Here is another rewritten version with a sharper crypto-news style:
Coldcard has issued an urgent warning to users, confirming that an active exploit targeting certain hardware wallets is still ongoing and advising affected bitcoin holders to immediately move their funds.
The hardware wallet developer said the vulnerability behind estimated losses of up to $114 million remains active, with specific devices and firmware versions still exposed to attacks.
“Please treat this as urgent. Migrate your funds,” Coldcard said in a public alert, instructing users to follow the guidance for their wallet model, update their devices, generate a new seed phrase, and carefully transfer their bitcoin. The company also urged users to share the warning with less active community members who may not have seen the notice, as those wallets remain at higher risk because the recovery process requires manual steps.
The alert follows reports of another wave of wallet drain attacks on Monday. Updated estimates showed approximately 449 BTC were taken from 709 addresses, pushing total losses linked to the exploit from around $89 million to as high as $114 million.
The vulnerability is linked to firmware code that has existed since 2021 and affects cases where a wallet relies on a single key without requiring additional authorization.
Only certain Coldcard devices and firmware versions are impacted. Mk3 users who created wallets on firmware 4.0.1 or later are advised to move their funds immediately. Owners of Mk4, Mk5, and Q models running versions below 5.6.0 or 1.5.0Q should upgrade their firmware, create a new wallet, and transfer their bitcoin to the new address.
Coinkite, the company behind Coldcard, said users who generated their wallets through the device’s dice-based entropy feature are not affected. That process requires manually rolling dice at least 50 times and entering the results, ensuring wallet keys are created from user-generated randomness rather than the affected software process.
A seed phrase is effectively the master key to a cryptocurrency wallet. If it is created using weak randomness or insufficient entropy, attackers may be able to reproduce the seed and gain access to funds without ever interacting with the physical device.
Vincent Bouzon, a cybersecurity expert at Ledger, said the incident reflects a weakness in a particular wallet implementation rather than a broader failure of self-custody.
Bouzon explained that all wallets depend on a root secret generated through high-quality entropy and that this process must rely on secure hardware designs that prevent silent fallback to less reliable software-based methods.
He added that software wallets operating on unsecured devices can pose even greater risks, while keeping assets on centralized exchanges does not provide true ownership, as users effectively hold a claim rather than direct control over their funds.
Bitcoin remained largely unaffected by the news, trading near $63,800 during early U.S. market hours on Tuesday.

































