Tuesday, August 11, 2026 Latest news About 📈 Live coin prices →
Bitcoin

If You Own a Coldcard Wallet, Block Says Move Your Bitcoin Now

Block found two bugs in Coldcard hardware wallets that could let hackers guess your keys — over 1,000 BTC may already be at risk.

Marcus Whitfield4 min read
If You Own a Coldcard Wallet, Block Says Move Your Bitcoin Now

If you keep your Bitcoin on a Coldcard hardware wallet, this is your cue to check your funds. Block, the payments company behind Cash App and the Bitkey wallet, has published details of two serious security flaws in Coldcard devices that could let attackers guess the secret numbers used to generate your wallet — potentially exposing over 1,000 BTC in the process.

For anyone new to hardware wallets, the whole point of a device like Coldcard is that it keeps your private keys — the secret codes that prove you own your Bitcoin — offline and away from hackers. That protection depends entirely on those keys being generated with genuinely random, unpredictable numbers. According to Block, that’s exactly what broke.

What actually went wrong

Block says its engineering and security teams first noticed something was off after reports came in of Bitcoin being remotely stolen from wallets that weren’t even Bitkey devices. That investigation led them to Coinkite’s Coldcard line — specifically the Mk2, Mk3, Mk4, Q and Mk5 models. Block has confirmed none of its own products, including Bitkey, are affected.

The company identified two separate coding errors. On older Mk2 and Mk3 firmware, a bug caused wallets to be generated using predictable values instead of proper hardware-based randomness. On the newer Mk4, Q and Mk5 devices, the firmware tried to boost randomness during startup using a secure chip — but a flaw limited that extra randomness to just 32 bits, far too little to keep a key truly unguessable.

That matters because weak randomness is one of the oldest tricks in the book for attackers: if a hacker can narrow down the possible values a wallet could have used, they can eventually brute-force their way to your private key and drain the funds without ever touching your device.

Why moving your coins to a new wallet might not be enough

Here’s the part that trips a lot of people up: simply sending your Bitcoin to a fresh wallet address doesn’t automatically fix the problem. Block warns that if your seed phrase — the 24-word backup that recreates your wallet — was originally generated on vulnerable Coldcard firmware, that seed itself stays compromised no matter where you later import it. The fix has to happen at the source: generating an entirely new seed on updated, patched hardware.

Block also flagged that wallets protected by a weak “25th word” passphrase — an extra layer some users add on top of their seed phrase — and certain multisignature setups (where more than one key is needed to move funds) could also be exposed, not just basic single-signature wallets.

How big is this, really?

Block says the attack it originally tracked targeted single-signature wallets over roughly an hour, but researchers believe the campaign may still be running. Security engineer Clay Garrett said the team has since matched 695 earlier transactions to the same on-chain fingerprint, accounting for an additional 488.11 BTC. Combined with the initial findings, Block’s preliminary analysis puts the total amount potentially stolen at 1,082.59 BTC — a substantial sum by any measure.

Block says it privately disclosed the vulnerabilities to Coinkite, the maker of Coldcard, before going public with the findings. Block engineer Max Guise put the advice bluntly on X: “Personally I recommend that anyone affected move funds as soon as they can safely do so.”

What this means if you hold a Coldcard

Hardware wallets are usually the gold standard for keeping crypto safe, which is exactly why a flaw like this is unsettling — it undermines the one thing people trust these devices to get right. If you own a Coldcard Mk2 through Mk5, don’t wait to see if you’re one of the unlucky ones. Check for a firmware update from Coinkite, and if your seed was generated before a fix was in place, plan to move your funds to a freshly generated wallet on patched hardware rather than assuming a simple transfer solves it.

More broadly, this is a good reminder that “self-custody” doesn’t mean “risk-free” — it just shifts the risk from an exchange to your own setup, and that setup is only as strong as the code running underneath it.

Read more: Fake IRS Letters Are Targeting Crypto Holders — Here’s How to Spot Them

Sources

More Bitcoin