🔥BTC/USDT

New Bitcoin addresses rise after Coldcard exploit

A sharp rise in new Bitcoin addresses has coincided with an urgent migration by affected Coldcard users after a long-standing firmware flaw exposed some wallets to offline brute-force attacks. The number of new addresses climbed from roughly 260,000 to more than 330,000 last week, ending a decline that had persisted through much of 2026, as users moved coins away from potentially compromised wallet seeds.

Coinkite hardware wallet users have lost at least 1,816 BTC, valued at about $116 million at prevailing market prices, across four reported theft waves since July 30. The incidents have been linked to a 2021 Coldcard firmware issue that generated wallet recovery seeds with a weak software-based random number generator instead of drawing sufficient randomness from the device’s hardware entropy source.

That defect weakened the unpredictability of affected seeds, which are the sets of words used to recover a Bitcoin wallet. If an attacker can narrow the range of possible seeds enough, they can attempt to recreate wallets offline and check whether any contain funds. The attack does not require physical possession of a Coldcard device, access to a user’s backup words, or a connection to the wallet itself.

Coinkite urges users to create entirely new wallets

Coinkite has advised users who created wallets between March 2021 and the release of the security patch to transfer funds into newly generated wallets. Updating a vulnerable device alone would not secure an old seed, because the weakness occurred when the original wallet was created.

Users need to generate a fresh wallet after updating to firmware version 4.2.0 or later, record the new recovery words securely, and move any remaining Bitcoin from the old wallet to an address controlled by the replacement seed. Reusing the previous seed on updated software would leave the original exposure in place.

The response helps explain why address activity has picked up, though a rise in new addresses cannot establish how many people were directly affected by the Coldcard issue. Bitcoin users may create multiple addresses for privacy, wallet management, exchange withdrawals, or other reasons. In this case, the timing aligns with a security-driven need for holders to separate funds from addresses associated with older wallet generations.

Glassnode recorded more than 890,000 BTC moving between addresses during a seven-day period and described the jump in transfer volume as the largest network spike of the year. Large movement totals do not necessarily represent new buying or selling: coins can move between addresses owned by the same person or entity. The current episode offers a practical example of how a security event can produce heavy on-chain activity without providing a clear signal about market direction.

Offline storage cannot fix flawed key generation

The Coldcard incident has brought renewed scrutiny to a less visible part of self-custody: how a wallet creates the cryptographic secret behind a recovery phrase. Hardware wallets are designed to keep private keys isolated from internet-connected computers, reducing exposure to malware and remote theft. Their security also depends on the software and randomness used during initial setup.

A random number generator is central to that process. Strong randomness makes a wallet seed effectively impossible to guess. Weak randomness can reduce the number of possible combinations far enough for attackers to search for vulnerable wallets with specialized computing resources. The resulting risk exists before a device is ever stored offline or placed in a secure location.

The case places particular weight on wallet provenance. A user can follow familiar self-custody practices—buying a hardware device, protecting the recovery phrase and keeping the wallet disconnected—while remaining exposed if the seed was generated by flawed firmware. The practical lesson is more specific than a general warning about hardware wallets: users need to know when their wallet was initialized, which firmware it used, and whether the provider has issued seed-generation security notices.

Custody choice involves different risks

The thefts have also renewed comparisons between direct self-custody and products that place custody with a regulated financial intermediary, including spot Bitcoin funds. Those structures remove the need for an individual holder to manage recovery phrases, firmware versions, device backups and inheritance arrangements. They also leave the holder with shares or an account claim rather than direct control of Bitcoin held on-chain.

That trade-off is central to the current debate. Self-custody gives users direct control of their assets and avoids reliance on a custodian’s operational controls, withdrawal policies or counterparty stability. It also places the technical burden of key generation and backup security on the user. Fund structures and custodial accounts can reduce certain operational mistakes while introducing fees, intermediary dependence and limited ability to use the underlying Bitcoin for on-chain transactions.

The reported Coldcard losses do not establish that one custody model is universally safer than another. They show that hardware isolation is only one layer in a security system. A wallet’s seed-generation process, firmware history, recovery procedures and user response to vulnerability notices can determine whether offline storage provides its intended protection.

For users with Coldcards created during the affected period, the immediate issue is not whether to retain self-custody, but whether their Bitcoin remains tied to an exposed seed. Moving funds to a newly created wallet generated on patched firmware removes the coins from addresses that attackers may be attempting to reproduce.


Concerned about wallet exploits? Strengthen your security setup and learn safer custody options in this detailed guide today.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

Sign up and trade to earn over 15,000 USDT
Sign up