Coldcard Urges Users to Move Bitcoin as Vulnerability Remains Exploited

cryptonews.ruPublished on 2026-08-05Last updated on 2026-08-05

Abstract

Coldcard has urgently warned users to move their Bitcoin holdings, confirming on Tuesday that a vulnerability—which has already led to the theft of up to $114 million from self-custody wallets—remains actively exploited. The company stressed this is not a precautionary alert, citing a fourth wave of fraudulent transactions on Monday that drained approximately 449 BTC from 709 addresses. The flaw, dormant since 2021, involves firmware in cases where funds are controlled by a single key without a second confirmation. Users of Mk3 models (with firmware 4.0.1 or later) must transfer funds immediately. Owners of Mk4, Mk5, and Q models with firmware below 5.6.0 or 1.5.0Q should update firmware, generate a new wallet, then move coins. The vulnerability is tied to insufficient entropy during seed phrase generation, potentially allowing attackers to guess the key and drain wallets remotely. An exception is made for users who employed the device’s “dice roll” feature for key generation, as those wallets never touched the compromised code. Vincent Buzon, a cybersecurity expert at rival hardware wallet maker Ledger, noted the incident stemmed from an implementation failure, emphasizing that secure entropy generation must be hardware-based. He warned that software wallets on unprotected devices are riskier, and holding funds on centralized exchanges represents “not ownership, but an IOU.” Bitcoin traded around $63,800 in the U.S. on Tuesday, largely unaffected by the wallet warning.

Coldcard Wallet developers have urgently called on users to move their Bitcoin, confirming on Tuesday that a vulnerability that led to the withdrawal of up to $114 million from self-custody wallets persists.

"Please treat this as an urgent matter. Move your funds," the company wrote, adding that the threat is active and asking users to warn owners who are "less frequently online" and may not have seen the alert.

These wallets are the most vulnerable because the fix must be performed manually.

"Follow the guidance for your model, update your device, generate a new seed phrase, and carefully move your funds. Help spread the word, especially to people who are less frequently online and may have missed this update. The threat remains active.", wrote Coldcard (@COLDCARDwallet) on August 4, 2026.

The warning is not precautionary. According to revised data from Galaxy Research, a fourth wave of fraudulent activity was reported on Monday, which continued throughout the day and led to the withdrawal of approximately 449 BTC from 709 addresses, increasing total losses from about $89 million to $114 million.

The vulnerability, which had been dormant since 2021, is related to firmware in cases where funds are controlled by a single key without requiring a second confirmation.

The risk, persisting until users take the necessary actions, is limited to specific devices and firmware versions. Mk3 owners, Coldcard's 2019 model, should move their funds now if the wallet was configured on firmware 4.0.1 or later. Mk4, Mk5, and Q owners with firmware below 5.6.0 or 1.5.0Q should update the firmware, create a new wallet, and then transfer their coins.

Coinkite stated that an exception is for those who used the device's "dice roll" feature, where the user physically rolls dice at least 50 times and inputs the results, and the wallet forms its key based on those numbers instead of generating its own. These wallets never touched the compromised code and are completely safe.

A seed phrase is the master key that controls a wallet's coins, so if it is generated with too low randomness or entropy, it can be guessed and regenerated by an attacker who can then drain the wallet without touching the device.

Vincent Buzon, a cybersecurity expert from competing hardware wallet maker Ledger, stated that the incident resulted from a failure in one implementation.

"Ultimately, every wallet relies on a root secret generated from high-quality entropy," Buzon wrote in an email, adding that generating this entropy "must be based on secure hardware with an architecture that cannot subtly fall back to an untrusted software source."

He said the alternatives are worse, calling software wallets on unsecured hardware even riskier and noting that entrusting funds to a centralized exchange is "not ownership, but an IOU."

On Tuesday in the US, Bitcoin traded around $63,800, virtually unchanged following the wallet warning.

Trending Cryptos

Related Questions

QAccording to the article, why are some Coldcard wallets particularly vulnerable, and what specific action is recommended for owners of the Mk3 model?

AWallets that are offline less frequently are most vulnerable because the fix must be applied manually. Owners of the Mk3 model (Coldcard 2019) should transfer their funds immediately if the wallet was set up with firmware version 4.0.1 or later.

QWhat is the total estimated financial loss from the exploitation of this vulnerability as of the report, and how many addresses were affected in the fourth wave?

AThe total estimated financial loss is approximately $114 million. In the fourth wave of fraudulent transactions, approximately 449 BTC were withdrawn from 709 addresses.

QWhat was the root cause of the vulnerability as described in the article, and how long had it been dormant?

AThe vulnerability is related to the firmware in cases where funds are controlled by a single key without requiring a second confirmation. It had been dormant since 2021.

QWhich specific Coldcard users are described as an exception and considered completely safe from this vulnerability, and why?

AUsers who employed the device's 'dice roll' feature are an exception and considered absolutely safe. This is because their wallet's key is generated based on the physical dice roll results (at least 50 times), meaning it never came into contact with the compromised code.

QAccording to cybersecurity expert Vincent Buzon from Ledger, what is the fundamental requirement for generating the entropy used to create a wallet's root secret?

AVincent Buzon stated that the generation of this entropy 'must be based on secure hardware with an architecture that cannot silently fall back to an untrusted software source.'

Related Reads

Besu Patches Vulnerabilities in 5 Components: What Node Operators Need to Know

The Ethereum client Besu, developed by the Hyperledger community, has patched five security vulnerabilities discovered by blockchain security firm CertiK. These vulnerabilities, detailed in four security advisories on August 14, were all addressed in version 26.7.1, an urgent security update initially released on July 27. The intentional delay between the patch release and the public disclosure of details gave node operators a crucial window to update. JiaLiang Chang, CertiK's Director of Security Engineering, explained this "patch first, details later" model provides defenders a time advantage, allowing them to identify affected systems, test the update, and coordinate deployments—particularly important for institutional or permissioned blockchain networks requiring formal change management. The vulnerabilities, found through CertiK's "Chain Scan" attack methodology, involved issues in block announcement handling, consensus proposal buffering, WebSocket subscription limits, and JSON-RPC filter creation. If exploited, they could have allowed an attacker to exhaust a node's memory or thread resources, compromising its availability and the consensus process. Chang highlighted that while the open-source ecosystem is moving toward more formalized security testing (like differential fuzzing and bug bounty programs), coverage remains uneven. Testing often focuses more on protocol compliance than on continuous resource exhaustion, race conditions, or deployment-specific failures. He emphasized that third-party research remains vital for uncovering attack vectors beyond routine development, advocating for a mature, cumulative security model combining continuous integration, multi-node attack testing, independent audits, and regression testing for each confirmed vulnerability.

cryptonews.ru21m ago

Besu Patches Vulnerabilities in 5 Components: What Node Operators Need to Know

cryptonews.ru21m ago

Hack of Term Finance: Attacker Withdraws $8.5 Million Through Governance System Vulnerability

Decentralized lending protocol Term Finance lost $8.5 million due to an exploit of its governance mechanism, not a smart contract hack. The attacker manipulated the low voter turnout in the Meta Vaults system. By depositing just 0.5 ETH, they received a token (tmvETH) representing a share in the vault. Most users did not convert this token into a separate voting token (gtmvETH). The attacker did, gaining control of 90.66% of the issued voting power despite owning only 0.017% of the vault's capital. The attacker created a legitimate governance proposal to disable the 7-day withdrawal timelock and add their own contract to receive user funds. The proposal, publicly viewable for about 145 hours, passed due to a quorum requirement of only 5% and simple majority rule. After voting ended on August 23, 2026, the proposal was executed, allowing the immediate theft of 2,841 WETH and 1.68 million USDC (later swapped for DAI) from several vaults. The incident highlights systemic risks in decentralized governance when voting rights are separated from economic stake and low participation thresholds exist. Security mechanisms like timelocks were ineffective as the attacker could disable them from within the proposal itself. In response, Term Labs irrevocably closed all Meta Vaults and revoked DAO roles. The core lending protocol remained unaffected. The attack underscores the need for governance designs where security parameters are protected from modification through ordinary proposals.

cryptonews.ru21m ago

Hack of Term Finance: Attacker Withdraws $8.5 Million Through Governance System Vulnerability

cryptonews.ru21m ago

Trading

Spot

Hot Articles

What is $BITCOIN

DIGITAL GOLD ($BITCOIN): A Comprehensive Analysis Introduction to DIGITAL GOLD ($BITCOIN) DIGITAL GOLD ($BITCOIN) is a blockchain-based project operating on the Solana network, which aims to combine the characteristics of traditional precious metals with the innovation of decentralized technologies. While it shares a name with Bitcoin, often referred to as “digital gold” due to its perception as a store of value, DIGITAL GOLD is a separate token designed to create a unique ecosystem within the Web3 landscape. Its goal is to position itself as a viable alternative digital asset, although specifics regarding its applications and functionalities are still developing. What is DIGITAL GOLD ($BITCOIN)? DIGITAL GOLD ($BITCOIN) is a cryptocurrency token explicitly designed for use on the Solana blockchain. In contrast to Bitcoin, which provides a widely recognized value storage role, this token appears to focus on broader applications and characteristics. Notable aspects include: Blockchain Infrastructure: The token is built on the Solana blockchain, known for its capacity to handle high-speed and low-cost transactions. Supply Dynamics: DIGITAL GOLD has a maximum supply capped at 100 quadrillion tokens (100P $BITCOIN), although details regarding its circulating supply are currently undisclosed. Utility: While precise functionalities are not explicitly outlined, there are indications that the token could be utilized for various applications, potentially involving decentralized applications (dApps) or asset tokenization strategies. Who is the Creator of DIGITAL GOLD ($BITCOIN)? At present, the identity of the creators and development team behind DIGITAL GOLD ($BITCOIN) remains unknown. This situation is typical among many innovative projects within the blockchain space, particularly those aligning with decentralized finance and meme coin phenomena. While such anonymity may foster a community-driven culture, it intensifies concerns about governance and accountability. Who are the Investors of DIGITAL GOLD ($BITCOIN)? The available information indicates that DIGITAL GOLD ($BITCOIN) does not have any known institutional backers or prominent venture capital investments. The project seems to operate on a peer-to-peer model focused on community support and adoption rather than traditional funding routes. Its activity and liquidity are primarily situated on decentralized exchanges (DEXs), such as PumpSwap, rather than established centralized trading platforms, further highlighting its grassroots approach. How DIGITAL GOLD ($BITCOIN) Works The operational mechanics of DIGITAL GOLD ($BITCOIN) can be elaborated on based on its blockchain design and network attributes: Consensus Mechanism: By leveraging Solana’s unique proof-of-history (PoH) combined with a proof-of-stake (PoS) model, the project ensures efficient transaction validation contributing to the network's high performance. Tokenomics: While specific deflationary mechanisms have not been extensively detailed, the vast maximum token supply implies that it may cater to microtransactions or niche use cases that are still to be defined. Interoperability: There exists the potential for integration with Solana’s broader ecosystem, including various decentralized finance (DeFi) platforms. However, the details regarding specific integrations remain unspecified. Timeline of Key Events Here is a timeline that highlights significant milestones concerning DIGITAL GOLD ($BITCOIN): 2023: The initial deployment of the token occurs on the Solana blockchain, marked by its contract address. 2024: DIGITAL GOLD gains visibility as it becomes available for trading on decentralized exchanges like PumpSwap, allowing users to trade it against SOL. 2025: The project witnesses sporadic trading activity and potential interest in community-led engagements, although no noteworthy partnerships or technical advancements have been documented as of yet. Critical Analysis Strengths Scalability: The underlying Solana infrastructure supports high transaction volumes, which could enhance the utility of $BITCOIN in various transaction scenarios. Accessibility: The potential low trading price per token could attract retail investors, facilitating wider participation due to fractional ownership opportunities. Risks Lack of Transparency: The absence of publicly known backers, developers, or an audit process may yield skepticism regarding the project's sustainability and trustworthiness. Market Volatility: The trading activity is heavily reliant on speculative behavior, which can result in significant price volatility and uncertainty for investors. Conclusion DIGITAL GOLD ($BITCOIN) emerges as an intriguing yet ambiguous project within the rapidly evolving Solana ecosystem. While it attempts to leverage the “digital gold” narrative, its departure from Bitcoin's established role as a store of value underscores the need for a clearer differentiation of its intended utility and governance structure. Future acceptance and adoption will likely depend on addressing the current opacity and defining its operational and economic strategies more explicitly. Note: This report encompasses synthesised information available as of October 2023, and developments may have transpired beyond the research period.

2.1k Total ViewsPublished 2025.05.13Updated 2025.05.13

What is $BITCOIN

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of BTC (BTC) are presented below.

活动图片