Coldcard’s makers aren’t asking hardware wallet owners to stay vigilant. They’re asking them to shift their coins today.
On Tuesday, Coinkite verified that the exploit siphoning bitcoin out of self-custodied wallets has not stopped. The tally of stolen funds now runs as high as $114 million.
“Please treat this as urgent. Migrate your funds,” the firm said, describing the threat as active and urging customers to pass the warning along to holders who are “less online” and might have missed the alert entirely.
That request carries more weight than it first appears. Because the remedy requires manual steps, the devices most at risk are the ones tucked away in a drawer, owned by someone who glances at crypto Twitter maybe once a month.
The sweeps carried on through the weekend
This is not a cautionary note published after the danger passed. According to CoinDesk’s Monday report, what may have been a fourth round of sweeps continued all day, pulling roughly 449 BTC out of 709 addresses based on Galaxy Research’s updated tally.
Those 24 hours alone lifted total losses from around $89 million to as much as $114 million. Four waves deep, and the attacker has yet to finish working down the list.
Coinkite’s advisory states in full: “Please treat this as urgent. Migrate your funds. Follow the advisory for your model, upgrade your device, generate a new seed, and carefully move your funds. Help spread the word, especially to people who are less online and may not see this update. The threat is still ongoing.”
A flaw that has gone unnoticed since 2021
The vulnerability originates in firmware that has been quietly in place since 2021, affecting setups where one key alone controls the funds and no second signature is needed.
The seed is the master key that governs a wallet’s coins. When one is created with insufficient randomness — entropy — an attacker can work it out and recreate it, emptying the wallet without ever laying a finger on the hardware.
There was no phishing link involved. No malware on the laptop, no hijacked browser extension. The device simply produced a key that could be deduced externally, and that is the entire attack.
Look up your model and firmware number
Exposure is limited to particular devices and firmware builds, and it persists until the owner does something about it.
Owners of the Mk3, released in 2019, should relocate their funds immediately if the wallet was initialised on firmware 4.0.1 or newer.
Those holding an Mk4, Mk5 or Q running firmware older than 5.6.0 or 1.5.0Q need to update the hardware, set up a fresh wallet, and then transfer the coins over. An update by itself accomplishes nothing, since the seed already in place came out of the faulty code.
Dice users came out unscathed
Coinkite points to a single exception, and it’s a pleasingly ironic one.
Anybody who went with the device’s dice method is in the clear. That process has you roll a physical die a minimum of 50 times, enter each result, and the wallet assembles its key from those figures rather than producing its own. Such wallets never ran through the flawed code at all.
It’s the tinfoil-hat option almost nobody bothers with, and this week it turned out to be the thing that spared people. Spend the extra 10 minutes back in 2021 rolling a die, and you have nothing to worry about.
A rival weighs in — not the way you’d assume
Vincent Bouzon, a cybersecurity expert at Ledger, a maker of rival hardware wallets, had an open goal here for a sales pitch. He mostly passed on it.
In Bouzon’s framing, what went wrong was one particular implementation, not self-custody as a concept.
“Every wallet ultimately depends on a root secret generated from high-quality entropy,” Bouzon said in an email to CoinDesk, noting that producing that entropy “must be anchored in secure hardware, with an architecture that cannot silently downgrade to an untrusted software-based source.”
The alternatives, he argued, are worse: software wallets running on non-secure hardware carry even more risk, and parking funds with a centralised exchange “isn’t ownership, it’s an IOU.”
Markets barely blinked
CoinDesk data showed bitcoin changing hands around $63,800 during early trading hours in the U.S. on Tuesday, essentially flat in the wake of the wallet warning.
There’s a lesson about scale in that. Losses in the hundreds of millions, split among hundreds of individual owners, hardly move the price — which is no consolation at all if your address is one of the 709.
Dig out your Coldcard. Read the model number off the back, pull up the firmware version in settings, and if you fall into either category described above, create a new seed and shift the coins before you shut the laptop. The attacker doesn’t need a single click from you to get there first.



STAY ALWAYS UP TO DATE