A significant exploit affecting Coldcard hardware wallets has resulted in the theft of at least 1,596 Bitcoin (BTC), valued at approximately $130 million, prompting a wave of fund movements across the Bitcoin network and reigniting discussions about the security of digital asset custody. The breach, stemming from a flaw in Coldcard’s firmware dating back to March 2021, has compromised the private keys of an estimated 7,300 addresses, forcing users to rapidly transfer their holdings to more secure locations.
The exploitation of this vulnerability has been meticulously documented by Galaxy Research, which identified three major attack waves and fourteen smaller incidents contributing to the confirmed losses. The firm has also flagged a potential fourth wave that could elevate the total stolen Bitcoin to 2,055 BTC, though these addresses are pending further victim reports before being officially added to the confirmed loss estimate. Alex Thorn, Head of Research at Galaxy, has been inundated with requests for assistance from at least 73 victims seeking to trace their stolen funds. These reports have been instrumental in identifying emerging attack patterns and suggesting the involvement of at least 15 distinct attackers exploiting the vulnerability.
A striking aspect of the ongoing crisis is that approximately 90% of the stolen Bitcoin has remained unmoved by the attackers. Crucially, all coins associated with the initial three confirmed waves of attacks are still held at the addresses controlled by the perpetrators. Galaxy Research has proactively shared the identified addresses with U.S. law enforcement agencies, cryptocurrency exchanges, and blockchain investigation firms, enabling them to flag any attempts by the attackers to move the funds through centralized platforms.
The Technical Flaw: A Weakness in Randomness

At the heart of the Coldcard crisis lies a subtle yet critical coding error within the device’s firmware. This flaw, present since March 2021, led to certain Coldcard units generating recovery seeds through a less robust software process. Instead of drawing sufficient randomness from the hardware’s dedicated random-number generator, the flawed process resulted in seeds with a significantly reduced number of possible combinations. This weakness allowed sophisticated attackers to remotely reconstruct the private keys associated with these compromised seeds without ever physically possessing the hardware wallet or obtaining the owner’s recovery words.
While Coldcard manufacturer Coinkite has issued a security update to prevent the generation of new weak seeds, this patch offers no protection to wallets whose recovery phrases were already generated using the flawed process. Coinkite has strongly urged users to install the update, create entirely new seeds, and migrate their Bitcoin holdings. The threat remains active for any affected wallet until its funds are transferred to an address derived from a securely generated seed.
On-Chain Activity Surges: A Network Under Strain
The urgency to secure funds has demonstrably impacted the broader Bitcoin network, driving on-chain activity to levels not seen in months, comparable to periods of significant market stress. Data from Santiment reveals a surge in active Bitcoin addresses, exceeding 712,000 over the past seven days, marking a three-month high. Concurrently, transactions valued at over $100,000 have reached 61,800 in the same period, the highest figure in five months.
CryptoQuant, a leading blockchain analytics firm, has identified the Coldcard crisis as the primary catalyst for this heightened network activity. Their analysis indicates that affected users are actively moving their coins into newly generated wallets, consolidating their balances, or, in some cases, transferring funds to custodial platforms. A report shared by CryptoQuant with CryptoSlate highlights that transactions valued below $100,000 have surged to $3.2 billion, a peak not observed since November 2024.

Furthermore, the spending activity of long-term holders outside of exchanges has seen a significant uptick. As of August 3rd, these holders were moving 406,000 BTC on a 30-day rolling basis, a substantial increase from 269,000 BTC prior to the exploit and the highest level recorded since January. It is important to note that these on-chain movements do not necessarily equate to selling. A transfer from a compromised Coldcard address to a newly secured wallet is registered as a "spent" transaction, even if the ownership of the Bitcoin remains with the original user.
The sheer volume of these migration efforts has also led to network congestion. The number of transactions awaiting confirmation in Bitcoin’s mempool, the waiting area for unconfirmed transactions, jumped from approximately 33,000 to around 96,000. This represents the highest level of mempool congestion since June 20th, as thousands of users simultaneously attempted to move their Bitcoin.
Exchange Inflows and the Shadow of Phishing
As users scramble to safeguard their assets, a portion of the migrated Bitcoin has found its way into centralized cryptocurrency exchanges. CryptoQuant data indicates that deposits from smaller holders have reached their highest point since February 6th. This suggests that some users are opting for immediate, albeit custodial, solutions while they assess their next steps, whether that involves setting up a new self-custody wallet or exploring alternative hardware providers.
Between July 28th and August 3rd, total exchange reserves saw an increase of approximately 17,500 BTC, rising from roughly 2.702 million BTC to 2.719 million BTC. Binance, the world’s largest cryptocurrency exchange by trading volume, absorbed a significant portion of this influx, receiving about 51% of the net increase, with its reserves climbing by approximately 9,000 BTC to 659,000 BTC. While these inflows might suggest potential short-term selling pressure due to increased availability for trading, they do not definitively indicate an intent to sell. Many of these deposits could be temporary measures while users secure new hardware and re-establish self-custody.

Simultaneously, the migration process has created a fertile ground for malicious actors. Criminals are actively distributing fraudulent migration instructions and impersonating wallet support teams, preying on the confusion and urgency of affected users. Trezor, a competitor to Coldcard in the hardware wallet market, has issued a public warning about an increase in phishing attempts following the disclosure of the Coldcard flaw.
Trezor strongly advises its users to never share their recovery seeds or enter them into any websites, applications, or forms that are received through unsolicited messages. The company emphasizes that recovery words should only be entered directly on a Trezor device during a legitimate wallet restoration process. They urge users to disregard any migration instructions received via email, direct messages, or phone calls and have confirmed that their devices are not affected by the Coldcard vulnerability.
The challenge facing Coldcard users is multifaceted: they must migrate their Bitcoin before their private keys are compromised, all while navigating a landscape rife with scammers attempting to obtain their recovery words directly. Importing an existing, compromised seed into another device does not rectify the vulnerability. The only secure solution involves generating an entirely new recovery phrase and transferring funds to an address derived from this new, secure seed. This process is more complex than a simple firmware update or a standard wallet restoration. Scammers are exploiting this complexity by directing users to fake applications, requesting recovery words under the guise of security checks, or providing malicious wallet addresses for fund transfers.
ETF Custody Emerges as a Viable Alternative
The widespread movement of Bitcoin to exchanges, coupled with the escalating risks associated with wallet migrations and phishing attacks, has inadvertently strengthened the case for holding Bitcoin through regulated investment products, such as spot Bitcoin Exchange-Traded Funds (ETFs).

Eric Balchunas, a Senior ETF Analyst at Bloomberg Intelligence, has suggested that the Coldcard breach could prompt some investors, including those who have historically favored self-custody and long-term holding, to consider migrating their holdings to spot Bitcoin ETFs. Historically, Bitcoin enthusiasts have been critical of ETFs, arguing that investors surrender control of their underlying coins and private keys, entrusting them instead to institutional custodians.
However, in the current climate, this arrangement may appear more appealing when contrasted with the perceived risks associated with relying on a single hardware wallet manufacturer. ETF issuers and their custodians are typically large, established financial institutions with extensive experience in safeguarding client assets. In contrast, Coldcard is a product of a relatively smaller Canadian company.
While institutional custody does not eliminate the possibility of theft or operational failure, Balchunas posits that a successful attack on an ETF custodian would likely trigger an immediate and comprehensive regulatory investigation. Such an event would necessitate a coordinated response involving the fund manager, the custodian, and law enforcement agencies.
Currently, there is no direct evidence to suggest that Coldcard users have purchased ETF shares as a direct consequence of this exploit. Moreover, the recent increase in exchange deposits might prove to be a temporary phenomenon, with users eventually returning to self-custody once they have established new, secure wallets. Nevertheless, the Coldcard breach has undeniably altered the risk-reward calculation for investors deciding on the optimal method for holding their Bitcoin. Self-custody offers independence from intermediaries but places the full burden of hardware and software security squarely on the user. For those now facing the daunting task of migrating away from compromised seeds while simultaneously evading phishing scams, the institutional framework, once criticized for its perceived centralization, might present a simpler, albeit different, path to security.

