Coldcard Warns Holders to Relocate Funds Amid Ongoing Exploit; OKX Sees Record BTC Deposits

Coldcard Warns Holders to Relocate Funds Amid Ongoing Exploit; OKX Sees Record BTC Deposits
Table of Contents

TL;DR

  • The Coldcard vulnerability, active in a 2021 firmware, has accumulated losses of up to $114 million drained from self-custody wallets.
  • The Mk3, Mk4, Mk5 and Q models are exposed depending on the firmware version installed; Coinkite urges users to migrate funds immediately.
  • OKX reports record inflows to centralized exchanges following the exploit, showing a dynamic inverse to the one triggered by the FTX collapse in 2022.

Coldcard, the popular bitcoin hardware wallet manufactured by Coinkite, is at the center of one of the largest thefts linked to a device flaw in the history of the crypto industry.

Developers confirmed that the Coldcard exploit remains active and that accumulated losses have already reached $114 million, drained from self-custody wallets across multiple waves of attacks. The fourth round of sweeps, documented by Galaxy Research, took approximately 449 BTC from 709 addresses in a single day.

The vulnerability originates in a firmware fragment that remained hidden since 2021 and affects configurations where a single key controls funds without requiring a second approval. The core weakness is insufficient entropy: when a seed is generated with low randomness, it can be reconstructed by an attacker who then drains the wallet without needing physical access to the device.

Coldcard: Which Models Are Exposed and What to Do

The models at risk are the Mk3 —if configured with firmware 4.0.1 or later— and the Mk4, Mk5 and Q with versions prior to 5.6.0 or 1.5.0Q. Coinkite indicated that those who generated their seed using the physical dice option, with at least 50 rolls, are safe because that process never used the defective code. For everyone else, the warning is clear: update the device, generate a new seed and move funds immediately.

Vincent Bouzon, cybersecurity expert at Ledger, a direct competitor in the hardware wallet segment, noted that the Coldcard incident is a specific implementation failure and not a verdict on self-custody in general. Bouzon warned that entropy generation “must be anchored in secure hardware, with an architecture that cannot silently degrade to an untrusted software source.”

The impact of the Coldcard exploit is already reflected in market flows. Jonathan Brockmeier, Chief Compliance Officer at OKX, stated that the exchange is recording “record levels of inflows to centralized exchanges” since the case became known.

Exploit coldcard

Parallels with the FTX Collapse

Brockmeier drew a direct analogy with the collapse of FTX, which in 2022 drove a mass migration toward self-custody, and described the current situation as an inverse movement. OKX also reported that during the first half of 2026 it blocked $26.3 million in losses linked to scams and protected more than $1.1 billion in assets belonging to more than half a million customers.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews