Crypto Incidents

Coldcard Threat Remains Active as Stolen BTC Moves

✶ The Main Takeaways
  • Coldcard users should migrate their Bitcoin immediately to prevent further theft, as the exploit remains active despite firmware updates.
  • Verify new wallet backups and conduct small test transactions before transferring larger amounts to avoid mistakes and potential phishing attempts.
  • Stolen funds are being moved and converted, highlighting the urgency for users to act quickly to secure their assets before further losses occur.

Coldcard has urged owners of potentially exposed wallets to migrate their Bitcoin immediately, warning that the threat behind the widening hardware wallet exploit remains active even after emergency firmware releases.

The latest alert shifts the focus from estimating losses to preventing further theft. Previous blockchain mapping placed the suspected damage near 1,816 BTC across more than 5,200 addresses, worth roughly $114 million at the time. Those figures remain provisional because analysts identified many victims through transaction patterns rather than direct reports.

Coldcard told users to update their device, generate an entirely new seed and carefully transfer their funds. Moving the existing recovery phrase to another wallet does not resolve the problem because the weakness belongs to the seed itself, not the physical Coldcard device.

Migration Carries Its Own Risks

Coinkite’s updated security advisory lists affected firmware across the Mk2, Mk3, Mk4, Mk5 and Q product lines. Patched versions correct future seed generation but cannot strengthen recovery phrases created under vulnerable software.

The company recommends verifying the new wallet backup and receiving address, sending a small test transaction and confirming its arrival before transferring the remaining balance. It also cautioned that rushing the process could expose users to mistakes, phishing attempts or malicious transaction requests.

Seeds supplemented at creation with at least 50 independent and private dice rolls are not considered vulnerable to this randomness flaw alone. Strong, unique BIP-39 passphrases provide another barrier, although Coinkite still recommends migration because neither measure repairs the underlying seed.

The warning follows a suspected fourth sweep, which used new destination addresses and a less concentrated transaction structure than the initial attacks. That change made later activity more difficult to cluster conclusively.

Stolen Funds Begin Leaving Bitcoin

Investigators have also observed movement beyond the first-stage collection addresses. Galaxy Research head Alex Thorn reported that approximately 17 BTC linked to a victim who lost nearly 30 BTC was routed through THORChain, converted into Ether and deposited at a centralized exchange.


That route does not guarantee the attacker can cash out. Publicly identified addresses can be flagged by exchanges and blockchain monitoring firms, while cross-chain transfers create additional records for investigators to follow. However, the movement shows that at least part of the stolen balance is no longer sitting dormant.

The exploit’s final cost therefore depends on two unresolved races: whether remaining users migrate before their seeds are discovered, and whether investigators or exchanges can intercept funds as attackers begin dispersing them across networks.

Mandy Williams
Written by

Mandy Williams

Mandy Williams is a full-time cryptocurrency reporter. Having entered the blockchain space in early 2017, she leverages a diverse background in multi-niche writing and content strategy to cover the evolving digital asset market. Mandy is dedicated to breaking down complex Web3 concepts and spreading mainstream awareness of blockchain technology.