Aug 4, 2026, 12:00 p.m. 2 min readColdcard wallet Mk4. (Coinkite)SummaryDevelopers of the Coldcard bitcoin wallet are urging affected users to urgently move their funds as an ongoing exploit has drained as much as $114 million from self-custodied wallets.The vulnerability affects certain Mk3 devices set up on firmware 4.0.1 or later and Mk4, Mk5 and Q devices on older firmware, while wallets created using the dice-roll option are considered safe.The flaw, dormant in firmware since 2021, allows attackers to guess poorly randomized seed keys and drain funds, even as bitcoin’s price has remained near $63,800 despite the warning.Developers behind the Coldcard wallet are telling users to urgently move their bitcoin, confirming Tuesday that the exploit — which has drained as much as $114 million from self-custodied wallets — is still ongoing."Please treat this as urgent. Migrate your funds," the company wrote, adding that the threat is active and asking users to warn holders who are "less online" and may not have seen the alert. Those are the wallets most exposed, since the fix has to be done by hand.Please treat this as urgent. Migrate your funds. Follow the advisory for your model, upgrade your device, generate a new seed, and carefully move your funds.Help spread the word, especially to people who are less online and may not see this update.The threat is still ongoing. https://t.co/cbJxJles8x— COLDCARD (@COLDCARDwallet) August 4, 2026 The warning is not precautionary. CoinDesk reported Monday that a possible fourth wave of sweeps ran through the day, taking roughly 449 BTC from 709 addresses on Galaxy Research's revised count and lifting cumulative losses from about $89 million to as much as $114 million.The flaw traces to firmware that has sat dormant since 2021, as CoinDesk wrote Friday, meaning one where a single key controls the funds with no second approval required stays at risk until its holder acts.As such, the risk is confined to specific devices and firmware. Owners of the Mk3, Coldcard's 2019 model, should move their funds now if the wallet was set up on firmware 4.0.1 or later. Coinkite has said the exception is anyone who used the device's dice option, where a user physically rolls dice at least 50 times and types in the results, and the wallet builds its key from those numbers instead of generating its own. Those wallets never touched the broken code and are safe. Mk4, Mk5 and Q owners on firmware below 5.6.0 or 1.5.0Q should update, create a new wallet and then move their coins across.A seed is the master key controlling a wallet's coins, so one produced with too little randomness can be guessed and regenerated by an attacker, who can then drain the wallet without ever touching the device."Every wallet ultimately depends on a root secret generated from high-quality entropy," Bouzon told CoinDesk in an email, adding that the generation of that entropy "must be anchored in secure hardware, with an architecture that cannot silently downgrade to an untrusted software-based source."He said the alternatives are worse, calling software wallets on non-secure hardware riskier still and saying that handing funds to a centralized exchange "isn't ownership, it's an IOU."Bitcoin traded near $63,800 in early US hours Tuesday, little moved following the wallet warning, per CoinDesk data.12345678910The Evolution of the Crypto CEX Landscape: A Case Study on BinanceThe Evolution of the Crypto CEX Landscape: A Case Study on BinanceBinance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.Jun 29, 2026Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.Why it matters:Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.View Full Report
Coldcard urges users to move bitcoin as active wallet exploit continues
The maker confirmed the flaw behind roughly $114 million in losses remains live, with specific models and firmware still exposed.

The maker confirmed the flaw behind roughly $114 million in losses remains live, with specific models and firmware still exposed.
- Migrate your funds," the company wrote, adding that the threat is active and asking users to warn holders who are "less online" and may not have seen the alert.
- Those are the wallets most exposed, since the fix has to be done by hand.Please treat this as urgent.
- Owners of the Mk3, Coldcard's 2019 model, should move their funds now if the wallet was set up on firmware 4.0.1 or later.
- Coinkite has said the exception is anyone who used the device's dice option, where a user physically rolls dice at least 50 times and types in the results, and the wallet builds its key from those numbers instead of generating its own.
What people are saying
Hot takes
Loading takes…
Comments
Discussion · 0
Sign in to comment, like, and save articles.
Sign inLoading comments…




