🔥BTC/USDT

Bitcoin small transfers hit post FTX high

Bitcoin transactions smaller than 1 BTC reached their highest daily volume since the collapse of FTX, as users reacted to an active suspected Coldcard wallet compromise by moving funds to new addresses. A total of 39,600 BTC was transferred in sub-1 BTC transactions on Friday, according to CryptoQuant research head Julio Moreno, only 300 BTC below the 39,900 BTC recorded on Nov. 16, 2022, shortly after FTX entered bankruptcy.

The burst of smaller transfers coincided with continued tracing of funds allegedly taken through a vulnerability affecting Coldcard-generated wallet addresses. Galaxy Research said Saturday that a newly identified wave of thefts removed another 207.7 BTC, worth roughly $13.2 million at the cited market price.

Galaxy Research estimated total losses at 1,367 BTC, or about $88.6 million, across 4,585 addresses. The figures indicate that the incident has expanded substantially beyond the initial set of compromised wallets identified in late July, while the rising number of addresses suggests the exposure was spread across many users rather than confined to a few large holders.

Thorn said Sunday that researchers were continuing to identify victim and attacker addresses, and urged users to move funds away from affected Coldcard-generated addresses if they had not already done so. The warning reflects the central operational concern for wallet users: moving assets is only protective when funds are sent to a newly generated address created with secure entropy, or randomness, rather than another address that could carry the same weakness.

Small holders move funds as theft tracking continues

Moreno linked Friday’s surge in sub-1 BTC transfers to heightened on-chain activity among smaller Bitcoin holders responding to the incident. The scale of activity resembles the movement seen during periods of acute market stress, though the immediate catalyst in this case appears to be wallet security rather than exchange solvency.

The Nov. 2022 comparison underscores how unusual the transaction count was. Transfers below 1 BTC often increase when retail holders reposition funds, consolidate smaller balances, or react to security alerts. In this case, the pattern is consistent with users testing wallet access, sending funds to replacement storage, and splitting balances across fresh addresses.

The suspected attack first emerged in late July. According to the supplied account, attackers initially took 1,082 BTC from 1,196 victims in 41 minutes on July 30. That speed suggested the attackers had already identified vulnerable private keys before beginning the withdrawals, enabling them to sweep affected addresses in rapid succession rather than probing wallets one by one on the Bitcoin network.

A consolidation address beginning with “bc1qq85v2c9” held about 562 BTC of the allegedly stolen funds, according to the supplied information. Addresses associated with thefts can help researchers follow the movement of funds, though public blockchain tracing does not by itself identify the people controlling those wallets or guarantee that funds will be recovered.

Vulnerability linked to predictable seed generation

The alleged compromise was tied to a software update first released in March 2021, according to the supplied account. The faulty code reportedly caused affected hardware wallets to use a predictable software randomizer when generating wallet seeds, rather than drawing randomness from a physical hardware component.

A seed phrase is the master secret used to derive a wallet’s private keys. If the process that produces it lacks enough unpredictability, an attacker may be able to recreate the seed and take control of addresses generated from it. Hardware wallets are designed to keep private keys offline, but their protection depends on secure seed generation at setup.

The described flaw would therefore affect wallets created under vulnerable firmware conditions, rather than every Bitcoin user or every form of self-custody. Users who received a seed from an affected device could remain exposed even if they later updated the wallet’s software, unless they moved funds to a completely new wallet generated under a secure process.

The supplied report identified version 5.6.0 as an emergency patch and advised users with vulnerable firmware to update their devices or transfer funds to new addresses. Reusing an older seed phrase after installing a patch would not remove the underlying risk if that seed had already been generated predictably.

Galaxy Research’s latest estimate shows that the incident was still developing as additional affected addresses were found. The average amount taken per victim reportedly declined over the preceding three days, a pattern that may indicate the attackers were reaching smaller balances after quickly sweeping larger, more easily identified wallets.

Custody debate follows a wallet-provider failure

The losses have revived debate over how Bitcoin holders should store assets, particularly whether users should rely on self-custody or third-party custodians. The evidence described in the incident points to a weakness in one wallet-generation process, rather than a failure of Bitcoin’s underlying network or of self-custody in general.

Neuman estimated that the amount of Bitcoin protected through self-custody could be 10 times greater than the value identified as stolen so far. The comparison places the reported losses against the much larger amount of Bitcoin held directly by users, while also showing how a single implementation flaw can create concentrated risk across thousands of wallets.

Eric Balchunas referred to spot Bitcoin exchange-traded funds as an option for users who prefer professional third-party custody. ETFs remove the need for holders to manage seed phrases and hardware devices themselves, but they also place control of the Bitcoin with a fund structure and its custodial arrangements rather than with the individual buyer.

For users choosing self-custody, the immediate lesson is less about abandoning hardware wallets than about verifying how keys were created and whether a device was affected by a known vulnerability. Moving funds to fresh addresses, generated after installing verified security updates or on an unaffected device, would cut the exposure tied to the reported flaw.

The unusual rise in sub-1 BTC transfers shows that many holders have already acted. With researchers continuing to identify new victim addresses, users of potentially affected Coldcard firmware face a narrower practical question: whether their current seed was created safely enough to remain trusted.


Concerned about wallet security? Learn safer storage methods in this detailed crypto storage guide today.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

Sign up and trade to earn over 15,000 USDT
Sign up