Key Point
Coldcard developers told affected users to urgently move their bitcoin because the exploit is still ongoing and has drained as much as $114 million from self-custodied wallets. The vulnerability affects certain Mk3 devices set up on firmware 4.0.1 or later and Mk4, Mk5 and Q devices on older firmware. Wallets created using the dice-roll option are considered safe. Galaxy Research's revised count put a possible fourth sweep at roughly 449 BTC from 709 addresses. Coldcard said affected users should follow the advisory for their model, upgrade the device, generate a new seed, and carefully move funds.
Why it matters: A live wallet exploit can weaken confidence in self-custody tools and may force users to move funds quickly to reduce theft risk.
Market Sentiment
Bearish, Stress-on, Tech-driven.
Reason: The exploit has drained as much as $114 million from self-custodied wallets, which creates a direct security concern for affected users.
Similar Past Cases
In June 2023, the Atomic Wallet hack affected less than 0.1% of 5 million users, while Elliptic later put stolen funds above $100 million and reported $1 million frozen across exchanges. (Decrypt) The difference is that the Atomic Wallet incident involved a non-custodial app, while the Coldcard case is tied to specific hardware wallet firmware and Bitcoin seed generation.
Ripple Effect
The first channel is self-custody confidence, because users may move funds from vulnerable devices into newly generated wallets while the exploit remains active. If additional sweeps continue, then hardware-wallet users may demand clearer firmware-risk disclosures and seed-generation guidance. If migration instructions reduce new drains, then the impact may stay concentrated among affected Coldcard devices.
Opportunities & Risks
Opportunities: If a user owns an affected Coldcard model, then moving funds after following the model advisory is a direct risk-reduction action. If Coldcard confirms the threat is contained, then confidence in unaffected setups may stabilize.
Risks: If owners delay manual migration, then vulnerable wallets can remain exposed to further drains. If users rush migration without verifying seed handling, then operational mistakes can create additional loss risk.

