Coldcard urges users to move bitcoin as exploit is still in progress
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
The Coldcard bitcoin wallet developers have urged users to immediately move their funds due to an ongoing exploit that has already led to the theft of up to $114 million from self-custodied wallets. The vulnerability affects certain Coldcard models (Mk3, Mk4, Mk5, Q) running specific firmware versions, allowing attackers to guess poorly randomized seed keys and drain wallet funds. Wallets created using the dice-roll option on Coldcard devices are considered safe.
Why it matters
The exploit poses a significant threat to users who have not updated or migrated their funds, as wallets with low-entropy seed keys can be compromised without direct access to the device. The incident highlights critical risks in hardware wallet security related to seed generation and firmware vulnerabilities. Coldcard's warning aims to prevent further losses and protect users who may not be as active online and aware of the danger.
Key context
The flaw has been present but dormant in Coldcard firmware since 2021 and involves a failure in secure seed key generation on some devices and firmware versions. The attack allows one root key to control funds without a second approval step, making the wallets vulnerable. Users need to upgrade firmware, create new wallets, and move funds manually to mitigate the risk. The dice-roll key generation method operates outside the compromised code and remains secure.
Key numbers and entities
Coldcard wallet developers and the company Coinkite are involved. The exploit has drained about $114 million from compromised wallets. Specific affected device models are Mk3 (firmware 4.0.1 or later), Mk4, Mk5, and Q (older firmware versions below 5.6.0 or 1.5.0Q). Bitcoin’s price remained around $63,800 at the time of reporting. Vincent Bouzon, a cybersecurity expert at Ledger, also commented on the issue.
What remains unclear
The source does not flag open questions but highlights that the threat remains active until affected users take the recommended actions, implying an ongoing risk. The exact number of wallets affected or the identities of attackers is not detailed.