Finst

Coldcard Warns of Active Bitcoin Wallet Exploit

Coldcard says a firmware bug in certain Mk3, Mk4, Mk5, and Q wallets is still being exploited. Users need to refresh their seed and move their Bitcoin.

Coldcard Warns of Active Bitcoin Wallet Exploit

Key Takeaways

  • Coldcard is telling users to move their Bitcoin immediately because an active exploit is still draining funds from self-custodied wallets.
  • Updated estimates put the total at about 449 BTC stolen from 709 addresses, lifting losses to as much as $114 million.
  • Coldcard says some models and firmware versions are exposed, while wallets created with the dice option are still safe.

The team behind the Coldcard wallet warned users on Tuesday to move their Bitcoin without delay, saying the exploit that has already drained millions from self-custodied wallets is still being used. The company said this is not a hypothetical risk. The attack is still live, and users who are not checking updates regularly may be the most exposed.

Active Threat for Users

Coldcard said users should move their funds, update the device, generate a new seed, and then transfer their coins carefully. The warning is mainly for wallets that require a manual fix, which means some holders may not see it in time.

According to earlier reporting from CoinDesk, the exploit was active again on Monday. Galaxy Research’s revised count shows about 449 BTC were taken from 709 addresses, pushing total losses from roughly $89 million (€77.2 million) to as much as $114 million (€98.8 million).

Which Wallets Are at Risk

The issue traces back to firmware that has been around since 2021 in certain setups, especially those where a single key controls the funds without a second approval step. That does not mean every user is affected, but it does leave specific models and firmware versions exposed.

Owners of the Mk3, the 2019 model, need to move their funds if the wallet is running firmware 4.0.1 or later. Users of the Mk4, Mk5, and Q should update, create a new wallet, and then move their coins if they are on firmware below 5.6.0 or 1.5.0Q.

Coldcard says wallets created with the dice option are not affected. In that setup, the user rolls dice at least 50 times and enters the result by hand, and the wallet builds the key from those numbers instead of generating random data on its own.

Why This Matters More Broadly

The incident is a reminder that hardware wallets can still be vulnerable to firmware bugs, even though they are designed to make self-custody safer. For European crypto users, the takeaway is that offline storage does not eliminate risk, especially if a seed process or firmware implementation turns out to be weak.

Vincent Bouzon, product security director at Ledger, described the issue as a flaw in one implementation rather than a verdict on self-custody overall. He said every wallet ultimately relies on a root secret with strong entropy, and that this process has to be grounded in secure hardware. Bitcoin traded around $63,800 (€55,300) in the early U.S. hours on Tuesday, little changed after the warning. A recent analysis of private keys suggests the broader trend is shifting as well, with attackers increasingly targeting key management instead of smart contracts.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.