A firmware vulnerability in Coldcard hardware wallets has led to $114 million in bitcoin losses, with affected models remaining exposed.
A critical flaw in Coldcard bitcoin wallets has resulted in losses totaling $114 million, with the exploit still active. The vulnerability affects specific models and firmware versions, allowing attackers to guess seed keys and drain funds from self-custodied wallets.
The issue impacts Mk3 devices on firmware 4.0.1 or later, as well as Mk4, Mk5, and Q devices running older firmware. Wallets created using the dice-roll option are unaffected. The flaw, present since 2021, has persisted despite bitcoin trading near $63,800.
Coldcard developers have urged users to migrate funds immediately, warning that the threat remains live. The company emphasized the need to alert less active users, who may not have seen the advisory, as manual updates are required to secure wallets.