Coldcard maker Coinkite is urging users to move their Bitcoin to freshly generated wallets as an active exploit targeting seeds created on affected firmware remains in progress, with funds still at risk unless owners take immediate remediation steps.
Coldcard maker Coinkite is urging users to move their Bitcoin to freshly generated wallets as an active exploit targeting seeds created on affected firmware remains in progress, with funds still at risk unless owners take immediate remediation steps.
Why Coldcard is telling users to move Bitcoin now
The warning is not a post-mortem of a resolved incident. The Coldcard Bitcoin exploit is still live, and CoinDesk reported on August 4, 2026 that Coldcard urged users to move bitcoin because the exploit remained active and certain Mk3, Mk4, Mk5, and Q setups were still exposed. For related coverage, see Boltz Disables Bitcoin Swaps: What It Means for Users.
WHAT TO KNOW
- The exploit is still in progress, not a resolved historical issue. Seeds generated on affected firmware remain at risk right now.
- Updating firmware alone does not fix an exposed seed. Owners must generate a new seed and move their coins.
The core risk sits with the wallet seed itself, the master secret that controls every address and every coin held on the device. Coinkite’s July 30, 2026 advisory, updated August 1, warns that funds controlled by seeds generated on affected firmware are at risk, according to the company’s security advisory. For related coverage, see Hashdex to Liquidate DEFI Bitcoin ETF This Month, Selling About 225 BTC.
Official and community messaging has centered on emergency seed migration and wallet safety rather than broad market contagion. Bitcoin held near $63,908 at press time, up about 1.96% over 24 hours, even as the crypto Fear & Greed Index sat at 25, or Extreme Fear. Early reporting indicated the hack had reached more than 1,000 Bitcoin addresses.
Which Coldcard wallets and firmware versions are affected
Coinkite says Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive are affected, meaning seeds generated on those releases were produced with weakened entropy.
The exposure is broader than the two oldest models. Seeds created on Mk4, Mk5, and Q devices before their fixed firmware releases are also affected, though with lower entropy severity than the Mk2 and Mk3 units.
There is one narrow exception. An affected seed is not considered at risk if it was created with at least 50 independent, private dice rolls, or protected by a strong, unique BIP-39 passphrase.
The advisory lists fixed firmware for every affected release track: Mk2/Mk3 4.2.0 and later, Mk4/Mk5 5.6.0 and later, Q 1.5.0Q and later, Mk4/Mk5 Edge 6.6.0X and later, and Q Edge 6.6.0QX and later.
Estimates of the damage vary. According to unconfirmed reports cited by CoinDesk, researchers believe the attacker had moved roughly 1,816 BTC, about $114 million, from more than 5,200 addresses since July 30, a figure not independently confirmed here through a block explorer. Separately, Galaxy Research has estimated losses could reach $130 million.
What users need to do to secure funds
The single most important point is that a firmware update alone is not enough. Coinkite explicitly says installing fixed firmware does not repair a seed already generated on affected firmware.
The official remediation is to install the fixed firmware, generate a completely new seed, verify a new receive address, and move funds to that new wallet, per Coinkite’s technical backgrounder. The old seed must be treated as compromised even if no funds have moved yet.
On the vendor side, Coinkite’s August 2, 2026 update says the company destroyed its remaining COLDCARD inventory manufactured with the vulnerable firmware and halted shipments once the flaw was confirmed, according to its incident update. The company also said its legal team would coordinate with law enforcement across multiple jurisdictions if warranted.
The incident echoes other recent Bitcoin infrastructure scares, including when Boltz disabled Lightning swaps after an exploit while assuring users their funds were safe. For Coldcard owners, the practical takeaway is direct: check your firmware version, and if your seed was generated on an affected release without the dice-roll or passphrase protections, migrate to a new wallet before spending anything.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
