Coldcard Users Urged to File Reports After Security Incident
Key Takeaways
- •Jack Mallers, CEO of Strike, issued a public advisory urging Coldcard hardware wallet users to report suspicious activity to local authorities.
- •Users were advised to retain all wallet-related documentation, including transaction records and communications, and to share transaction IDs to assist with investigations.
- •Coldcard is manufactured by Toronto-based Coinkite and is widely used for secure Bitcoin storage due to its air-gapped signing design.
- •The advisory has drawn attention from security experts and users, raising concerns about potential vulnerabilities in the hardware wallet ecosystem.
- •The hardware wallet sector has faced recurring security challenges including supply chain attacks, counterfeit devices, and social engineering attempts targeting seed phrases.

Crypto community members have raised concerns about a potential security issue affecting Coldcard hardware wallet users. Jack Mallers, a prominent figure in the cryptocurrency space and CEO of Bitcoin payments platform Strike, issued an advisory via social media urging Coldcard users to take immediate action.
In a post on X (formerly Twitter), Mallers advised users to file reports with their local authorities and to retain all records related to their wallets. He also encouraged affected users to reach out directly with transaction details, including transaction IDs, so that further investigation can take place. The post can be found here: https://x.com/jackmallers/status/2083285799907258850
Details of the Advisory
Mallers stressed the importance of not discarding any documentation or data tied to the wallet, including transaction records and related communications. Users who notice suspicious activity were encouraged to report it promptly and to share transaction identifiers that may assist in any ongoing investigation.
The advisory has drawn attention from both users and security experts within the cryptocurrency community, highlighting what some see as potential vulnerabilities in the hardware wallet ecosystem.
About Coldcard
Coldcard, manufactured by Toronto-based Coinkite, is a widely used hardware wallet designed for secure Bitcoin storage. It is particularly popular among Bitcoin users for its air-gapped design, which allows signing transactions without a direct internet or USB connection to a computer. As a prominent product in the hardware wallet market alongside competitors such as Ledger and Trezor, any security concerns involving Coldcard have the potential to affect a significant number of users and to influence broader confidence in hardware-based crypto storage solutions.
Broader Context
Hardware wallets have become an increasingly common target for threats as the cryptocurrency landscape continues to evolve. While these devices are generally marketed as one of the most secure methods for storing digital assets, incidents such as this underscore the importance of remaining vigilant. The hardware wallet sector has seen repeated security challenges over the years, including supply chain attacks, counterfeit device distribution, and social engineering attempts aimed at extracting seed phrases from users. These episodes have periodically tested user trust in self-custody solutions even as adoption of hardware wallets has grown.
Mallers' advisory serves as a reminder that even hardware-based solutions require careful attention to security practices. Users are encouraged to stay informed about any updates from wallet manufacturers and to monitor community discussions for emerging information.
Users who believe they may be affected should retain all relevant records, file reports with appropriate authorities, and follow any further guidance issued by Coldcard or community members involved in investigating the matter.