
Here is another rewritten version with a more news-focused flow:
Coldcard has urged users to take immediate action after confirming that an ongoing exploit targeting certain wallet setups remains active, with affected bitcoin holders advised to move their funds to new wallets.
The hardware wallet provider said the vulnerability behind estimated losses of up to $114 million continues to impact specific devices and firmware versions. The company emphasized that users must manually secure their wallets rather than wait for an automatic fix.
In its emergency notice, Coldcard instructed customers to follow model-specific guidance, update their devices, create a new seed phrase, and transfer their bitcoin holdings. The company also encouraged users to spread the warning to less active community members who may have missed the alert.
The latest warning follows additional wallet sweeps reported earlier this week. Revised estimates indicate attackers drained around 449 BTC from 709 addresses, pushing total losses linked to the exploit from approximately $89 million to as high as $114 million.
The security issue stems from firmware code that has remained in place since 2021. The affected cases involve wallets relying on a single key to authorize transactions without an additional approval layer.
Only certain Coldcard configurations are vulnerable. Mk3 owners who created wallets using firmware version 4.0.1 or later are advised to migrate funds immediately. Users of Mk4, Mk5, and Q models running firmware versions below 5.6.0 or 1.5.0Q should upgrade, generate a new wallet, and move their bitcoin.
Coinkite, Coldcard’s developer, said wallets created through the device’s dice-based entropy option are not impacted. The feature allows users to manually generate wallet randomness by rolling dice at least 50 times, avoiding reliance on the affected code.
A wallet seed phrase is the primary key controlling access to funds. If generated with insufficient randomness, attackers can potentially reproduce the seed and access assets without interacting with the physical wallet.
Vincent Bouzon, a cybersecurity expert at Ledger, said the incident highlights shortcomings in one implementation rather than undermining the broader concept of self-custody.
Bouzon explained that hardware wallets depend on secure entropy generation and must ensure that key creation cannot silently switch to weaker software-based methods.
He added that software wallets running on vulnerable devices can carry even greater security risks, while exchange-held funds do not represent full ownership because users depend on the platform’s promise to return their assets.
Bitcoin prices remained relatively stable following the warning, trading near $63,800 during early U.S. market hours on Tuesday.






