y created wallets. KARR BLUETOOTH FLAW EXPOSES 2.2M CARS TO THEFT RISK However, the company warned that simply installing the update will not protect people who already created a recovery phrase using the affected software. Instead, Coinkite is urging those users to create a brand-new recovery phrase using the updated software and move their bitcoin into the newly secured wallet. Updating the firmware does not repair a seed that was generated by affected firmware, the company said in a security advisory. A new seed must be generated and the funds migrated to the new wallet. Coinkite also warned that moving the same recovery phrase into another wallet does not solve the problem because the weakness follows the recovery phrase itself, not the physical device. Coinkite CEO Rodolfo Novak issued a public apology on X, saying the company was heartbroken and taking full accountability for the firmware bug. I'm sorry and I'm devastated, Novak wrote. Our team is heartbroken about yesterday's news. Novak urged customers to act immediately. If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further, he wrote. He also asked the public to help spread the warning. If you know anyone who owns a Coldcard, please make sure they see this, Novak wrote. Some affected users may not be watching social media right now, and every hour matters. Novak said Coinkite is still working to determine exactly how many people may have been affected and plans to publish a detailed explanation of what went wrong after its investigation is complete. We do not have full attribution or scope of the issue yet, and we won't speculate until our full technical evaluation is complete, Novak wrote. The company said it will also help affected customers who want to file police reports or insurance claims and is cooperating with blockchain investigators and law enforcement agencies. The warning quickly spread across the cryptocurrency industry. If you're using a COLDCARD, any version firmware or MK, migrate your funds immediately, Jan3 CEO Samson Mow wrote on X. If you know someone who is, let them know ASAP... Attacks are ongoing so do it quickly. While the initial warning focused on older Coldcard devices, Coinkite has since expanded the list of affected products to include additional models and software versions. The company also said customers who created their recovery phrase using at least 50 private dice rolls are not affected by this specific flaw alone. However, Coinkite recommends that anyone who is unsure how their wallet was set up create a new recovery phrase and move their funds as a precaution. Block emphasized that none of its own products or customers are affected by the vulnerability. The company said it published its findings after working with anonymous security researchers and receiving reports from Coldcard users. Separately, developers of Jack Dorsey's Bitkey wallet said they are investigating a different reported issue involving their product but are not advising customers to stop using the wallet. Our recommendation is to continue to use your Bitkey normally, Bitkey developer Clay Garrett wrote on X. Garrett said the reported issue would require exceptional circumstances to exploit and would not give an attacker enough information to steal customers' funds. Our assessment is this presents no risk of remote drains or immediate funds loss, Garrett wrote. FOX Business reached out to Coinkite, Galaxy Research, Block, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI , the Royal Canadian Mounted Police (RCMP), the Canadian Centre for Cyber Security and Chainalysis for comment but did not immediately receive a response. Find more updates on this story at FOXBusiness.com.