Urgent Alert: Coldcard Bitcoin Wallets Under Attack – $114 Million Stolen, Users Must Act Now
Bitcoin cold wallet developer Coldcard has issued a critical emergency warning, confirming an ongoing series of sophisticated hacker attacks that have already siphoned off an estimated $114 million in Bitcoin. The company is strongly urging all users to immediately transfer their funds from Coldcard wallets to new, secure addresses.
In a stark emergency statement posted on social media, the Coldcard team emphasized: “Please treat this as an emergency and transfer your funds immediately.”
To mitigate further losses, Coldcard advises users to take immediate action: update their device to the latest firmware, regenerate a new mnemonic seed phrase, and then transfer all Bitcoin holdings to a newly established wallet. The company also appealed to the community to help spread this urgent message, especially reaching out to long-term users who may not actively follow social media updates, as these inactive wallets are currently prime targets for attackers.
Fourth Wave of Attacks Pushes Losses Past $100 Million Mark
This isn’t a speculative warning; the threat is very real and escalating. Research firm Galaxy Research reported on Monday the detection of a suspected fourth wave of attacks, during which hackers reportedly drained approximately 449 Bitcoin from 709 distinct addresses. This latest breach alone pushed the cumulative losses from an already staggering $89 million to an alarming $114 million.
The root cause of this widespread digital asset theft is a critical vulnerability that has reportedly lain dormant within Coldcard’s firmware since 2021. This flaw allows attackers to potentially deduce private keys and steal assets if a user’s wallet is solely controlled by a single private key and lacks additional authorization mechanisms, such as multi-signature (multisig) protection.
Coldcard’s Critical Directives: Secure Your Assets Now
Coldcard has clarified that the vulnerability primarily affects specific device models and firmware versions. The risk will persist unless users proactively implement protective measures. Official recommendations are detailed below:
- Coldcard Mk3 (2019 Model): If your wallet was created using firmware version 4.0.1 or any newer iteration, you must transfer all assets immediately.
- Coldcard Mk4, Mk5, and Q Models: If your device’s firmware version is below 5.6.0 (or 1.5.0Q for the Q model), you should first update the firmware. Following the update, create an entirely new wallet and then transfer your Bitcoin to this new address.
An important exception was highlighted by Coinkite, Coldcard’s parent company: wallets initially set up using the physical “Dice option” feature are considered absolutely secure. This method involves users rolling dice at least 50 times and inputting the results to generate cryptographic keys based on true random numbers, rather than relying solely on the system’s built-in pseudo-random number generator. These wallets, having avoided contact with the compromised code, remain unaffected.
In the realm of cryptography, a mnemonic seed phrase serves as the ultimate master key to control wallet assets. If the system responsible for generating this phrase lacks sufficient entropy (true randomness), attackers can exploit this weakness to easily deduce and reconstruct the key. This allows them to remotely drain a wallet’s contents without needing any physical access to the device.
Expert Perspective: A Vendor Flaw, Not a Self-Custody Failure
Responding to the incident, Vincent Bouzon, a cybersecurity expert from Ledger, a competitor in the cold wallet market, offered a crucial perspective. He asserts that this event represents a “technical implementation flaw” specific to a single vendor, rather than a fundamental indictment of the core principles of self-custody.
Bouzon further cautioned against abandoning self-custody out of panic. He emphasized that switching to other options, such as pure software (hot) wallets without robust hardware protection, introduces significantly higher risks. Similarly, entrusting funds to centralized exchanges, while seemingly convenient, means “you don’t truly own these assets; at most, it’s just an IOU.”
Disclaimer: This article is for informational purposes only and does not constitute investment advice. All content and views expressed are for reference only and do not represent the opinions or positions of BlockBeats. Investors should conduct their own research and make independent decisions. The author and BlockBeats will not be held responsible for any direct or indirect losses incurred from investor transactions.