Active Exploit Drains 449 BTC as Coldcard Urges Immediate Migration

Key Takeaways

Coldcard confirms an ongoing exploit targeting specific firmware versions, draining up to $114 million from self-custodied wallets. Users of Mk3, Mk4, Mk5, and Q devices are urged to migrate funds immediately, while those using the dice option remain safe

Woofun AI reports that the developers behind the Coldcard wallet issued an urgent directive for users to relocate their bitcoin, confirming on Tuesday that an active exploit continues to drain millions from self-custodied wallets. The threat, identified by Coinkite executive Bouzon, remains ongoing and requires manual intervention, posing a severe risk to holders who may not be actively monitoring digital alerts. The company emphasized that the warning is not precautionary but a response to a live attack vector, urging the community to assist less connected users who are most exposed to this silent drain.

The financial scale of the incident has escalated rapidly, with reports on Monday that a potential fourth wave of sweeps occurred throughout the day. This latest surge extracted roughly 449 BTC from 709 addresses, according to Galaxy Research's revised count, pushing cumulative losses from approximately $89 million to as much as $114 million. The sheer volume of stolen assets underscores the severity of the vulnerability, highlighting how quickly automated attacks can exploit dormant flaws in widely used hardware security devices.

Structurally, the flaw originates from firmware that has remained dormant since 2021, as noted on Friday, leaving any wallet configured with a single key and no second approval requirement at risk until the holder takes action. The vulnerability is specifically tied to the Mk3 model, released in 2019, where devices set up on firmware 4.0.1 or later are compromised. This historical context reveals that the security breach was not introduced recently but has been latent within the system for years, waiting for attackers to identify and exploit the lack of multi-signature safeguards in older configurations.

Woofun AI data shows that notably, not all users are affected, as Coinkite clarified that those who utilized the dice option for key generation remain safe. This method requires users to physically roll dice at least 50 times and input the results, ensuring the wallet builds its key from external randomness rather than internal generation. Consequently, these wallets never interacted with the broken code.

However, owners of the Mk4, Mk5, and Q models running firmware below 5.6.0 or 1.5.0Q must update their devices, create new wallets, and carefully migrate their coins to avoid similar exposure to the exploit.

A more critical variable is the cryptographic mechanics behind the breach, where a seed serves as the master key controlling a wallet's coins. If this seed is produced with insufficient randomness, it can be guessed and regenerated by an attacker, allowing them to drain the wallet without ever physically accessing the device. Bouzon explained that every wallet depends on a root secret generated from high-quality entropy, which must be anchored in secure hardware to prevent silent downgrades to untrusted software-based sources. He argued that software wallets on non-secure hardware are even riskier, and that handing funds to a centralized exchange is not ownership but merely an IOU.

Bitcoin traded near $63,800 in early US hours on Tuesday, showing little movement following the wallet warning. This market stability suggests that investors have not yet priced in the full systemic risk posed by the exploit, or that the affected user base is small enough relative to the broader market to avoid immediate volatility. This marks a critical juncture for self-custody security, as the incident highlights the ongoing challenges of maintaining robust cryptographic standards in long-term hardware deployments.

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions