Coldcard Warns Users to Move Bitcoin as Exploit Continues, Losses Reach $114M
AI مارکیٹ کا خلاصہ
Coldcard is urging users to migrate bitcoin as an ongoing exploit tied to dormant firmware entropy flaws has drained up to $114M from specific self-custody setups. The incident elevates operational and custodial risk across hardware wallets, may trigger precautionary on-chain movements and higher security-driven selling pressure, and reinforces counterparty vs self-custody tradeoffs. Spot BTC was little changed immediately, suggesting contained but material confidence impact.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+1.05%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Coldcard wallet maker Coinkite is urging users to move their bitcoin immediately, saying an active exploit draining self-custodied wallets remains in progress. In a Tuesday update, the company told users to "treat this as urgent" and to help alert people who are "less online", noting that the fix requires manual action and those users may be most exposed.
The warning follows new reporting from CoinDesk that a suspected fourth wave of automated sweeps ran Monday, removing about 449 BTC from 709 addresses based on a revised Galaxy Research tally. That activity pushed estimated cumulative losses from roughly $89 million to as much as $114 million.
CoinDesk previously reported the underlying weakness stems from firmware code that has existed since 2021. Wallets in which a single key can move funds without a second approval remain at risk until the owner takes action, and exposure is limited to certain devices and firmware versions.
Guidance varies by model:
- Mk3 (2019 model): Users should move funds now if the wallet was initialized on firmware 4.0.1 or later.
- Exception: Coinkite said users who generated their seed using the device's dice feature — physically rolling dice at least 50 times and entering the results — are not affected because those wallets did not rely on the vulnerable code.
- Mk4, Mk5 and Q: Owners running firmware below 5.6.0 or 1.5.0Q should update, generate a new seed, create a new wallet and then transfer coins to the new setup.
A seed is the master secret controlling a wallet's funds. If a seed is created with insufficient randomness, an attacker may be able to guess and recreate it, enabling theft without needing physical access to the device. In an email to CoinDesk, Bouzon said wallet security ultimately depends on a root secret generated from high-quality entropy and that this process "must be anchored in secure hardware" with an architecture that cannot be silently downgraded to an untrusted software-based source. He argued that alternatives are worse, describing software wallets on non-secure hardware as even riskier and saying that keeping funds on a centralized exchange "isn't ownership, it's an IOU."
Bitcoin traded around $63,800 in early U.S. hours Tuesday, little changed after the Coldcard advisory, according to CoinDesk data.