Small transfers in Bitcoin surged, on the same scale as during the FTX crash.
Bitcoin experienced a surge in very small transfers (single transactions less than 1 BTC), with an intensity similar to the last wave during the FTX crash. The activity coincides with researchers continuing to track a suspected Coldcard-related hacker incident, highlighting the speed with which users respond to suspected damage to self-managed tools.
According to Julio Moreno, director of research at CryptoQuant, transfers of less than 1 BTC last Friday hit a single-day record since November 2022, with a total of 39,600 BTC transferred. This figure is only 300 BTC less than the 39,900 BTC figure on November 16, 2022 (shortly after FTX filed for bankruptcy). Moreno viewed the comparison as an urgent sign and said users appeared to be "taking action."
Key Daily Data
According to CryptoQuant's Julio Moreno data, the amount of Bitcoin transfers less than 1 BTC in a single day reached the highest level since November 2022, totaling 39,600 BTC.
Galaxy Research said that after identifying an additional 207.7 BTC stolen in another round of attacks, the suspected Coldcard incident has caused damage to an estimated 1,367 BTC, involving 4,585 addresses.
Galaxy's Alex Thorn warned that the attack was continuing and urged affected users to immediately transfer funds from addresses generated by Coldcard.
The incident has reignited debate about whether self-hosting is safer than relying on third-party platforms, with executives believing the impact will vary depending on the user's approach.
The surge in small transfers is similar to the post-FTX scenario
While large-scale market fluctuations often dominate the headlines, current data focuses on behavior at the daily wallet operation level: transfers of less than 1 BTC. Moreno's analysis suggests that the market is experiencing levels of small withdrawals not seen since FTX filed for bankruptcy.
This comparison is important because it points to a user's reflexive behavior-transferring funds in small increments-rather than a single, coordinated "whale" action. After the FTX incident, exchange-related uncertainty prompted users to take faster and more defensive actions. This time, the catalyst is different: ongoing concerns related to the addresses generated by Coldcard.
Moreno observed that daily transfers of this magnitude have not occurred since the FTX crash, suggesting that the Coldcard incident may be triggering a similar level of immediate risk. This does not prove equivalence in scale or cause, but it does suggest that even if the underlying events are different, user reactions may look similar.
Galaxy Research details new wave of theft
Galaxy Research, a unit of Galaxy Digital, reported on Saturday that it had identified another round of attacks linked to suspected Coldcard hacking. In this round, as many as 207.7 BTC was withdrawn-worth approximately $13.2 million at the price quoted by Galaxy at the time.
Including newly identified activity, Galaxy estimated the total loss at 1,367 BTC, affecting 4,585 addresses. Galaxy's report suggests that the incident was not a single moment of exploitation, but an ongoing process, with both victim and attacker infrastructure emerging as investigators continue to improve their tracking.
The "ongoing" warning prompted users to immediately withdraw cash.
Alex Thorn, head of company-wide research at Galaxy Digital, said in a platform X post on Sunday that the attack was still active. Thorn urges users to immediately transfer funds from addresses generated by Coldcard if they have not yet done so.
Thorn added that his team is still constantly identifying new victim and attacker addresses. He also pointed out that user reports have helped investigators and authorities track stolen funds, reinforcing a practical lesson: In incidents where on-chain patterns are evolving, information provided by users can speed up investigations.
This warning also reminds people that self-custody is not only about holding assets, but also about operational readiness. When wallet-generated addresses are involved,"reaction time" becomes part of the security model-whether or not users follow best practices.
Self-custody debate resurfaces: commentators debate "failure" versus "risk control"
The suspected Coldcard hack once again led discussions to a long-standing divergence in cryptocurrency security: self-custody versus third-party custody. Self-custody is a basic principle of Bitcoin, emphasizing user control rather than relying on intermediaries. However, security incidents involving consumer-grade tools can complicate this narrative and raise new questions about usability and security.
Nick Neuman, CEO of Bitcoin security company Casa, refuted the claim that "self-custody is over." He believes that because self-hosting is distributed, users have time to respond after threats are identified. Neuman estimates that in this attack, the amount of bitcoins protected through self-custody may be 10 times the amount stolen and identified.
This position redefines the debate from "whether an event is likely to occur" to "how the system responds once the risk becomes visible." In Neuman's view, the continued presence of victims does not negate the defensive advantages self-hosting can provide-especially if users monitor, verify and act on warnings.
Others view this issue from a different perspective. Eric Balchunas, senior ETF analyst at Bloomberg, said via Platform X that Bitcoin exchange-traded funds (ETFs) may provide a safer and more convenient alternative to many users, noting that ETFs have a longer operating history.
In contrast, critics of this view say the Coldcard incident reflects the failure of a specific wallet provider or implementation, rather than a fundamental collapse of self-hosting itself. Readers need to be aware of the tensions: "Self-custody" is not a single technology, but a set of practices and tools, so events can be interpreted as systematic or local, depending on what the reader believes went wrong.
What to focus on next
Given that Galaxy says attacks are still underway and continues to identify new victim and attacker addresses, the next key signal will be whether transfer patterns and wallet-specific metrics stabilize as users move funds. The bigger question for investors and builders is how quickly the broader community can verify affected addresses and coordinate the response-because in this case, speed itself is part of the safety outcome.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC