Coldcard Wallet Vulnerability Leads to $70M in Bitcoin Losses

iconNS3
Share
AI summary iconSummary
Vulnerability news emerged as over 1,000 BTC, worth about $70 million, was moved from 1,200 Coldcard-linked addresses. Coinkite warned users that seed phrases from Mk3 devices with firmware 4.0.1 or later may be compromised. The alert later expanded to include some Mk4, Mk5, and Coldcard Q versions. Emergency firmware updates were released. Coinkite CEO Rodolfo Novak apologized and said the company accepts full responsibility. Bitcoin news continues to highlight security risks in hardware wallets.

Key Point

Galaxy Research stated on Friday that over 1,000 BTC from nearly 1,200 addresses have been moved, valued at approximately $70 million, with the transactions believed to be linked to a vulnerability affecting Coldcard hardware wallets. Coinkite warned on Thursday about an ongoing issue with seed phrases generated by Coldcard Mk3 devices. Coinkite said users who generated seed phrases using Mk3 devices with firmware version 4.0.1, released in March 2021, or later may have funds at risk. Coinkite later expanded the risk alert to certain firmware versions of Mk4, Mk5, and Coldcard Q, and released emergency firmware updates for all affected models. Coinkite CEO Rodolfo Novak, also known as NVK, apologized on Friday and said the company takes full responsibility for the firmware vulnerability.

Why it matters: Wallet firmware vulnerabilities could weaken self-custody confidence when affected seed generation creates direct loss risk.

Market Sentiment

Bearish, Stress-on, Event-driven, Fear.

Reason: The reported movement of over 1,000 BTC linked to a Coldcard vulnerability creates direct custody-risk pressure for Bitcoin holders.

Similar Past Cases

In June 2023, Atomic Wallet users lost more than $35 million in crypto after a large wallet compromise, and user confidence shifted toward security audits and fund-tracking efforts. (Fortune) Difference: Atomic Wallet involved a software wallet service, while the current case centers on hardware wallet firmware and seed phrase generation.

Ripple Effect

Weak seed phrase generation can turn self-custody into a correlated loss channel across users who relied on the same firmware. If more affected firmware versions or linked BTC movements appear, then wallet-risk repricing could spread from one product to broader hardware wallet trust.

Opportunities & Risks

Opportunities: If emergency firmware updates reduce new linked movements, then users can treat the incident as more contained and focus on confirmed affected-device guidance.

Risks: If Coinkite expands the affected scope again, then reducing exposure to affected wallets and moving funds to verified safe storage can limit operational risk.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.