Coldcard says exploit is still active as losses rise to $114 million

Coldcard says exploit is still active as losses rise to $114 million

N
News Editor
2026-08-05 03:34:33
Coldcard has issued an urgent warning telling users to move bitcoin out of affected wallets immediately, saying the exploit campaign tied to a firmware flaw is still underway. The wallet maker advised users to update firmware based on device model, generate a new seed phrase, and transfer funds into a newly created wallet. Galaxy Research said on Monday that a suspected fourth wave of theft moved about 449 BTC from 709 addresses, pushing total losses from $89 million to roughly $114 million. Coldcard said the issue affects only certain device models and firmware versions, while parent company Coinkite noted that wallets created with the physical dice option are not exposed because their keys were generated outside the vulnerable code path. Ledger security specialist Vincent Bouzon said the incident reflects an implementation failure by one vendor rather than a failure of self-custody itself, and warned against shifting funds into software wallets or centralized exchanges out of panic.

Coldcard has warned users to treat the situation as urgent and move funds immediately, saying the theft campaign linked to its wallet vulnerability is still ongoing. In a statement posted on social media on Tuesday, the team said, "Please treat this as an urgent event and move your funds immediately."

The company told users to update to the latest firmware for their device model, generate a new seed phrase, and move all bitcoin into a newly created wallet. It also asked the community to spread the message, especially to people who have not followed recent updates and may not have seen the notice, since long-idle wallets are now seen as easier targets.

Suspected fourth wave pushed losses above $100 million

The warning followed fresh signs that the exploit had not stopped. Galaxy Research said on Monday that it had likely detected a fourth wave of attacks, with hackers moving about 449 BTC from 709 addresses. That raised the estimated total loss from $89 million to roughly $114 million.

According to the report, the incident traces back to a vulnerability that had been present in Coldcard firmware since 2021. If a wallet was controlled by a single private key and did not use a second layer of authorization such as multisig protection, an attacker could use the flaw to derive the private key and steal the assets.

Affected models and firmware guidance

Coldcard said the exposure is limited to specific device models and firmware versions, but the risk remains unless users take protective action.

  • Coldcard Mk3, launched in 2019: users should move assets immediately if the wallet was created with firmware version 4.0.1 or later.
  • Coldcard Mk4, Mk5 and Q: if the firmware version is below 5.6.0, or below 1.5.0Q for the Q model, users should update firmware first, create a new wallet, and then move bitcoin to a new address.

Parent company Coinkite identified one exception. Wallets created with the physical dice option, where the user rolled dice at least 50 times and entered the results so the wallet key was generated from that randomness rather than the built-in software routine, are described as fully safe because they never touched the infected code.

The issue centers on seed generation randomness

The report said a seed phrase functions as the master key to wallet assets. If the generation process does not have enough entropy, attackers may be able to derive and reconstruct that key. In that case, they would not need physical access to the device to drain funds remotely.

Ledger security specialist says self-custody is not the problem

Vincent Bouzon, a security specialist at rival hardware wallet maker Ledger, said the case was a technical implementation failure by one manufacturer and should not be used to dismiss the core value of self-custody.

He also argued that abandoning self-custody out of panic could expose users to other risks. Software-only wallets without secure hardware protection carry high risk, he said, while storing funds on a centralized exchange does not mean the user truly owns the assets and amounts at most to an IOU.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.