A bug in popular Coldcard hardware wallets lets hackers steal Bitcoin. Around 1000 BTC already stolen. Users must act immediately.
If you store Bitcoin on a Coldcard hardware wallet, you may need to act right now. A serious security flaw has been discovered, and hackers are already using it to steal people's money.
First, some basics. A hardware wallet is a physical device (like a small USB stick) that stores the secret keys to your Bitcoin offline, so hackers can't reach them over the internet. The Coldcard is one popular brand. A seed phrase (or word seed) is a list of secret words that acts like the master password to your crypto — anyone who has it can steal all your coins.
Here's the problem: Coldcard models MK3, MK4, MK5, and Q had a bug in how they created these seed phrases. The device didn't use enough true randomness (called entropy), which means attackers can guess the secret words and drain the wallet — without you clicking anything.
Key facts:
Bottom line: Don't panic, but don't wait. Move your funds to safety, update your device, and warn any friends who own a Coldcard — many people may not even know they're at risk.
This is an AI-generated summary. Read the original article at: https://bitcoinmagazine.com/news/coldcard-security-risk-immediate-action-required