ColdCard Vulnerability Sparks Mass Migration to Secure Hardware Wallets
A recent security vulnerability in the ColdCard hardware wallet has sent users scrambling to migrate to safer alternatives. The issue, which affected devices running firmware versions 4.0.1 through 4.1.9, or on early Mk4, Mk5, and Q releases, allowed attackers to sweep Bitcoin from compromised wallets.
According to TRM Labs, the vulnerability was exploited in four waves, resulting in the theft of approximately 1,816 BTC, valued at around $116 million. The company behind ColdCard, Coinkite, acknowledged that funds generated during this window were at risk and advised users to migrate to a new seed.
CoinKite went on to recommend several alternative hardware wallets, including Ledger, Trezor, Blockstream Jade, BitBox, and others. Each of these companies has since confirmed their devices are unaffected by the vulnerability and have provided guidance for affected users to safely transfer their funds.