Losses linked to a security flaw in Coldcard Bitcoin hardware wallets have climbed to $88 million as attackers continue siphoning funds from compromised devices. The breach targets Coldcard wallets, produced by Coinkite, and represents one of the largest self-custody wallet security incidents this year.

The vulnerability stems from how wallet seeds were generated on specific Coldcard Mk3 devices. This flaw allowed hackers to systematically drain user wallets created under these insecure conditions. Coinkite issued a warning and detailed the issue in a technical report that explains the risk tied to compromised seed generation. This is not a single hack event but an ongoing exploitation of affected seed-generated wallets.

Because the problem lies deep in the wallet’s seed creation, all assets stored in these vulnerable wallets face risk. The total $88 million figure accounts for funds that attackers have already moved, showing the exploit’s severity beyond routine firmware advisories. The incident severely undermines user confidence in self-custody solutions considered secure by Bitcoin holders.

For more context on self-custody risks and wallet security, see Firmware Bug Exposes Coldcard Wallets to Massive Bitcoin Thefts.

This information is for educational purposes and does not constitute financial advice.