Coldcard Wallet Exploit Drains Over $100 Million
A Coldcard wallet exploit has drained around $114 million from self-custodied wallets since at least August 4, 2026. Coinkite developers are urging affected users to move their funds immediately.
The vulnerability affects certain Mk3 devices set up on firmware 4.0.1 or later and Mk4, Mk5, and Q devices on older firmware. Wallets created using the dice-roll option are considered safe.
According to Coinkite, the flaw allows attackers to guess poorly randomized seed keys and drain funds, even as Bitcoin's price remains near $63,800.