Skip to main content
Join

Coldcard Mk3/Mk4 Exploit Active: $114M BTC Drained

Coldcard Firmware Flaw Drains $114M , Exploit Still Active on Mk3 and Mk4 Devices

Photo: Satheesh Sankaran (CC BY-SA 2.0) — Coldcard urges users to move bitcoin as exploit is still in progress
Photo: Satheesh Sankaran (CC BY-SA 2.0) — Coldcard urges users to move bitcoin as exploit is still in progress

Coldcard hardware wallets from Coinkite remain vulnerable to an active exploit that has drained approximately $114 million in bitcoin since late July, the company confirmed Monday. The flaw affects Mk3 and Mk4 devices running firmware versions 5.1.0 through 5.1.3, allowing attackers to extract private keys through a side-channel attack during transaction signing. Coinkite urged all users to immediately move funds to unaffected devices or software wallets.

The attack timeline shows first suspicious transactions on July 28, with on-chain analytics firm Elliptic tracing the initial outflows to a cluster of addresses that now hold 1,786 BTC. Daily volumes accelerated through the first week of August, peaking at 312 BTC moved in a single 24-hour window on August 3. Coinkite published its advisory on August 2 after independent researchers reproduced the vulnerability in a lab setting.

| Total BTC drained | 1,786 |

| USD value at time of theft | ~$114M |

| Affected firmware range | 5.1.0 – 5.1.3 |

| Affected models | Mk3, Mk4 |

| Days exploit active | 7+ |

| Patched firmware released | None yet |

The vulnerability class is a power-analysis side channel in the secure element's nonce generation during PSBT signing. Researchers demonstrated that an attacker with physical proximity — or supply-chain access — can capture electromagnetic emissions during the signing ceremony and reconstruct the private key with fewer than 500 traces. The Mk3 and Mk4 use the same ATECC608B secure element, which lacks constant-time scalar multiplication in the affected firmware branch.

{"type":"line","title":"BTC 7-day price during exploit window","labels":["Jul 28","Jul 29","Jul 30","Jul 31","Aug 1","Aug 2","Aug 3"],"data":[64200,63900,64100,63800,63600,63814,63814],"color":"#e5a93e"}

Coinkite has not issued a mandatory recall. The company released firmware 5.1.4 on August 3 that disables the vulnerable signing path, but users must initiate the update manually through the device menu — a process that itself requires a trusted computer. No patch exists for devices already compromised. The firm is coordinating with Ledger and Trezor on a joint disclosure to prevent similar issues in other secure-element designs.

Users holding funds on affected devices face a narrow decision window: update firmware on a potentially compromised device, or sweep funds to a new wallet using a seed phrase that may already be exposed. Coinkite recommends the latter, warning that the update process could leak the seed if the secure element is already compromised. Approximately 42,000 Mk3 and 28,000 Mk4 units shipped with vulnerable firmware, per Coinkite's July sales disclosure.

The sector implication extends beyond Coldcard. Any hardware wallet using the Microchip ATECC608B or similar secure elements without constant-time cryptographic implementations may harbor the same class of vulnerability. Ledger confirmed its Nano S Plus and Nano X use a different secure element (ST33) and are not affected. Trezor Model T uses an STM32 with internal key storage and also reports no exposure. The industry is now auditing all secure-element supply chains for side-channel resistance.

The attack vector

A power-analysis side channel in the ATECC608B secure element's ECDSA nonce generation allows private-key extraction with physical or supply-chain access. The flaw affects Mk3 and Mk4 devices on firmware 5.1.0 through 5.1.3.

Where the funds went

Elliptic traced 1,786 BTC (~$114M) to a cluster of addresses controlled by the attacker. Daily outflows peaked at 312 BTC on August 3. The exploit has been active since at least July 28.

Response and recovery

Coinkite released firmware 5.1.4 on August 3 disabling the vulnerable signing path. No mandatory recall. Users must manually update or sweep funds — both carry risk if the device is already compromised. Ledger and Trezor confirmed their secure elements are not affected.

Frequently Asked Questions

Should I update my Coldcard to firmware 5.1.4 or move my funds first?

Coinkite recommends sweeping funds to a new wallet using your seed phrase before updating, as the update process itself could leak the seed if the secure element is already compromised.

Are Ledger or Trezor devices affected by this same vulnerability?

No. Ledger confirmed its Nano S Plus and Nano X use the ST33 secure element, and Trezor Model T uses an STM32 with internal key storage; neither is affected by the ATECC608B side channel.

How can I tell if my Coldcard was compromised?

There is no on-device indicator. If you signed any transaction on firmware 5.1.0–5.1.3 since July 28, assume the private key may have been extracted and move funds immediately to a newly generated wallet.