×

Coldcard Tells Users to Secure Bitcoin Holdings While Wallet Attack Persists

Coldcard Tells Users to Secure Bitcoin Holdings While Wallet Attack Persists

Here is another rewritten version with a tighter, publication-style approach:


Coldcard has issued an urgent security alert, warning users that an active exploit affecting certain hardware wallet setups is still underway and advising impacted bitcoin holders to move their funds immediately.

The hardware wallet maker confirmed that the vulnerability responsible for losses estimated at up to $114 million remains unresolved for specific devices and firmware versions.

Coldcard instructed users to treat the issue as urgent, update their wallets, generate new seed phrases, and transfer their bitcoin according to the recommended steps for their specific models. The company also urged users to notify less active community members who may not have seen the warning, as securing affected wallets requires manual action.

The alert follows continued wallet-draining activity. Updated figures indicate that attackers conducted another sweep involving roughly 449 BTC across 709 addresses, increasing estimated losses from about $89 million to as much as $114 million.

The exploit is linked to firmware code introduced in 2021 and affects scenarios where a wallet’s funds are protected by a single key without an additional approval requirement.

The risk applies only to certain Coldcard devices and firmware versions. Mk3 users whose wallets were created on firmware 4.0.1 or later should move their funds immediately. Mk4, Mk5, and Q owners running older firmware versions below 5.6.0 or 1.5.0Q are advised to update, create a new wallet, and migrate their holdings.

Coinkite, the company behind Coldcard, said wallets generated using the device’s dice-based entropy feature are safe. The method allows users to manually create randomness by rolling dice at least 50 times, preventing exposure to the affected key-generation process.

A seed phrase acts as the master key for a cryptocurrency wallet. If it is created using weak randomness, attackers may be able to recreate the seed and steal funds without gaining access to the physical device.

Vincent Bouzon, a cybersecurity specialist at Ledger, said the issue reflects a flaw in a specific implementation rather than a failure of the self-custody approach.

He noted that secure wallets depend on strong entropy generation backed by hardware protections, ensuring that key creation cannot fall back to unreliable software-based sources.

Bouzon also warned that software wallets running on insecure devices may present greater risks, while storing assets on centralized exchanges does not provide true ownership because users are effectively relying on the platform’s promise to honor their balances.

Bitcoin showed little immediate reaction to the security incident, trading near $63,800 during early U.S. trading hours on Tuesday.


Share this content:

Copyright © 2025 CoinsNewz