Coldcard Firmware Vulnerability: Renewed Security Alert as Bitcoin Drains Persist
In brief
- Coldcard firmware vulnerability from March 2021 enabled systematic bitcoin drains from thousands of devices
- Mishaboar renewed urgent alert urging all Coldcard users to migrate funds and generate new seed phrases
- Galaxy Research identified three attack waves targeting 4,585 addresses holding 1,367.05 BTC ($88.6M)
- Coldcard released patches and advised users to upgrade firmware and create entirely new seeds
The Alert and Immediate Actions
Mishaboar issued an important alert to crypto holders in a recent X post, directing it at anyone who has ever used a Coldcard device of any kind. The advisory urged immediate fund migration to a new wallet. Critically, Mishaboar advised users never to reuse the Coldcard seed phrase but rather to create an entirely new one on the new wallet.
This isn't a new threat. A vulnerability in a March 2021 Coldcard firmware release allowed attackers to systematically drain bitcoin from thousands of wallets. Coldcard released patches following the discovery, and current firmware versions incorporate fixes for this specific vulnerability. However, the company's response—urging users to upgrade devices, generate new seeds, and move funds—underscores that historical exposure remains a serious concern for anyone who used vulnerable firmware versions before patches were available.
Scale of Historical Losses
Galaxy Research identified three suspected attack waves targeting addresses generated by Coldcard, involving 4,585 addresses and 1,367.05 BTC worth approximately $88.6 million. These losses occurred during the 2021 attack period. The stolen bitcoin had been dormant for an average of 3.18 years before the incident, indicating that attackers drained funds years ago and have not actively moved the stolen coins since then.
This distinction matters. The $88.6 million figure represents historical losses from 2021, not an indication of current active draining of new wallets.
Ongoing Threat Assessment
Alex Thorn, Galaxy Research's head of research, stated that attacks linked to the Coldcard vulnerability are ongoing. The nature of this ongoing activity appears to center on previously compromised addresses rather than new wallets being drained today. Users who upgraded their firmware to patched versions and generated new seeds after the 2021 incident face significantly lower risk than those who continued using vulnerable firmware versions without taking remedial action.
The renewed alert from Mishaboar reflects the persistent nature of the historical threat and the importance of addressing any remaining exposure. For users uncertain whether they used a vulnerable firmware version, migration remains the safest course of action.


