Coldcard has told users to move funds immediately after a $38 million Bitcoin theft traced back to compromised seeds generated on certain firmware versions of its hardware wallets. The issue, disclosed on July 31, hits seeds created on Coldcard Mk3 firmware from version 4.0.1 onward, plus a subset of older Mk4, Mk5, and Q firmware builds.
Why it matters
Coldcard is one of the best-known Bitcoin-only hardware wallets, long pitched to self-custody maximalists on the strength of its air-gapped operation and open-source firmware. A supply-chain compromise of that brand cuts against the narrative that secure-element devices are the safest retail custody option. The disclosed scope (Mk3 from 4.0.1, plus select older Mk4/Mk5/Q) points to a load-bearing weakness in seed generation rather than a single bad batch, which is why the vendor told users to migrate funds, not just patch firmware.
Market impact
The $38M figure is one of the largest single-wallet hardware-wallet losses on record, but it lands against a clean Bitcoin tape: BTC price held flat through the disclosure window, suggesting the market is treating the event as vendor-specific rather than systemic. Watch for follow-up firmware releases, official post-mortems from independent researchers, and any indication the weakness extends to competing hardware wallets before pricing the next leg.
Frequently asked questions
-
Which Coldcard models are affected by the compromise?
Coldcard said seeds created on Mk3 firmware from version 4.0.1 onward are affected, along with some older Mk4, Mk5, and Q firmware builds.
-
How much Bitcoin was stolen in the Coldcard attack?
The disclosed theft totals around $38 million in BTC, making it one of the largest single-wallet hardware-wallet losses on record.
-
Why is Coldcard telling users to move funds instead of just patching?
Coldcard urged migration rather than a firmware patch because the issue stems from seed generation, not a localized flaw that a simple update would close.
-
Did Bitcoin's price move after the Coldcard warning?
BTC held flat through the disclosure window, suggesting traders read the event as vendor-specific rather than a broader industry failure.
-
Is this a Coldcard-only problem or a wider hardware-wallet risk?
The disclosed scope so far points at Coldcard specifically, but watch for independent post-mortems to confirm the weakness has not crossed into competing devices.
Crypto News