Coldcard Wallet Flaw Puts $114 Million in Bitcoin at Risk — Users Told to Move Funds Now
A security flaw in Coldcard hardware wallets running a 2021 firmware version has been exploited to drain an estimated $114 million from self-custody cryptocurrency wallets. Coinkite, the company behind Coldcard, has confirmed that its Mk3, Mk4, Mk5 and Q models may be affected depending on which firmware version is installed on the device.
Coinkite is urging all affected users to move their funds to a secure wallet immediately while the issue is addressed. Hardware wallets are widely used because they store private keys offline, making them a preferred option for people and businesses holding cryptocurrency, but this incident shows that even offline devices are not immune to serious vulnerabilities if firmware is not kept current.
While this issue centres on a consumer and business self-custody device rather than a typical business network, any Australian small business holding cryptocurrency assets — whether for payments, treasury, or client services — should treat this as a serious warning. Firmware update practices and asset custody procedures deserve the same scrutiny as any other business-critical security control.