Block’s security team uncovered two major vulnerabilities across several Coldcard hardware wallet models, raising alarms for Bitcoin holders relying on these devices. Users are now advised to transfer their funds promptly to avoid potential losses.

The issues affect Coldcard models Mk2 through Mk5, including Q, by compromising the randomness used during wallet generation. For Mk2 and Mk3, a coding mistake caused predictable values to replace proper hardware-generated entropy. Newer models tried to enhance randomness at boot but a flaw limited this to just 32 bits, making wallets easier to breach. Importing a seed from an affected Coldcard into another wallet does not remove the risk, as the compromised seed remains vulnerable.

Block’s investigation began after reports of remote Bitcoin theft from non-Bitkey wallets surfaced. Although Bitkey products remain unaffected, over 1,000 BTC might be exposed, primarily from single-signature wallets attacked during a roughly one-hour window. Wallets protected by weak 25th-word passphrases and some multisignature setups could also be targeted. Security engineer Clay Garrett noted that at least 695 earlier transactions show the same on-chain signature linked to this vulnerability.

Block disclosed the flaws to Coldcard manufacturer Coinkite privately before going public. Max Guise, a Block engineer, urged users on X to move their funds as safely and quickly as possible. The incident highlights the ongoing risks hardware wallets face even as they aim to enhance security for self-custody Bitcoin users.