EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Coldcard hacked, small bitcoin transfers soared to highest level since FTX crash

2026-08-03 00:50:42
Bookmark

Bitcoin holders transferred nearly 40,000 small BTC in a single day, the largest since 2022.

Last Friday, Bitcoin holders transferred 39,600 bitcoins through a single transaction less than 1 BTC, setting a record for a small single day transfer since November 2022. Julio Moreno, director of research at CryptoQuant, pointed to the data on Saturday and directly linked it to a self-managed attack that has continued to affect Coldcard's hardware wallet since July 30.

This figure is only 300 less than the 39,900 BTC on November 16, 2022 (a few days after FTX filed for bankruptcy). Moreno said that this was a signal that "Bitcoin civilians" were taking action to protect their assets, and it was the first time that such a large-scale transfer of small wallets had occurred since the exchange collapse that changed the industry's concept of custody.

The reason for the migration wave

The surge can be traced to a firmware vulnerability in Coldcard, a bitcoin-specific hardware wallet produced by Canadian company Coinkite. On July 30, an attacker stole approximately 594 BTC (worth approximately $38 million) from approximately 500 wallets in 25 minutes. The attacker never came into contact with physical equipment.

The root cause lies in a random number generator vulnerability introduced in March 2021. Coldcard firmware should have disabled MicroPython's built-in random number source and used its own hardware generator instead. But the directive failed to take effect on some devices due to a checking flaw in a supporting code base. The resulting seed phrase is not a real random number, but predictable and guessable data.

An attacker can reconstruct candidate seeds on an ordinary computer, deduce the address corresponding to each seed, and match it with the Bitcoin public blockchain. The entire process requires no malware, phishing attacks or physical contact. Affected are wallets created on Mk3 firmware versions between 2021 and 2026, many of which were left untouched for years until they were swept away.

Losses continued to climb over the course of a week

The original estimate of 594 BTC was quickly refreshed. Galaxy Research, a research arm owned by Galaxy Digital, traced the second wave of attacks on July 31, pushing total losses to 1,082.65 BTC (involving 1,196 addresses), worth approximately $70 million. After the third wave of attacks on the same day, the damage increased to 2,673 addresses totaling 1,158.66 BTC.

As of August 1, Galaxy's tracking data has reached approximately 1,367 BTC (approximately US$88.6 million), involving 4,585 addresses. Alex Thorne, head of research for Galaxy company-wide, said on Sunday that the attack was still underway and urged all those holding funds at addresses generated by Coldcard to transfer assets immediately.

Coinkite released an emergency firmware update on July 31 covering Mk3, Mk4, Mk5 and Q devices. However, updating the firmware cannot fix seeds that have been generated under the defective code. Affected people must generate new seeds on the patched firmware and transfer funds to new addresses-which is why the volume of transfers tracked by CryptoQuant has surged.

Why pass phrases protect

Wallets protected using a BIP-39 passphrase (extra words or phrases superimposed on top of a standard seed) mostly survive theft. The passphrase changes the way the final key is derived, making it impossible for an attacker to reproduce his guesses based solely on public chip data. Security researchers point out that this is the clearest practical defense measure that came into play in this incident.

Blockaid, a blockchain security company, pointed out that most of the cryptocurrency losses in the first half of 2026 were due to key leaks and operational errors, rather than smart contract vulnerabilities. Its CEO Ido Ben-Natan said the Coldcard incident fits this pattern: the vulnerability occurs during the key generation phase of the wallet, and users cannot verify that step themselves.

Self-custody debate resurfaces

This incident has reignited the debate about whether it is safer to hold the key yourself than to trust a third party. Casa CEO Nick Neumann refuted the idea that "self-custody failed" and estimated that the amount of bitcoins safely held in self-custody was about ten times the amount stolen.

Eric Balchunas, senior ETF analyst at Bloomberg, believes that spot Bitcoin ETFs provide a more practical option for many holders, and points to the operating record of the ETF industry. Others in the community countered that the vulnerability targeted specific hardware wallet manufacturers and was not a failure of the self-managed model itself. Some analysts expect the incident to prompt cautious holders to switch to regulated custodians and ETFs, at least in the short term.

Future Outlook

The Coldcard vulnerability is the third major known case of its kind, following the 2023 "Milk Sad" random number vulnerability and the 2026 mobile wallet vulnerability "Ill Bloom". Each vulnerability appears in the same stage: wallet creation, which users cannot independently audit.

The practical lesson for Bitcoin holders is not that self-custody failed, but that the source of wallet nonce is as important as keeping the device offline. No matter how secure a physical device is, seeds generated by weak entropy are at risk. The current wave of transfers below 1 BTC is a practical move for users to learn this lesson and migrate funds to seeds generated by patched firmware while the attack window is still open.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP