Coldcard Issues Urgent Alert, Advises BTC Holders to Transfer Funds Amid Live Attack

Here is another rewritten version with a more concise and analytical tone:


Coldcard has warned users that a live exploit affecting certain hardware wallet configurations is still active, urging bitcoin holders with vulnerable devices to transfer their funds immediately.

The wallet manufacturer confirmed Tuesday that the security issue responsible for up to $114 million in losses has not been fully contained, with specific models and firmware versions remaining at risk.

The company issued an urgent message telling users to migrate their funds, update their devices, create new wallet seeds, and follow the recommended steps for their specific model. Coldcard also asked the community to notify users who may be less active online, as manual intervention is required to secure affected wallets.

The warning follows a reported continuation of wallet drain activity. According to revised estimates, attackers removed about 449 BTC from 709 addresses during another wave of sweeps, increasing total losses from roughly $89 million to as much as $114 million.

The vulnerability is tied to firmware code dating back to 2021 and primarily affects wallets where a single key controls funds without requiring a secondary approval mechanism.

The exposure is limited to certain devices and software versions. Mk3 users who initialized wallets on firmware 4.0.1 or newer are advised to move their bitcoin immediately. Mk4, Mk5, and Q users running firmware below version 5.6.0 or 1.5.0Q should update, create a fresh wallet, and transfer assets.

Coinkite said wallets created using Coldcard’s dice-based seed generation method are unaffected. The feature allows users to manually generate entropy by rolling dice at least 50 times, ensuring wallet keys are created from user-provided randomness rather than the compromised process.

A seed phrase serves as the root credential for accessing wallet funds. If it is generated with inadequate randomness, attackers may be able to reconstruct the key and drain assets without needing physical access to the device.

Vincent Bouzon, a cybersecurity specialist at Ledger, said the incident demonstrates a failure in a specific implementation rather than a weakness in the self-custody model itself.

Bouzon noted that secure wallet systems depend on strong entropy generation and hardware protections that prevent devices from falling back to insecure software-based sources.

He also argued that software wallets on unsecured hardware introduce greater risks, while centralized exchanges do not provide genuine ownership because users ultimately hold a claim on funds rather than direct control.

Bitcoin showed limited market reaction to the security warning, trading around $63,800 during early U.S. trading hours on Tuesday.