The developers of Coldcard, a cold wallet manufacturer, are urging users to transfer their bitcoin following an exploit that has already resulted in approximately $114 million in losses from self-managed wallets.
The vulnerability affects certain models and firmware versions that remain exposed.
According to the company, the flaw is still active, impacting specific Mk3 devices running on firmware version 4.0.1 or later, as well as Mk4, Mk5, and Q models operating on older firmware. Wallets that were generated using the dice-roll method are deemed secure.
This exploit has been a concern since 2021, enabling attackers to predict poorly randomized seed keys and potentially drain funds, despite bitcoin's price hovering around $63,800.
Coldcard has made an urgent appeal to users, stating, "Please treat this as urgent. Migrate your funds," and emphasizing that the threat is ongoing. They advised users to inform others who may not be aware of the situation, particularly those who are less active online, as they are at higher risk.
Please treat this as urgent. Migrate your funds. Follow the advisory for your model, upgrade your device, generate a new seed, and carefully move your funds.
— COLDCARD (@COLDCARDwallet) August 4, 2026
Help spread the word, especially to people who are less online and may not see this update.
The threat is still ongoing. https://t.co/cbJxJles8x
This warning is serious, not just a precaution. Reports indicate that a potential fourth wave of attacks occurred recently, with around 449 BTC being stolen from 709 addresses, raising total losses from about $89 million to as much as $114 million.
The flaw is linked to firmware that has been inactive since 2021, particularly in cases where a single key governs the funds without requiring a second approval.
The risk is limited to specific devices and firmware versions. Users of the Mk3 model, released in 2019, should transfer their funds immediately if their device is set up on firmware 4.0.1 or later. Owners of Mk4, Mk5, and Q models should update to firmware above 5.6.0 or 1.5.0Q, create a new wallet, and then transfer their coins.
Coinkite has indicated that those who used the device's dice option, where users physically roll dice multiple times and input the results, are safe, as these wallets did not interact with the compromised code.
A seed serves as the master key for a wallet's coins, and if it is generated with insufficient randomness, it can be guessed by an attacker, allowing them to drain the wallet without needing physical access.
Vincent Bouzon, a cybersecurity expert at Ledger, noted that this incident reflects a failure in one implementation rather than a broader issue with self-custody. He emphasized that every wallet relies on a root secret generated from high-quality entropy, which must be secured in hardware that cannot be downgraded to unreliable software sources.
He also remarked that alternatives, such as software wallets on insecure hardware, pose greater risks, and that trusting a centralized exchange does not equate to ownership but rather an IOU.
As of early U.S. trading hours on Tuesday, bitcoin's price remained stable around $63,800, despite the warnings from Coldcard.
UPDATE (Aug. 4, 12:10 UTC): Added the first reference to Bouzon in the fourth-last paragraph.
