Todayan hour ago
Project update
Coldcard Wallet Flaw Drains $38M From Owners

Coldcard Wallet Flaw Drains $38M From Owners

About 500 people who kept bitcoin on older Coldcard Mk3 hardware wallets were robbed. Around 594 BTC, roughly $38M, was swept out of their wallets in just 25 minutes.


Some Mk3 devices on older firmware skipped the chip's true random generator, so their secret keys came from predictable data instead. That let an attacker recreate the keys and drain the coins. Newer models like Mk4, Q and Mk5 are reported unaffected.


The flaw affects seeds made on Mk3 firmware 4.0.1 to 5.0.3. Maker Coinkite says there is no public proof yet directly tying the bug to this sweep, so treat the link as suspected, not confirmed. The BTC looks unrecoverable, passphrase-protected wallets are considered low risk, and Coinkite advises moving funds to a new seed on unaffected hardware. No token is involved.