Coldcard Security Warning as 449 BTC Disappears in New Attack Wave
A fresh wave of attacks on specific Coldcard wallets has resulted in the loss of nearly 450 BTC as experts warn users to move their funds immediately.

BTCcoinbeat.news
BTC/USD live chart
LIVEA fourth wave of attacks targeting Bitcoin wallets created with specific Coldcard firmware has hit the market. Blockchain researcher Alex Thorn reports that approximately 449 BTC has been moved from hundreds of addresses in a short window of time. This incident follows three previous rounds of theft that researchers have tied to a weak entropy vulnerability in Coldcard hardware released after March 2021.
Data shows that these stolen funds are being moved into new addresses with no prior history. While total losses from all four waves now exceed 1,800 BTC, analysts suggest the attackers have kept most of the stolen capital in their own control. One victim reported that some of their stolen assets were routed through an online gambling platform, though most of the seized crypto remains dormant for now.
The vulnerability affects seeds generated on Mk3, Mk4, Mk5, and Q devices using outdated firmware. Although the manufacturer, Coinkite, has released patches and halted sales of vulnerable inventory, any seed generated on older firmware remains at risk. The company has stated that a software fix cannot retroactively secure an existing, exposed seed.
If you use a Coldcard, you should move your funds to a brand new seed on a secure, updated device immediately. Users currently seeing suspicious transactions in their mempool might have a narrow window to use Replace by Fee settings to outbid the attacker and rescue their funds before the transaction confirms on the network.
Prices update live from CoinMarketCap. Market data, not financial advice.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!



