Coldcard has warned users to treat the situation as urgent and move funds immediately, saying the theft campaign linked to its wallet vulnerability is still ongoing. In a statement posted on social media on Tuesday, the team said, "Please treat this as an urgent event and move your funds immediately."
The company told users to update to the latest firmware for their device model, generate a new seed phrase, and move all bitcoin into a newly created wallet. It also asked the community to spread the message, especially to people who have not followed recent updates and may not have seen the notice, since long-idle wallets are now seen as easier targets.
Suspected fourth wave pushed losses above $100 million
The warning followed fresh signs that the exploit had not stopped. Galaxy Research said on Monday that it had likely detected a fourth wave of attacks, with hackers moving about 449 BTC from 709 addresses. That raised the estimated total loss from $89 million to roughly $114 million.
According to the report, the incident traces back to a vulnerability that had been present in Coldcard firmware since 2021. If a wallet was controlled by a single private key and did not use a second layer of authorization such as multisig protection, an attacker could use the flaw to derive the private key and steal the assets.
Affected models and firmware guidance
Coldcard said the exposure is limited to specific device models and firmware versions, but the risk remains unless users take protective action.
- Coldcard Mk3, launched in 2019: users should move assets immediately if the wallet was created with firmware version 4.0.1 or later.
- Coldcard Mk4, Mk5 and Q: if the firmware version is below 5.6.0, or below 1.5.0Q for the Q model, users should update firmware first, create a new wallet, and then move bitcoin to a new address.
Parent company Coinkite identified one exception. Wallets created with the physical dice option, where the user rolled dice at least 50 times and entered the results so the wallet key was generated from that randomness rather than the built-in software routine, are described as fully safe because they never touched the infected code.
The issue centers on seed generation randomness
The report said a seed phrase functions as the master key to wallet assets. If the generation process does not have enough entropy, attackers may be able to derive and reconstruct that key. In that case, they would not need physical access to the device to drain funds remotely.
Ledger security specialist says self-custody is not the problem
Vincent Bouzon, a security specialist at rival hardware wallet maker Ledger, said the case was a technical implementation failure by one manufacturer and should not be used to dismiss the core value of self-custody.
He also argued that abandoning self-custody out of panic could expose users to other risks. Software-only wallets without secure hardware protection carry high risk, he said, while storing funds on a centralized exchange does not mean the user truly owns the assets and amounts at most to an IOU.

