Skip to content
Back to Guavy Wire
Crypto

COLDCARD Wallets Compromised by Critical Entropy Flaw

Instruments
BTC COL
Share

A critical entropy flaw in COLDCARD hardware wallets has put hundreds of devices at risk. The bug, which affects wallet models Mk3 running firmware version 4.0.1 or later, can be exploited to steal BTC.

According to Coinkite, the company behind COLDCARD, users are encouraged to create new seeds and move funds as soon as they perform firmware software updates.

The flaw was discovered after approximately 594 BTC worth nearly $40 million was stolen from wallets possibly associated with the weakness. Coinkite has released emergency firmware updates for current-generation devices, including version 5.6.0 for Mk4 and Mk5 models and version 1.5.0Q for the Q device.

The company admits that threat actors may have exploited state-of-the-art artificial intelligence tools to uncover vulnerabilities that older methods of review didn't catch. Coinkite has conducted a thorough audit of its own code base with one of the most popular AI models in the industry and still found the error.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc