en
Back to the list

Coldcard urges users to move bitcoin as active wallet exploit continues

source-logo  coindesk.com 1 h
image

Developers behind the Coldcard wallet are telling users to urgently move their bitcoin, confirming Tuesday that the exploit — which has drained as much as $114 million from self-custodied wallets — is still ongoing.

"Please treat this as urgent. Migrate your funds," the company wrote, adding that the threat is active and asking users to warn holders who are "less online" and may not have seen the alert. Those are the wallets most exposed, since the fix has to be done by hand.

Please treat this as urgent. Migrate your funds. Follow the advisory for your model, upgrade your device, generate a new seed, and carefully move your funds.

Help spread the word, especially to people who are less online and may not see this update.

The threat is still ongoing. https://t.co/cbJxJles8x

— COLDCARD (@COLDCARDwallet) August 4, 2026

The warning is not precautionary. CoinDesk reported Monday that a possible fourth wave of sweeps ran through the day, taking roughly 449 BTC from 709 addresses on Galaxy Research's revised count and lifting cumulative losses from about $89 million to as much as $114 million.

The flaw traces to firmware that has sat dormant since 2021, as CoinDesk wrote Friday, meaning one where a single key controls the funds with no second approval required stays at risk until its holder acts.

As such, the risk is confined to specific devices and firmware. Owners of the Mk3, Coldcard's 2019 model, should move their funds now if the wallet was set up on firmware 4.0.1 or later.

Coinkite has said the exception is anyone who used the device's dice option, where a user physically rolls dice at least 50 times and types in the results, and the wallet builds its key from those numbers instead of generating its own. Those wallets never touched the broken code and are safe. Mk4, Mk5 and Q owners on firmware below 5.6.0 or 1.5.0Q should update, create a new wallet and then move their coins across.

A seed is the master key controlling a wallet's coins, so one produced with too little randomness can be guessed and regenerated by an attacker, who can then drain the wallet without ever touching the device.

"Every wallet ultimately depends on a root secret generated from high-quality entropy," Bouzon told CoinDesk in an email, adding that the generation of that entropy "must be anchored in secure hardware, with an architecture that cannot silently downgrade to an untrusted software-based source."

He said the alternatives are worse, calling software wallets on non-secure hardware riskier still and saying that handing funds to a centralized exchange "isn't ownership, it's an IOU."

Bitcoin traded near $63,800 in early US hours Tuesday, little moved following the wallet warning, per CoinDesk data.

coindesk.com