Coldcard Warns Users to Move Funds Amid $114M Exploit
Coldcard, a bitcoin wallet provider, is urging its users to move their funds immediately due to an exploit that has already drained as much as $114 million from self-custodied wallets.
The vulnerability affects certain devices set up on firmware 4.0.1 or later for the Mk3 model and older firmware for the Mk4, Mk5, and Q models. Wallets created using the dice-roll option are considered safe.
The flaw has been dormant in the firmware since 2021, allowing attackers to guess poorly randomized seed keys and drain funds even as bitcoin's price remains near $63,800.
Vincent Bouzon, a cybersecurity expert at Ledger, said that the incident was a failure of one implementation rather than a verdict on self-custody. He noted that every wallet depends on a root secret generated from high-quality entropy and must be anchored in secure hardware.