COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: Block warns Coldcard users after critical wallet flaws exposed, 1,082 BTC at risk
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Bitcoin (BTC) > Block warns Coldcard users after critical wallet flaws exposed, 1,082 BTC at risk
Bitcoin (BTC)

Block warns Coldcard users after critical wallet flaws exposed, 1,082 BTC at risk

In Brief

  • 🚨 Block warns Coldcard users after critical wallet flaws exposed.

  • 💰 Over 1,082 BTC potentially stolen as attackers exploit device vulnerabilities.

  • 🔒 Affected wallets include several Coldcard models, not Block’s own Bitkey.

  • 🕵️‍♂️ Security experts urge Bitcoin self-custody users to move funds from $BTC wallets at risk.
Onur Atam
Onur Atam 12 minutes ago
Share
SHARE

Block has urged Bitcoin holders using Coldcard hardware wallets to immediately transfer their funds following the public disclosure of two major vulnerabilities impacting several Coldcard models. The call to action came after security teams at Block, a US-based technology and financial services company led by Jack Dorsey, received reports of Bitcoin thefts from wallets not affiliated with its own Bitkey product.

Contents
Critical vulnerabilities in Coldcard devicesTechnical details of wallet vulnerabilitiesResponse from Block and Coinkite

Critical vulnerabilities in Coldcard devices

Block’s investigation identified severe security flaws in Coldcard Mk2, Mk3, Mk4, Q, and Mk5 models, hardware wallets produced by Coinkite. While Bitkey and other Block products remain unaffected, the vulnerabilities expose users of affected devices to significant risk, particularly those leveraging single-signature wallets.

Engineers explained that an initial attack wave exploited these flaws over a period of approximately one hour. Despite this brief window, researchers cautioned that the campaign may still be ongoing, with additional affected users potentially emerging.

The flaws reportedly impact both wallets protected with weak 25th-word passphrases and select multisignature configurations.

Block noted that single-signature wallets were the primary initial targets, but devices using weak passphrases or certain multisig arrangements could also be vulnerable to exploitation.

Technical details of wallet vulnerabilities

The first vulnerability is present in the Mk2 and Mk3 firmware. A coding mistake led to wallet creation processes that depended on predictable rather than sufficiently random hardware-generated values, undermining the security assumptions for generating private keys on these models.

Later models—Mk4, Q, and Mk5—were designed to strengthen entropy input during the device boot sequence using secure-element sources. However, the implementation reduced additional randomness to just 32 bits, leaving those wallets vulnerable as well.

Security experts warned that importing a seed created with affected firmware into another wallet does not eliminate the core risk, since the compromised seed remains inherently unsafe.

Mini dictionary: Entropy, in cryptography, refers to the measure of randomness collected by a system, which is critical for generating secure cryptographic keys. Insufficient entropy can make keys predictable and easier for attackers to compromise.

Response from Block and Coinkite

Block stated that it shared the findings privately with Coinkite prior to the public announcement, aiming to give the manufacturer time to assess and manage the impact on Coldcard users.

Max Guise, a security engineer at Block, recommended rapid action from affected users. Writing on X, Guise urged anyone with potentially exposed wallets to move their funds as soon as it was safe to do so.

Max Guise emphasized the urgency, advising users to migrate their Bitcoin off vulnerable devices at the earliest safe opportunity.

Clay Garrett, another security engineer, highlighted that further investigation revealed 695 previous transactions displaying the same on-chain signature as the initial exploit, representing an additional loss of 488.11 BTC.

Block’s preliminary review suggests up to 1,082.59 BTC may have been stolen in total using these vulnerabilities.

Affected Device ModelsFlaw TypeEstimated Impact (BTC)
Coldcard Mk2, Mk3Predictable wallet generationInitial exploit
Coldcard Mk4, Q, Mk5Weak entropy on boot (32 bits)Additional 488.11 BTC
All affected devicesCombined campaigns1,082.59 BTC
You can follow our news on X, Telegram, Facebook & Coinmarketcap
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

Hyperscale Data sells 100 Bitcoin, backs $1.2 billion AI campus in Michigan

Bitcoin whale adds $80.9 million, price nears key $64,900 resistance

Strategy reports $8.22 billion Q2 loss as Bitcoin falls 50% from peak

Ray Dalio confirms 1% Bitcoin allocation, says gold still preferred

Bitcoin holds above $64,500 as US inflation data meets forecasts, Bitwise expects muted rate sensitivity

Onur Atam 31 July, 2026 - 8:56 am 31 July, 2026 - 8:55 am
Share This Article
Facebook Twitter
Share
Onur Atam
By Onur Atam
Follow:
The author, who is an attorney, specializes primarily in Information Technology Law and Commercial Law. His areas of interest include internet technologies, the cryptocurrency ecosystem, blockchain applications, and next-generation financial technologies.He closely follows developments in digital assets, cryptocurrency regulations, fintech applications, e-commerce, data security, and areas where technology intersects with the law. His goal is to provide a clear and accessible analysis of current developments in the fields of cryptocurrency and financial technologies from a legal perspective.
Previous Article Uniswap rises 9%, reclaims support as UNI volume and V4 adoption climb
Next Article AVAX repeats bullish breakout, YourGrails expands real-world asset use
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

AVAX repeats bullish breakout, YourGrails expands real-world asset use
Avalanche (AVAX)
Uniswap rises 9%, reclaims support as UNI volume and V4 adoption climb
Uniswap (UNI)
Wintermute reports 72% of OTC crypto spot flow from institutions in H1 2026
Cryptocurrency News
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?