Block Exposes Coldcard Wallet Flaws That May Have Put 1,082 BTC at Risk

Daily Feed
Block Exposes Coldcard Wallet Flaws That May Have Put 1,082 BTC at Risk

Block says vulnerabilities in several Coldcard hardware wallets may have exposed more than 1, 000 BTC to theft, and if you use one of these devices, this is not the time to shrug and hope for the best.

  • Two critical bugs were disclosed in multiple Coldcard generations
  • Potential exposure could reach 1, 082.59 BTC
  • Single-signature wallets were hit first, but some multisig setups may also be at risk
  • Affected users are being urged to move funds safely and quickly

Block’s engineering and security teams say they started investigating reports of Bitcoin being taken from wallets outside of Bitkey, Block’s own product. That work led them to flaws in Coldcard Mk2, Mk3, Mk4, Q, and Mk5 devices, which the company publicly disclosed after privately notifying Coinkite, the maker of Coldcard.

According to Block engineer Max Guise, users who may be affected should not sit on their hands.

“Personally I recommend that anyone affected move funds as soon as they can safely do so, ”

That warning is blunt, but the logic is simple. In Bitcoin self-custody, the keys are the money. If wallet creation is compromised, the attacker may not need to break into the device later. They may already know enough to steal the funds.

What Block says it found

Block says its teams started receiving reports of Bitcoin being remotely stolen from non-Bitkey wallets. The investigation pointed to vulnerabilities in several Coldcard hardware wallets, with the affected models listed as Mk2, Mk3, Mk4, Q, and Mk5.

Block also said none of its own products, including Bitkey, were affected.

The core issue appears to be wallet generation, not some dramatic movie-style intrusion into a live device. That distinction matters. If a cryptocurrency wallet’s seed is created with weak or predictable randomness, the damage can begin before the user has even finished setting up the wallet. At that point, the vault is already bent at the hinges.

Why randomness is the whole game

Hardware wallets are supposed to keep private keys offline. But “offline” is only part of the promise. The other half is entropy, the randomness used to generate the keys in the first place.

Coldcard’s own documentation emphasizes this point. It supports dice-roll entropy and PGP verification of firmware because secure self-custody depends on trustworthy randomness and trustworthy software. If either one goes sideways, the whole setup gets shaky fast.

Block says the flaws differed by model. For Coldcard Mk2 and Mk3, a coding error reportedly caused wallet generation to rely on predictable values instead of enough hardware-generated randomness. For Mk4, Q, and Mk5, Block says a flaw reduced added randomness to 32 bits.

That 32-bit figure matters because it means the extra randomness was far smaller than it should have been for cryptographic safety. In plain English, the search space may have been dramatically smaller than users expected, which can make a supposedly unguessable key much easier to reconstruct if an attacker knows what to look for.

This is not a small cosmetic bug. It goes straight to the foundation of self-custody. A hardware wallet is only as strong as the seed it creates.

Who seems most exposed

Block says the initial theft campaign targeted single-signature wallets, which use one private key to authorize spending. That setup is simpler to manage, but it also gives an attacker fewer obstacles if the key material was generated badly.

The company also warned that wallets protected with weak 25th-word passphrases and some multisignature setups could be at risk. A 25th-word passphrase is an extra secret added on top of a seed phrase. It can strengthen a wallet, but only if the passphrase is strong and handled properly. It does not rescue a wallet whose underlying seed was generated from compromised randomness.

Multisignature setups are more resilient than single-key wallets, but they are not magical armor. If one or more keys in the multisig setup were created on affected devices, that weakness can carry over into the whole arrangement. Bad randomness anywhere in the key-generation chain can poison the result.

How large could the damage be?

Block’s preliminary analysis says the total potentially stolen could rise to 1, 082.59 BTC. Security engineer Clay Garrett said researchers also identified 695 earlier transactions matching the same on-chain fingerprint, adding another 488.11 BTC to the total they were tracking.

An on-chain fingerprint is a recognizable pattern in blockchain activity that lets investigators link related transactions or theft behavior. In this case, it suggests the same campaign may have produced more than one wave of theft, not just a single isolated incident.

Researchers warned the campaign is likely still active. If that assessment holds up, the risk is not just historical. It is current.

There is also an uncomfortable detail that should not be glossed over: simply importing an affected seed into another wallet does not necessarily remove the threat. If the seed itself was generated from flawed randomness, moving it around does not make it safe. You cannot launder bad entropy by giving it a fresh interface.

What users should do now

If you think you may be affected, the safest move is to treat the old seed as compromised and move funds using a fresh wallet created on trusted, verified hardware and firmware. That means clean generation, careful verification, and no recycling of the same vulnerable seed material.

For hardware wallets, firmware verification is not optional theater. Coldcard’s own guidance stresses checking signed firmware and validating the update path in its COLDCARD FAQ. That is the unglamorous part of self-custody that keeps the whole thing from becoming expensive cosplay.

And if you use multisig, do not assume the setup is automatically fine just because it has more than one signer. If any signer was generated on affected hardware, that needs to be part of the threat assessment.

Users who want to inspect firmware and follow the vendor’s paranoid update flow can use Verifying and Upgrading Firmware on COLDCARD with PGP and as a reference, while device details for the affected models are available on the Error extracting content page.

There is also a wider consumer-security angle here. Wallet users who have been burned by sloppy vendor promises may want to keep an eye on broader hardware wallet coverage, including Coldcard MK5 Launches as Bitcoin-Only Hardware Wallet with and even retail adoption plays like Best Buy Sells Tangem Hardware Wallets Nationwide, Boosting.

If you’re the type who wants to see how badly operational mistakes can spiral, the China Court Upholds 107 BTC Theft Conviction Over Stolen case is a grim reminder that seed phrase security is not some abstract nerd concern, it is the whole ballgame.

And because crypto security controversies have a habit of turning into online trench warfare, some users have been pointing to community discussion like Coldcard CEO Denies Wallet-Wide Vulnerability After 594, which shows just how fast a technical issue becomes a reputation war.

For readers tracking the broader security tooling side of things, a mention of Malwarebytes for Windows, now available on the Microsoft may seem out of place at first glance, but it underscores a boring truth: most crypto losses still start with basic endpoint hygiene going to hell.

Key questions and takeaways

  • What is self-custody?
    It means you control your own Bitcoin keys instead of trusting an exchange or custodian. That gives you more freedom, but it also means you carry the full security burden.

  • Why are these Coldcard flaws serious?
    Because they may affect wallet generation itself. If the randomness used to create a seed was weak or predictable, an attacker may be able to reconstruct keys and steal funds.

  • Which devices are named as affected?
    Block says Coldcard Mk2, Mk3, Mk4, Q, and Mk5 are affected. It also says Bitkey, Block’s own wallet product, was not affected.

  • Are multisig wallets automatically safe?
    No. Some multisignature setups may also be at risk if one or more keys were generated on affected devices or were otherwise built on weak entropy.

  • Does moving an old seed to a new wallet fix the problem?
    No, not if the seed itself was generated from compromised randomness. The safer approach is to create a fresh wallet on clean, verified hardware and move funds from there.

  • How serious could the exposure be?
    Block’s preliminary estimate puts the potentially stolen amount at 1, 082.59 BTC, with 695 earlier transactions adding another 488.11 BTC to the picture.

Self-custody is freedom, but it is not a vibe. It lives or dies on the quality of the device, the firmware, and the randomness behind the keys. If those foundations crack, the damage can be brutal, and no glossy hardware shell can save you from bad entropy.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog