A firmware flaw affecting certain Coldcard hardware wallets has been linked to the theft of 1,367.05 Bitcoin from 4,585 compromised addresses, according to Galaxy Research, prompting affected users to abandon vulnerable recovery phrases and move funds to entirely new wallets.
Coinkite, the maker of Coldcard, issued a user risk alert on July 30 stating that affected firmware versions generated seed phrases with less randomness than intended. Seed phrases are the human-readable backups that create a wallet’s private keys. Once a weak phrase has been created, installing a firmware update cannot make its existing keys secure; users must transfer their Bitcoin to a wallet generated with a new recovery phrase.
Galaxy Research said the thefts occurred across three attack waves and that most stolen Bitcoin remained in addresses associated with the attackers. The first wave took 1,083 BTC in a 41-minute period through what Galaxy described as a highly automated operation. Later attacks targeted smaller balances, with average losses of roughly 0.1 BTC per victim.
The incident has produced unusually large Bitcoin movements that risk being misread as a wave of voluntary selling. Much of the activity appears tied to wallet replacement, emergency transfers, and the consolidation or temporary parking of funds while holders migrate away from exposed addresses.
Weak seed phrases exposed wallets without physical access
Galaxy Research attributed the vulnerability to a coding error introduced in a 2021 update. According to the research firm, the error redirected wallet-generation processes toward a predictable software fallback, reducing the effective randomness required to create secure seed phrases.
That gave attackers a route to derive vulnerable private keys offline rather than needing to compromise a device, intercept a transaction, or obtain a user’s physical Coldcard wallet. Hardware wallets protect keys from internet-connected devices, but that protection depends on the wallet’s cryptographic setup producing unpredictable keys in the first place.
Coinkite’s July 30 alert placed the immediate burden on users of affected versions: funds need to be swept into a newly generated wallet, using a recovery phrase that was not created under the flawed firmware. A firmware update can prevent future vulnerable wallet creation, but it cannot change a private key already derived from a weak seed.
Galaxy Research said it had compiled victim reports and shared information with law enforcement, compliance organizations, and other investigators. Thorn, cited in the research, said the team identified about 600 suspected hacker-controlled addresses.
Some stolen funds have begun moving through methods commonly used to complicate tracing, according to blockchain-security firm Thorn. These include peel chains, where a wallet repeatedly sends smaller portions onward while retaining change; cross-chain services; and offshore gambling sites. Galaxy said the bulk of the stolen Bitcoin had not yet left attacker-linked addresses.
Emergency migration lifted transaction activity
The rush to replace affected wallets coincided with a sharp increase in smaller Bitcoin transfers. On July 31, Bitcoin transactions with outputs below 1 BTC totaled 39,600 BTC, according to the data cited in the supplied material. That was the highest daily amount in that transaction category since November 2022, when it reached 39,900 BTC.
Active Bitcoin addresses also rose sharply. CryptoQuant data showed daily active addresses climbing from about 645,000 on July 30 to nearly 1 million the following day, the highest level since Dec. 10, 2024. Moreno said the rise was concentrated among sending addresses, while receiving addresses grew much less.
That imbalance fits a migration event more closely than ordinary retail activity. Affected holders would be expected to create a secure destination wallet, then send funds away from one or more exposed addresses. The number of outgoing addresses can rise rapidly during that process even if the number of new long-term Bitcoin users does not.
Bitcoin deposits involving transfers below 10 BTC also reached 7,300 BTC, their highest level since Feb. 6, according to CryptoQuant. Some of those deposits may reflect funds temporarily placed on trading platforms while users set up replacement storage, while others may represent actual sales. The on-chain totals alone cannot reliably separate the two motives.
Bitcoin traded near $63,526 on Sunday afternoon and remained above $63,000, according to the supplied market data. The price response was comparatively contained relative to the scale of the reported theft, though short-term market activity can remain sensitive as stolen coins move and wallet migrations continue.
Older coins could distort supply indicators
Maartunn said 77,402 long-dormant Bitcoin moved after the vulnerability became public. Such movements can alter several closely watched on-chain measures, including long-term holder supply, coin days destroyed, and spent output age distribution.
Coin days destroyed measures how long Bitcoin had remained unspent before moving. When coins held for years suddenly change addresses, the metric can jump even if their owners have no intention of selling. The Coldcard response therefore creates a practical warning for analysts relying on models that treat old-coin movement as a straightforward sign of distribution.
Exchange deposit alerts may carry the same limitation. A holder who moves Bitcoin from an at-risk wallet to a platform before setting up new cold storage creates a deposit signal that resembles potential selling activity. The transfer may instead be part of an urgent security process.
Social sentiment deteriorated as news of the flaw spread. Santiment reported that bullish comments relative to bearish comments across X, Reddit, and Telegram fell to 0.58, the lowest reading in its modern social-data history. That reaction reflects concern over hardware-wallet security and the uncertainty around how much stolen Bitcoin may eventually reach liquid markets.
Investigators turn to open-weight AI tools
Thorn said U.S.-based large language models blocked some efforts to analyze attack payloads, leading Galaxy’s team to use a Chinese open-source AI model for tracing work. Security teams can encounter automated restrictions when examining malware code, exploit instructions, or command-and-control logs, even where the purpose is defensive analysis.
Hugging Face described a similar problem in a separate security incident. The company said its team needed to review more than 17,000 event records and encountered blocked queries when commercial frontier models were used to assess exploit payloads and command-and-control logs. Hugging Face said it completed local forensic work using the open-weight GLM 5.2 model, reducing a process that had taken days to a matter of hours.
For Coldcard users covered by Coinkite’s alert, the immediate response is more direct than any firmware patch: generate a new wallet with a secure recovery phrase and move funds before an attacker can derive the old private keys. The resulting transfers may keep Bitcoin’s on-chain activity unusually elevated until the affected balances have been relocated.
Protect your funds with stronger storage habits—learn key crypto wallet mistakes to avoid before your next Bitcoin move.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

