A sudden wave of Bitcoin holders rushed to move their funds after the disclosure of a critical vulnerability in Coinkite’s Coldcard hardware wallets, pushing activity among smaller holders to levels not seen since the collapse of FTX, according to new on-chain analysis that suggests the industry’s latest security crisis has shaken confidence in one of its most trusted self-custody devices.
- Coinkite's Coldcard hardware wallets suffer a critical firmware vulnerability that allows attackers to reconstruct recovery seeds without physical device access.
- Daily active Bitcoin addresses surged to one million on July 31 as small holders moved thirty-nine thousand six hundred BTC.
- Shaken confidence in premium self-custody triggers the largest retail migration since the FTX collapse, forcing long-term holders toward centralized exchanges.
The surge followed the exploitation of a firmware flaw that allowed attackers to reconstruct recovery seeds generated by vulnerable Coldcard devices and steal Bitcoin without requiring physical access to the wallets. Researchers say the incident triggered one of the largest precautionary migrations of coins in recent years as users scrambled to secure their holdings before additional wallets could be compromised.
On-Chain Activity Reaches FTX-Era Levels
According to a report published by blockchain analytics firm CryptoQuant, daily active Bitcoin addresses climbed from about 645,000 on July 30 to nearly one million on July 31, marking the highest level since December 2024.
The increase came almost entirely from addresses sending Bitcoin rather than receiving it, suggesting existing holders were moving funds instead of new participants entering the network.
CryptoQuant found transfers involving wallets holding less than 1 BTC reached approximately 39,600 BTC on July 31. That was just below the 39,900 BTC moved by similar-sized holders following the collapse of FTX in November 2022.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseMeasured by value, transfers below $100,000 totaled roughly $3.2 billion, the largest daily figure since November 2024.
Julio Moreno, CryptoQuant’s head of research, said the movement appeared to reflect widespread efforts by users to secure their assets rather than normal trading activity.
“If there’s a silver lining to this whole Coldcard hack mess, it’s that the awareness raised by so many people urging others to move their funds seems to be working,” Moreno wrote on X.
He added that on-chain indicators, including active addresses, transfers from small holders, exchange inflows and mempool transactions, all pointed to a broad migration of Bitcoin as holders attempted to move funds to safety.
Moreno cautioned that blockchain data cannot determine how much Bitcoin remains exposed to the vulnerability.
Firmware Vulnerability Triggered Multi-Wave Theft
The migration followed the disclosure of a serious firmware vulnerability affecting multiple generations of Coldcard hardware wallets manufactured by Coinkite.
Security researchers said the flaw reduced the randomness used to generate wallet recovery seeds, allowing attackers to reconstruct private keys offline for affected devices.
The first large wave of thefts began around July 30, when attackers rapidly drained more than 1,000 BTC before additional wallets were targeted in subsequent waves.
Industry estimates of total losses have continued to rise as investigators identified more compromised wallets. Independent research firms including Galaxy Research have estimated losses exceeding $100 million, although the final figure remains uncertain.
Coinkite has since released emergency firmware updates and advised affected customers to generate entirely new recovery seeds on patched devices before transferring any remaining funds.
Long-Term Holders Also Joined the Exodus
CryptoQuant’s data showed the migration extended beyond retail traders.
The firm’s measure of long-term holder spending by non-exchange wallets rose to approximately 406,000 BTC on a rolling 30-day basis by August 3, up sharply from about 269,000 BTC only four days earlier. The reading reached its highest level since January.
That increase is notable because Coldcard wallets are widely used by long-term Bitcoin holders who prioritize offline storage over frequent trading.
Part of the movement also flowed toward centralized exchanges.
Deposits from wallets holding less than 1 BTC climbed to their highest level since February, suggesting some users temporarily preferred custodial platforms over purchasing replacement hardware wallets while securing their funds.
The Bitcoin network itself reflected the sudden rush.
CryptoQuant reported transactions waiting in the mempool increased from roughly 33,000 to about 96,000, the highest level since June, as thousands of users attempted to move coins over a short period.
Self-Custody Confidence Faces Rare Test
The Coldcard incident differs from previous market shocks because it did not originate from a failed exchange, stablecoin or lending platform.
Instead, the trigger was a vulnerability in a hardware wallet long regarded as one of Bitcoin’s most security-focused storage devices.
The scale of the on-chain response suggests many holders viewed immediate migration as the safest option despite the additional transaction costs and network congestion.
CryptoQuant said the activity illustrated how quickly confidence in self-custody infrastructure can shift when vulnerabilities emerge, even among users who typically move coins infrequently.
While the data indicates broad awareness of the issue, the firm said blockchain analysis cannot determine how many vulnerable wallets remain active or how much Bitcoin may still be at risk.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





