August 5, 2026

Real-Time Crypto Insights, News And Articles

Coldcard Warns Bitcoin Users to Move Funds as Active Exploit Continues

Here is a fully paraphrased version with a polished news-style structure:


Cold wallet manufacturer Coldcard has warned users that an ongoing vulnerability remains active, urging affected customers to move their bitcoin after the exploit caused estimated losses of up to $114 million.

The developers behind Coldcard issued an urgent alert on Tuesday, confirming that attackers are still exploiting the flaw and draining funds from some self-custody wallets.

“Please treat this as urgent. Migrate your funds,” the company said, urging users to follow the security advisory for their specific device, upgrade firmware, create a new seed phrase, and carefully transfer their holdings. Coldcard also encouraged users to spread the message to less active community members who may not have seen the warning, as those wallets remain among the most vulnerable because the fix requires manual action.

The warning comes after reports that another wave of wallet sweeps occurred on Monday. Updated figures showed attackers removed approximately 449 BTC from 709 addresses, increasing estimated total losses from around $89 million to as much as $114 million.

The vulnerability originates from firmware code that has existed since 2021. The affected scenario involves wallets where a single compromised key controls funds without requiring an additional approval layer.

The issue is limited to certain Coldcard models and firmware versions. Owners of the Mk3 model, released in 2019, are advised to immediately move funds if the wallet was initialized on firmware version 4.0.1 or newer. Users of Mk4, Mk5, and Q models running firmware versions below 5.6.0 or 1.5.0Q should update their devices, create a fresh wallet, and transfer their bitcoin.

Coldcard maker Coinkite noted that wallets created using the device’s dice-based entropy feature are not affected. This process requires users to manually roll dice at least 50 times and enter the results, allowing the wallet to generate keys from user-provided randomness rather than the vulnerable code path.

A wallet seed phrase acts as the primary key controlling cryptocurrency funds. If the seed is generated with insufficient randomness, attackers may be able to recreate it and access the wallet without physical access to the device.

Vincent Bouzon, a cybersecurity specialist at hardware wallet provider Ledger, said the incident highlights a flaw in a specific implementation rather than a failure of self-custody itself.

According to Bouzon, every cryptocurrency wallet relies on a root secret created from strong randomness, and that process must depend on secure hardware protections to prevent systems from silently falling back to weaker software-based generation methods.

He added that alternatives such as software wallets running on insecure devices can introduce even greater risks, while storing funds on centralized exchanges does not represent true ownership because users effectively hold a claim rather than direct control of their assets.

Bitcoin showed little reaction to the incident, trading near $63,800 during early U.S. trading hours on Tuesday.


About The Author