Updated Aug 4, 2026, 12:12 p.m. Published Aug 4, 2026, 12:00 p.m. 2 min readColdcard wallet Mk4. (Coinkite)SummaryThe developers of the Coldcard bitcoin wallet urged users to move their funds amid an exploit that has already drained as much as $114 million from self-custodied wallets.The vulnerability affects certain Mk3 devices set up on firmware 4.0.1 or later and Mk4, Mk5 and Q devices on older firmware. Wallets created using the dice-roll option are considered safe.The flaw, dormant in firmware since 2021, allows attackers to guess poorly randomized seed keys and drain funds, even as bitcoin’s price has remained near $63,800 despite the warning.The developers behind the Coldcard wallet told users to urgently move their bitcoin BTC$63,756.04, confirming Tuesday that the exploit — which has drained as much as $114 million from self-custodied wallets — is still in progress."Please treat this as urgent. Migrate your funds," the company wrote, adding that the threat is active and asking users to warn holders who are "less online" and may not have seen the alert. Those are the wallets most exposed, since the fix has to be done by hand.Please treat this as urgent. Migrate your funds. Follow the advisory for your model, upgrade your device, generate a new seed, and carefully move your funds.Help spread the word, especially to people who are less online and may not see this update.The threat is still ongoing. https://t.co/cbJxJles8x— COLDCARD (@COLDCARDwallet) August 4, 2026