Coldcard Exploit Drains $114M from Self-Custody Wallets
Coldcard, a hardware wallet manufacturer by Coinkite, has warned users to migrate their funds due to an ongoing exploit that has drained up to $114 million from self-custody wallets. The vulnerability, which affects configurations where a single key controls funds without requiring a second approval, is linked to a firmware fragment that remained hidden since 2021.
The fourth round of sweeps, documented by Galaxy Research, took approximately 449 BTC from 709 addresses in a single day. Coinkite has urged users to update their devices, generate new seeds, and move funds immediately, citing that those who generated their seed using the physical dice option with at least 50 rolls are safe.
Vincent Bouzon, cybersecurity expert at Ledger, noted that the Coldcard incident is a specific implementation failure and not a verdict on self-custody in general. He warned that entropy generation 'must be anchored in secure hardware, with an architecture that cannot silently degrade to an untrusted software source.'
OKX has reported record levels of inflows to centralized exchanges since the case became known, drawing parallels with the collapse of FTX in 2022.