XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Markets
● Markets

Critical Vulnerabilities in Coldcard Wallets Prompt Urgent Fund Transfer Warnings for Bitcoin Holders

Block disclosed critical security flaws in multiple Coldcard hardware wallet models, potentially exposing over 1,000 BTC to theft. Bitcoin users are being advised to move their funds immediately.

JM
by Jacob Marquez · Markets Desk
Published July 31, 2026 · 2 min read

Multiple Generations of Coldcard Affected by Critical Flaws

Technology company Block has publicly disclosed two critical security vulnerabilities affecting several generations of Coldcard hardware wallets used for Bitcoin self-custody. According to Block, as reported by U.Today, the security issues impact the Coldcard Mk2, Mk3, Mk4, Q, and Mk5 devices. The company emphasized that its own Bitkey product remains entirely unaffected by these vulnerabilities.

How the Vulnerabilities Compromise Bitcoin Security

The two vulnerabilities operate through different mechanisms depending on the wallet generation affected. In the Coldcard Mk2 and Mk3 models, a coding error in the firmware caused wallet generation to depend on predictable values instead of utilizing the device’s hardware-generated randomness. This fundamental weakness undermined the cryptographic strength of wallets created on these devices. For the newer Mk4, Q, and Mk5 generations, Block identified a different flaw: although the firmware attempted to enhance entropy during the boot process using secure-element input, a design error limited the additional randomness to just 32 bits—far below the security requirements for cryptography. Users should be aware that simply importing an affected seed phrase into a different wallet does not eliminate the vulnerability; wallets generated using the compromised firmware remain at risk.

The initial attack, according to Block’s investigation, primarily targeted single-signature Bitcoin wallets and occurred over approximately one hour. However, researchers indicated the campaign appears to still be active. Wallets protected with weaker 25th-word passphrases and certain multisignature configurations are also susceptible to compromise. Block engineer Max Guise publicly advised anyone affected to move their funds to safety as soon as feasible.

Potential Scale of Theft and Market Implications

The breach appears significantly larger than initially detected. Security researcher Clay Garrett identified 695 earlier transactions displaying identical on-chain fingerprints to the discovered attack, representing an additional 488.11 BTC in potential theft. Block’s preliminary analysis indicates that when combined with initially identified losses, the total amount potentially stolen could reach 1,082.59 BTC. The company shared its findings with Coldcard manufacturer Coinkite through private disclosure before making the vulnerabilities public. This incident highlights the cascading risks that security flaws in widely-used cryptocurrency infrastructure can pose to the broader digital asset ecosystem and investor confidence.

Source: Block, via U.Today. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Markets Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.