Coldcard Wallet developers have urgently called on users to move their Bitcoin, confirming on Tuesday that a vulnerability that led to the withdrawal of up to $114 million from self-custody wallets persists.
"Please treat this as an urgent matter. Move your funds," the company wrote, adding that the threat is active and asking users to warn owners who are "less frequently online" and may not have seen the alert.
These wallets are the most vulnerable because the fix must be performed manually.
"Follow the guidance for your model, update your device, generate a new seed phrase, and carefully move your funds. Help spread the word, especially to people who are less frequently online and may have missed this update. The threat remains active.", wrote Coldcard (@COLDCARDwallet) on August 4, 2026.
The warning is not precautionary. According to revised data from Galaxy Research, a fourth wave of fraudulent activity was reported on Monday, which continued throughout the day and led to the withdrawal of approximately 449 BTC from 709 addresses, increasing total losses from about $89 million to $114 million.
The vulnerability, which had been dormant since 2021, is related to firmware in cases where funds are controlled by a single key without requiring a second confirmation.
The risk, persisting until users take the necessary actions, is limited to specific devices and firmware versions. Mk3 owners, Coldcard's 2019 model, should move their funds now if the wallet was configured on firmware 4.0.1 or later. Mk4, Mk5, and Q owners with firmware below 5.6.0 or 1.5.0Q should update the firmware, create a new wallet, and then transfer their coins.
Coinkite stated that an exception is for those who used the device's "dice roll" feature, where the user physically rolls dice at least 50 times and inputs the results, and the wallet forms its key based on those numbers instead of generating its own. These wallets never touched the compromised code and are completely safe.
A seed phrase is the master key that controls a wallet's coins, so if it is generated with too low randomness or entropy, it can be guessed and regenerated by an attacker who can then drain the wallet without touching the device.
Vincent Buzon, a cybersecurity expert from competing hardware wallet maker Ledger, stated that the incident resulted from a failure in one implementation.
"Ultimately, every wallet relies on a root secret generated from high-quality entropy," Buzon wrote in an email, adding that generating this entropy "must be based on secure hardware with an architecture that cannot subtly fall back to an untrusted software source."
He said the alternatives are worse, calling software wallets on unsecured hardware even riskier and noting that entrusting funds to a centralized exchange is "not ownership, but an IOU."
On Tuesday in the US, Bitcoin traded around $63,800, virtually unchanged following the wallet warning.







