Coldcard Wallet Theft Drains 594 BTC from 500 Users Amid Firmware Bug
Approximately 500 Coldcard hardware wallet owners lost a combined 594.48 BTC ($38.2 million) due to a firmware vulnerability, according to on-chain analysts.
On the night of July 31, roughly 500 owners of Coldcard hardware wallets had 594.48 BTC (around $38.2 million) stolen. The incident was flagged by on-chain analytics firm Lookonchain.
Developer Coinkite acknowledged the issue in a blog post, stating the vulnerability is tied to device firmware. The company did not directly confirm that user funds were compromised, but described the flaw in detail.
The vulnerability exists in all Mk3 firmware versions starting from 4.0.1. It also affects seed phrases generated on:
- Mk4 and Mk5 devices before firmware version 5.6.0
- Q devices before firmware version 1.5.0Q
Users are strongly advised to update their device software as soon as possible.
Source: ForkLog