Coldcard told users to urgently migrate Bitcoin (BTC) into newly generated wallets as exploit losses exceeded $100 million and some estimates approached $130 million.
Key Points:
- Coldcard said the threat remains active and urged users to upgrade devices, create new seeds and move funds carefully.
- Galaxy Research estimated confirmed losses above $100 million, while some reports placed possible total exposure near $130 million.
- Joe Consorti said blockchain tracking could make much of the stolen Bitcoin difficult for the attacker to spend.
Coldcard Migration Warning
Coldcard posted the warning on X on Aug. 4, telling customers to follow model-specific advisories and treat the problem as urgent. “Please treat this as urgent. Migrate your funds,” the company said, adding that “the threat is still ongoing.”
The alert followed several attack waves that began near the end of July, after users reported missing funds and Coinkite acknowledged a critical weakness in the wallet's code. Updating firmware alone is not enough.
Coldcard said users should install updated software, generate a new seed and carefully transfer their holdings, while asking customers to alert people who may not see the warning. Users must create a fresh seed.
Also Read: BlackRock Brings Ethereum Shares To Its $311B European Cash Platform
Bitcoin Theft Impact
Galaxy Research said confirmed thefts had moved above $100 million, while other estimates suggested the total could approach $130 million as investigators reviewed additional suspicious transfers. More losses may emerge. The final figure remains uncertain.
Consorti said the attacker may face difficulty spending much of the stolen Bitcoin because analysts are tracking the coins across the public blockchain. That visibility does not return funds.
The Coldcard crisis began at the end of July, when users said funds stored on their hardware wallets had disappeared before the team acknowledged the vulnerability.
Loss estimates then climbed from millions of dollars to more than $100 million, while repeated warnings showed that the risk had not yet been contained.
Read Next: OpenAI Answers Apple's Trade Secrets Suit By Publishing Its Own Emails






