cryptography or network. Wallets using strong randomness are unaffected.
Affected holders must move funds to a new seed. A firmware update alone does not repair a key that was generated with weak randomness.
Read More →