Block has urged Bitcoin holders using Coldcard hardware wallets to immediately transfer their funds following the public disclosure of two major vulnerabilities impacting several Coldcard models. The call to action came after security teams at Block, a US-based technology and financial services company led by Jack Dorsey, received reports of Bitcoin thefts from wallets not affiliated with its own Bitkey product.
Block warns Coldcard users after critical wallet flaws exposed, 1,082 BTC at risk
Critical vulnerabilities in Coldcard devices
Block’s investigation identified severe security flaws in Coldcard Mk2, Mk3, Mk4, Q, and Mk5 models, hardware wallets produced by Coinkite. While Bitkey and other Block products remain unaffected, the vulnerabilities expose users of affected devices to significant risk, particularly those leveraging single-signature wallets.
Engineers explained that an initial attack wave exploited these flaws over a period of approximately one hour. Despite this brief window, researchers cautioned that the campaign may still be ongoing, with additional affected users potentially emerging.
The flaws reportedly impact both wallets protected with weak 25th-word passphrases and select multisignature configurations.
Block noted that single-signature wallets were the primary initial targets, but devices using weak passphrases or certain multisig arrangements could also be vulnerable to exploitation.
Technical details of wallet vulnerabilities
The first vulnerability is present in the Mk2 and Mk3 firmware. A coding mistake led to wallet creation processes that depended on predictable rather than sufficiently random hardware-generated values, undermining the security assumptions for generating private keys on these models.
Later models—Mk4, Q, and Mk5—were designed to strengthen entropy input during the device boot sequence using secure-element sources. However, the implementation reduced additional randomness to just 32 bits, leaving those wallets vulnerable as well.
Security experts warned that importing a seed created with affected firmware into another wallet does not eliminate the core risk, since the compromised seed remains inherently unsafe.
Mini dictionary: Entropy, in cryptography, refers to the measure of randomness collected by a system, which is critical for generating secure cryptographic keys. Insufficient entropy can make keys predictable and easier for attackers to compromise.
Response from Block and Coinkite
Block stated that it shared the findings privately with Coinkite prior to the public announcement, aiming to give the manufacturer time to assess and manage the impact on Coldcard users.
Max Guise, a security engineer at Block, recommended rapid action from affected users. Writing on X, Guise urged anyone with potentially exposed wallets to move their funds as soon as it was safe to do so.
Max Guise emphasized the urgency, advising users to migrate their Bitcoin off vulnerable devices at the earliest safe opportunity.
Clay Garrett, another security engineer, highlighted that further investigation revealed 695 previous transactions displaying the same on-chain signature as the initial exploit, representing an additional loss of 488.11 BTC.
Block’s preliminary review suggests up to 1,082.59 BTC may have been stolen in total using these vulnerabilities.
| Coldcard Mk2, Mk3 | Predictable wallet generation | Initial exploit |
| Coldcard Mk4, Q, Mk5 | Weak entropy on boot (32 bits) | Additional 488.11 BTC |
| All affected devices | Combined campaigns | 1,082.59 BTC |
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Bitcoin Has Less Than 11 Hours Left Before July Close: Bullish August Setup in Focus

Stellar highlights Q2 network progress and outlines 2025 roadmap in leadership webinar
Bitcoin’s bear market hits 49% depth, making it the mildest structural decline on record
Global Energy Roundup: Market Talk
