Coldcard Users Urged to Move Funds as Critical Wallet Flaws Exposed
Block has issued an urgent warning to users of Coldcard hardware wallets following the discovery of critical vulnerabilities in several models. The security flaws, which have already led to thefts of up to 1,082 BTC, were identified by Block's engineers after reports of Bitcoin thefts from non-Block affiliated wallets.
The affected devices include the Coldcard Mk2, Mk3, Mk4, Q, and Mk5 models, all produced by Coinkite. While the vulnerabilities primarily target single-signature wallets, users with weak passphrases or specific multisignature configurations may also be at risk.
Block shared its findings privately with Coinkite before publicly disclosing them to give the manufacturer time to assess and manage the impact on Coldcard users. Max Guise, a security engineer at Block, urged affected users to transfer their funds as soon as it was safe to do so. Clay Garrett highlighted that further investigation revealed 695 previous transactions displaying the same on-chain signature as the initial exploit.