The people who build the Coldcard hardware wallet are not telling you to be careful. They’re telling you to move your money today.
Coinkite confirmed Tuesday that the exploit draining self-custodied bitcoin wallets is still in progress. Losses have reached as much as $114 million.
“Please treat this as urgent. Migrate your funds,” the company wrote, adding that the threat is active and asking users to warn holders who are “less online” and may not have seen the alert.
That last part matters more than it sounds. The fix has to be done by hand, so the wallets sitting in a drawer belonging to someone who checks crypto Twitter once a month are the ones most exposed.
The sweeps didn’t stop over the weekend
This isn’t a precautionary notice issued after the fact. CoinDesk reported Monday that a possible fourth wave of sweeps ran throughout the day, taking roughly 449 BTC from 709 addresses on Galaxy Research’s revised count.
That single day pushed cumulative losses from about $89 million to as much as $114 million. Four waves in, and the attacker is still working through the list.
The full advisory from the company reads: “Please treat this as urgent. Migrate your funds. Follow the advisory for your model, upgrade your device, generate a new seed, and carefully move your funds. Help spread the word, especially to people who are less online and may not see this update. The threat is still ongoing.”
The bug has been sitting there since 2021
The flaw traces to firmware that has sat dormant since 2021, in cases where a single key controls the funds with no second approval required.
A seed is the master key controlling a wallet’s coins. One produced with too little randomness, or entropy, can be guessed and regenerated by an attacker, who can then drain the wallet without ever touching the device.
No phishing link. No malware on your laptop. No compromised browser extension. The device generated a key that could be worked out from the outside, and that’s the whole attack.
Check your model and your firmware version
The risk is confined to specific devices and firmware, and it remains until users take action.
If you own an Mk3, the 2019 model, move your funds now if the wallet was set up on firmware 4.0.1 or later.
Mk4, Mk5 and Q owners on firmware below 5.6.0 or 1.5.0Q should update the device, create a new wallet and then move their coins across. Updating alone doesn’t help, because the seed you already have was generated by the broken code.
The dice rollers got lucky
Coinkite has said there’s one exception, and it’s an unusually satisfying one.
Anyone who used the device’s dice option is safe. You physically roll dice at least 50 times, type in the results, and the wallet builds its key from those numbers instead of generating its own. Those wallets never touched the broken code.
It’s the paranoid setting nobody uses, and this week it’s the one that saved people. If you took the extra 10 minutes in 2021 to sit there rolling a die, you’re fine.
A competitor’s take, and it’s not the one you’d expect
Vincent Bouzon, cybersecurity expert at Ledger, which makes competing hardware wallets, could have used this to sell devices. He didn’t quite.
Bouzon said the incident was a failure of one implementation rather than a verdict on self-custody.
“Every wallet ultimately depends on a root secret generated from high-quality entropy,” Bouzon told CoinDesk in an email, adding that the generation of that entropy “must be anchored in secure hardware, with an architecture that cannot silently downgrade to an untrusted software-based source.”
He said the alternatives are worse, calling software wallets on non-secure hardware riskier still, and saying that handing funds to a centralized exchange “isn’t ownership, it’s an IOU.”
The market shrugged
Bitcoin traded near $63,800 in early U.S. hours Tuesday, little moved following the wallet warning, per CoinDesk data.
That tells you something about scale. A nine-figure loss spread across hundreds of individual holders barely registers on the price, which is cold comfort if you’re one of the 709 addresses.
Go find your Coldcard. Check the model number on the back and the firmware version in the settings menu, and if you land in either bracket above, generate a new seed and move the coins before you close the laptop. The attacker doesn’t need you to click anything to get there first.