Community Trust ScoreLikely Real
Bitcoin self-custody just took a serious hit. Block’s engineering and security teams went public with two critical firmware vulnerabilities found across multiple generations of Coldcard hardware wallets — and the numbers are bad.
The affected devices cover a wide range: Coldcard Mk2, Mk3, Mk4, Q, and Mk5. Block launched its investigation after reports came in of Bitcoin being remotely stolen from wallets that weren’t Bitkey. That detail matters — Block was clear that its own Bitkey product isn’t affected. But for Coldcard users across those five models, the picture is pretty grim. The initial wave of attacks hit wallets running single-signature setups, and each attack ran for roughly an hour. Block’s warning was blunt: the campaign could still be active.
Users with weak 25th-word passphrases are also at risk. So are some multisignature configurations.
What the Firmware Actually Got Wrong
The two flaws are distinct, and both stem from randomness failures — basically the worst thing that can happen in cryptographic key generation.
For Mk2 and Mk3, the bug was a coding error that caused wallets to generate keys using predictable values instead of truly random ones. Predictable randomness in crypto key generation is essentially a skeleton key for attackers. If they can guess or reconstruct the values your wallet used, they can derive your private keys. That’s it. Game over.
The Mk4, Q, and Mk5 models had a different but equally serious problem. The firmware was supposed to pull in entropy from a secure element during boot to strengthen randomness. It didn’t work. The actual randomness was reduced to just 32 bits — far below what’s considered safe for any serious cryptographic application.
And here’s the part that catches a lot of people off guard: moving the compromised seed phrase to a different wallet doesn’t fix anything. The seed itself was generated with flawed randomness. It’s already exposed. The only real move is to generate a completely fresh wallet on clean, unaffected hardware and transfer funds there.
Block Told Coinkite First — Then Went Public
Block privately told Coinkite, the company that makes Coldcard, about the vulnerabilities before publishing anything. That’s standard responsible disclosure practice. Max Guise, a Block engineer, then went on X and told affected users to move their funds immediately when it’s safe to do so.
Security engineer Clay Garrett dug into the on-chain data and found something that made the situation look worse. Researchers tracked 695 earlier transactions that share the same on-chain fingerprint — a pattern that points to the same underlying exploit. Those transactions add up to 488.11 BTC. Stack that on top of Block’s preliminary numbers and the estimated total potentially stolen climbs to 1,082.59 BTC. That’s a lot of Bitcoin.
That figure is still preliminary. Block hasn’t called it final. But 695 transactions with a matching fingerprint isn’t noise — it looks coordinated.
What Affected Users Should Do Right Now
The advice from Block is straightforward, if uncomfortable: move your funds. Don’t wait for Coinkite to issue a patch or a statement. As of Block’s disclosure, there’s no confirmed timeline for any corrective update from Coinkite, and no word on whether affected users will get direct guidance from the manufacturer.
That leaves Coldcard users in a tough spot. Hardware wallet owners often choose self-custody precisely because they want to stay out of situations where they’re dependent on a company’s response time. Right now, though, the safest path runs directly through acting fast and not assuming the vulnerability window has closed.
Single-sig wallet holders are the clearest target based on what’s known. But users with weak passphrases or certain multisig setups can’t assume they’re safe either. Block’s language on that was careful but not reassuring.
The broader takeaway for the hardware wallet industry is probably uncomfortable reading. Firmware randomness failures aren’t new as a category of risk — but seeing them surface across five distinct Coldcard models, affecting both older and newer hardware, raises real questions about how security audits were being run and how often. Entropy bugs in key generation are exactly the kind of flaw that can sit quietly in firmware for a long time before anyone notices. By the time they do, the damage is already done.
No details yet on how long the vulnerable firmware was in circulation. Unclear whether Coinkite has confirmed the findings publicly. Block’s preliminary estimate puts the potential loss at 1,082.59 BTC across 695 flagged transactions.
Frequently Asked Questions
Which Coldcard models are affected by the Block-disclosed vulnerabilities?
Block’s findings cover Coldcard Mk2, Mk3, Mk4, Q, and Mk5 — all five models had firmware-level randomness flaws that could expose private keys.
How much Bitcoin may have been stolen through these Coldcard exploits?
Block’s preliminary analysis, combined with Clay Garrett’s on-chain research tracking 695 transactions with a shared fingerprint totaling 488.11 BTC, puts the estimated total at 1,082.59 BTC.
