Coldcard urges users to move bitcoin as exploit is still in progress
The cold wallet maker said the flaw behind roughly $114 million in losses remains live, with specific models and firmware still exposed.
The developers of Coldcard wallet have urged users to move their bitcoin due to an ongoing exploit that has drained up to $114 million from self-custodied wallets. The threat is still active, and the company is calling for urgent action, emphasizing that the fix requires manual intervention. Users are advised to migrate their funds, upgrade their devices, generate new seeds, and carefully transfer their funds.
The company is emphasizing the urgency of this matter and encouraging users to inform others who may not be as online-savvy. The flaw stems from firmware that has been inactive since 2021, affecting devices that use a single key for fund control without requiring a second approval. The risk persists until users take action, and it is specifically relevant to Coldcard's Mk3 model, firmware 4.0.1 or later.
Owners of Mk4, Mk5, and Q models should also update their firmware and take necessary precautions. Coinkite has noted that dice option users are not at risk, as their wallets were not affected by the broken code. Experts have emphasized that the incident is a failure in implementation, rather than a critique of self-custody. They have stressed the importance of secure entropy generation and hardware-based solutions for wallet security.
Written by urgent.news from CoinDesk's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.