BTC news: Coldcard urges users to move bitcoin as active wallet exploit continues
The cold wallet maker said the flaw behind roughly $114 million in losses remains live, with specific models and firmware still exposed.
By Shaurya Malwa|Edited by Sheldon Reback
Updated Aug 4, 2026, 12:12 p.m. Published Aug 4, 2026, 12:00 p.m.
Condividi questo articolo

Summary
The developers behind the Coldcard wallet told users to urgently move their bitcoin BTC$63.778,44, confirming Tuesday that the exploit — which has drained as much as $114 million from self-custodied wallets — is still in progress.
“Please treat this as urgent. Migrate your funds,” the company wrote, adding that the threat is active and asking users to warn holders who are “less online” and may not have seen the alert. Those are the wallets most exposed, since the fix has to be done by hand.
The warning is not precautionary. CoinDesk reported Monday that a possible fourth wave of sweeps ran throughout the day, taking roughly 449 BTC from 709 addresses on Galaxy Research’s revised count and lifting cumulative losses from about $89 million to as much as $114 million.
The flaw traces to firmware that has sat dormant since 2021, in cases where a single key controls the funds with no second approval required.
The risk, which remains until users take action, is confined to specific devices and firmware. Owners of the Mk3, Coldcard’s 2019 model, should move their funds now if the wallet was set up on firmware 4.0.1 or later. Mk4, Mk5 and Q owners on firmware below 5.6.0 or 1.5.0Q should update, create a new wallet and then move their coins across.
Coinkite has said the exception is anyone who used the device’s dice option, where a user physically rolls dice at least 50 times and types in the results, and the wallet builds its key from those numbers instead of generating its own. Those wallets never touched the broken code and are safe.
A seed is the master key controlling a wallet’s coins, so one produced with too little randomness, or entropy, can be guessed and regenerated by an attacker, who can then drain the wallet without ever touching the device.
Vincent Bouzon, director of product security at Ledger, which makes competing hardware wallets, said the incident was a failure of one implementation rather than a verdict on self-custody.
“Every wallet ultimately depends on a root secret generated from high-quality entropy,” Bouzon told CoinDesk in an email, adding that the generation of that entropy “must be anchored in secure hardware, with an architecture that cannot silently downgrade to an untrusted software-based source.”
He said the alternatives are worse, calling software wallets on non-secure hardware riskier still and saying that handing funds to a centralized exchange “isn’t ownership, it’s an IOU.”
Bitcoin traded near $63,800 in early U.S. hours Tuesday, little moved following the wallet warning, per CoinDesk data.
UPDATE (Aug. 4, 12:10 UTC): Adds first reference to Bouzon in fourth-last paragraph.
Related Assets
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
Jun 29, 2026
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
Why it matters:
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.


