Urgent Bitcoin Warning for Coldcard Users: Critical Call Following $114 Million Exploit
Coldcard wallet developers have urged users to immediately move their Bitcoin (BTC) assets to new addresses due to an ongoing security vulnerability.
As security concerns rise in the cryptocurrency world, popular hardware wallet manufacturer Coldcard has faced a serious exploit. The company confirmed that approximately $114 million worth of assets have been stolen from user-controlled wallets so far. Stating that the threat is still active, officials emphasized the need to warn users who may not interact frequently with the internet and might have missed this alert.
The vulnerability stems from a flaw in key generation software that has existed since 2021. Due to insufficient randomness during the creation of wallet keys, attackers can guess these keys and drain the wallets. Accounts controlled by a single key without a second confirmation mechanism are in the highest risk group.
Critical Security Warning for Coldcard Models
The security risk is limited to specific device models and software versions. Users of the full-keyboard Coldcard Q and the numeric keypad Mk5 models, as well as Mk3 and Mk4 users, need to take urgent precautions. Mk3 owners using firmware 4.0.1 or higher are requested to move their funds immediately; for Mk4, Mk5, and Q models, it is vital to upgrade to the latest firmware version and generate a completely new recovery seed.
The only group unaffected by the vulnerability are those who used the physical dice roll method during wallet setup. Assets of users who manually created their own keys by rolling dice at least 50 times remain safe, as they did not come into contact with the faulty code. Experts state that this incident is not a general failure of self-custody methods, but rather a flaw in a specific software implementation. Despite these developments, the Bitcoin (BTC) price is trading sideways around the $63,800 level.