Recent activity around Coldcard's hardware wallet has revived concerns about the security of seed generation.
Galaxy Research, a research arm of Galaxy Digital, estimates that the third wave of attacks related to Coldcard generated addresses has resulted in the loss of a total of 1367 bitcoins (approximately US$88.6 million) from 4585 addresses. At the same time, on-chain data shows that small bitcoin holders are rapidly turning to exchanges or other custody channels. Julio Moreno, head of research at CryptoQuant, said that transfers of less than 1 bitcoin reached the highest single-day level since 2022 last Friday, with a total of 39600 bitcoins transferred-only 300 fewer than the 39900 bitcoins recorded shortly after FTX filed for bankruptcy on November 16, 2022. [TAG
Key Points
Galaxy Research estimates that Coldcard-related weekend losses have spread to 4585 addresses, totaling 1367 bitcoins. CryptoQuant's data showed that transfers of less than 1 bitcoin soared to their highest single-day level since 2022, suggesting that small users are quickly reallocating funds. Galaxy Digital's Alex Thorne said the attacks continued and urged users to immediately transfer funds from affected Coldcard generation addresses. The flaw in the report relates to a flaw in Coldcard's seed generation process, which allegedly does not rely on a "truly random" number generator.
Coldcard security incidents affect user behavior
The Coldcard incident is eye-catching not only because of the scale of its estimated losses, but also because it quickly changed users 'behavior on the chain. Following reports of stolen funds, many holders appear to be reducing their exposure to the infected wallet ecosystem and moving to more liquid platforms. Moreno put this trend into a broader pattern in his observations on CryptoQuant: On Friday, transfers of less than 1 bitcoin soared to 39600 bitcoins, reaching its highest single-day level since 2022. While the reasons for transferring bitcoins below 1 can be varied, changes of this magnitude are consistent with panic-driven fund consolidation behavior-especially among small holders who may prefer a centralized exchange because of its faster speed or believe that certain services are better resistant to the specific failure patterns described in the Coldcard case.
Galaxy Research tracks weekend loss range
In an update on Saturday, Galaxy Research said the third wave of attacks had pushed estimated losses to 1367 bitcoins, spread across 4585 addresses. Previous reports have cited similar on-chain extraction patterns in previous waves of attacks, further confirming that the incident did not stop after the first report. Alex Thorne, head of company-wide research at Galaxy Digital, warned on the X platform on Sunday that the attack was continuing. He urged all users who had not yet transferred funds to immediately remove them from the addresses generated by Coldcard. For investors and traders, the implications are straightforward: loopholes in custody can translate into sudden changes in market liquidity, forced selling decisions, and higher operational risks-which not only affect large traders, but also the vast number of users with relatively small balances.
Technical causes behind the vulnerability
Thorne's warning focuses on the technical root cause described in this security incident: a pointed weakness in the Coldcard seed generation process. Concerns raised in the report were that the process did not use a "truly random" number generator. This distinction is critical to security analysis. The seed generation flaw is particularly damaging because it affects how private keys are generated. Unlike purely software-level vulnerabilities, which may be patched through the wallet interface, seed generation issues can affect the certainty of wallet recovery-meaning an attacker may be able to copy or narrow down the range of keys used by affected devices.
Investors should pay attention to custody risks in the course of events
Coldcard-related incidents highlight a larger dynamic in crypto risk management: When an event occurs, immediate follow-up reactions on the chain often reveal more about users 'true priorities than public statements. On the one hand, multiple address losses and on the other, an increase in transfer activity, especially small transfers-a combination that suggests users are quickly deciding where to place their funds next. The practical lesson for anyone who holds Bitcoin protected by hardware-generated addresses is to treat escrow updates as a time sensitive matter. Even if trading in the broader market is calm, custody failures can lead to localized surges in withdrawal and consumption activity, with a ripple effect through liquidity and exchange capital flows. Looking forward, readers should pay attention to whether the total estimated loss continues to rise and whether the on-chain transfer pattern remains high after the initial response window-signals that can help determine whether the worst has really passed or whether there are still more affected addresses that are becoming targets.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC