
Coldcard, a prominent bitcoin hardware wallet maker, has issued an urgent warning urging users to move their funds as an ongoing exploit continues to drain self-custodied wallets. The company said the vulnerability behind approximately $114 million in losses is still live, and that specific models and firmware versions remain exposed. Users who have not yet transferred their bitcoin are being told to take action immediately, as the exploit shows no signs of being fully contained.
What happened?
The developers of the Coldcard bitcoin wallet publicly advised users to move their bitcoin while the exploit is still active. According to the advisory, the flaw has already led to losses of as much as $114 million from self-custodied wallets. The warning is unusually direct, reflecting the severity of the situation. Hardware wallets are generally considered one of the safest ways to store cryptocurrency because they keep private keys offline, but this incident shows that flaws in the seed generation process can undermine that security.
The exploit is not a breach of Coldcard's servers or a phishing attack. Instead, it targets the way certain wallets generate their recovery seeds. If the seed phrase is created with insufficient randomness, an attacker can guess it and drain the associated bitcoin. The company said this vulnerability has been dormant in the firmware since 2021, meaning that a wide range of wallets created over the past several years may be at risk.
Affected devices and firmware versions
Coldcard's advisory specifically identified the models and firmware configurations that are exposed. The vulnerability affects certain Mk3 devices set up on firmware 4.0.1 or later, as well as Mk4, Mk5 and Q devices running older firmware. This is a broad set of devices, and many long-time Coldcard users may fall into the affected category.
Wallets created using the dice-roll option are considered safe, according to the company. The dice-roll method allows users to generate a seed phrase using physical dice, which provides a much higher degree of randomness than the default generation method on affected firmware. Users who created their wallets with dice-roll-generated seeds may not need to move their funds, but those who relied on standard setup should be cautious.
The company also noted that the exploit is still in progress, meaning that attackers are actively scanning for vulnerable wallets. Because the flaw has existed for years, the threat is not limited to new users. Anyone who set up an affected device after the vulnerable firmware was introduced could be exposed, even if they have held their bitcoin without incident for a long time.
Why seed randomness matters
Bitcoin wallets rely on cryptographic keys to control funds. These keys are generated from a seed phrase, typically 12 or 24 words, which can be used to restore a wallet on any compatible device. The security of that seed phrase depends entirely on the randomness of its generation. If the random number generator in a device is flawed, predictable, or influenced by external factors, an attacker may be able to reproduce the seed and steal the funds.
In this case, the vulnerability allowed attackers to guess poorly randomized seed keys. Rather than trying to crack a single wallet, attackers could generate a large number of potential seeds and sweep any wallet that matches. This kind of attack is often called a "seed sweep" and can be automated at scale. The fact that the flaw has been dormant since 2021 suggests that attackers may have been quietly exploiting it, or that it was only recently discovered after a wave of unusual wallet drains.
The $114 million figure gives a sense of the scale. While that amount represents a small fraction of bitcoin's total market, it is significant for individual users, many of whom have lost their entire savings. Hardware wallet makers have built their reputations on the promise of secure self-custody, and incidents like this can shake user confidence in the broader ecosystem.
What is the dice-roll option?
Coldcard has long promoted its dice-roll option as a way for users to generate seeds with verifiable randomness. Instead of relying on the device's internal random number generator, the user physically rolls dice and enters the results. This introduces a source of entropy that is independent of the device's firmware. Because the dice rolls are physical events, attackers cannot predict them without observing the actual rolls.
The dice-roll option is considered safe in this advisory, but it is important to note that it can still be done incorrectly. For example, if users roll the dice in a predictable pattern or do not mix the results properly, the seed may still have weaknesses. Coldcard has provided detailed instructions on how to use dice rolls correctly, including how many rolls are needed and how to convert the results into a valid seed phrase. Users who are unsure about their setup are encouraged to transfer funds to a freshly generated wallet and be meticulous about following the recommended procedure.
Bitcoin price reaction
Despite the serious warning, bitcoin's price remained relatively stable. At the time of the advisory, bitcoin was trading near $63,800. Market reaction was muted, likely because the exploit is specific to certain hardware wallets and does not affect the bitcoin network itself. The broader market has been focused on inflation data, exchange-traded fund flows, and macroeconomic conditions rather than isolated incidents affecting a niche hardware wallet vendor.
However, the lack of a sharp price drop does not diminish the impact on affected users. For those who have lost funds, the price stability is little comfort. The incident also highlights an often-overlooked risk in self-custody: the security of the device is only as strong as its random number generation. Even the most advanced hardware wallet can be compromised if the random number source is flawed.
How users should respond
Coldcard is recommending that all potentially affected users move their bitcoin to a new wallet as soon as possible. The new wallet should be created using a method with verified randomness, such as the dice-roll option, or on a different device that is not vulnerable. Users should not simply update the firmware on their existing device and continue using the same seed phrase. While a firmware update may prevent future attacks, the old seed phrase has already been exposed to the vulnerability and could still be at risk.
For maximum safety, users should create an entirely new wallet with a new seed phrase, transfer their bitcoin to it, and then securely wipe the old device. Alternatively, they could move funds to a reputable exchange or custodian while they assess their options. This is not a decision to take lightly, as moving funds introduces its own risks, but in this case the risk of staying is greater.
Broader implications for hardware wallets
This incident is a reminder that hardware wallets are not immune to security flaws. The hardware wallet industry has grown rapidly over the past decade, driven by demand for self-custody and fear of exchange hacks. Companies like Coldcard have earned a reputation for prioritizing security and transparency, which makes this exploit all the more concerning.
Hardware wallet users should stay informed about firmware updates and advisories from their device makers. Many people set up a hardware wallet once and forget about it, assuming that the device will remain secure indefinitely. This event shows that firmware vulnerabilities can be introduced over time and may go unnoticed for years. Regularly checking for security announcements and periodically reviewing wallet setup practices is essential for anyone serious about protecting their assets.
The exploit also raises questions about the broader supply chain. A flawed random number generator could originate from a hardware component, a software library, or a configuration mistake. In this case, the company did not immediately disclose the root cause, but it is likely to be the subject of ongoing investigation. Security researchers will probably analyze the flaw in depth to understand how it was introduced and whether other devices are affected.
What has changed since the warning
Since the advisory was released, Coldcard has continued to provide updates. The company emphasized that the exploit is still active, meaning that attackers are still looking for vulnerable wallets. This is why the urgency is so high: waiting even a few days could put funds at greater risk. Users who have already moved their bitcoin may breathe a little easier, but those who have not acted should make it a top priority.
Some users have taken to online forums to share their experiences, with many confirming that they used the dice-roll option and therefore felt safe. Others reported that they were using affected firmware and had already transferred their funds. The community's response has been largely supportive, but there is also a sense of frustration that such a serious flaw could persist for years without detection.
While the full financial impact may not be known for some time, the $114 million figure is likely to grow if the exploit continues. Attackers typically act quickly once a vulnerability becomes known, because they know that the window of opportunity is limited. Users who delay mitigation are essentially racing against the attackers.
The incident serves as a stark reminder that bitcoin security is not just about protecting against external threats. It is also about ensuring that the tools we use to generate keys and seeds are truly random and secure. In the world of cryptography, randomness is everything. A single weakness in the random number generator can invalidate all other security measures.
For now, the priority for affected Coldcard users is clear: move bitcoin to a safe wallet, create a new seed with verified randomness, and stay alert for further announcements from the company. The exploit remains a threat, and only proactive action can protect funds from being drained.
Source:Coindesk News
