toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trading
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
Be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android app
More download options

Coldcard firmware flaw exposes weak Bitcoin seeds

2026-08-03 03:16

A firmware flaw affecting certain Coldcard hardware wallets has been linked to the theft of 1,367.05 Bitcoin from 4,585 compromised addresses, according to Galaxy Research, prompting affected users to abandon vulnerable recovery phrases and move funds to entirely new wallets.

Coinkite, the maker of Coldcard, issued a user risk alert on July 30 stating that affected firmware versions generated seed phrases with less randomness than intended. Seed phrases are the human-readable backups that create a wallet’s private keys. Once a weak phrase has been created, installing a firmware update cannot make its existing keys secure; users must transfer their Bitcoin to a wallet generated with a new recovery phrase.

Galaxy Research said the thefts occurred across three attack waves and that most stolen Bitcoin remained in addresses associated with the attackers. The first wave took 1,083 BTC in a 41-minute period through what Galaxy described as a highly automated operation. Later attacks targeted smaller balances, with average losses of roughly 0.1 BTC per victim.

The incident has produced unusually large Bitcoin movements that risk being misread as a wave of voluntary selling. Much of the activity appears tied to wallet replacement, emergency transfers, and the consolidation or temporary parking of funds while holders migrate away from exposed addresses.

Weak seed phrases exposed wallets without physical access

Galaxy Research attributed the vulnerability to a coding error introduced in a 2021 update. According to the research firm, the error redirected wallet-generation processes toward a predictable software fallback, reducing the effective randomness required to create secure seed phrases.

That gave attackers a route to derive vulnerable private keys offline rather than needing to compromise a device, intercept a transaction, or obtain a user’s physical Coldcard wallet. Hardware wallets protect keys from internet-connected devices, but that protection depends on the wallet’s cryptographic setup producing unpredictable keys in the first place.

Coinkite’s July 30 alert placed the immediate burden on users of affected versions: funds need to be swept into a newly generated wallet, using a recovery phrase that was not created under the flawed firmware. A firmware update can prevent future vulnerable wallet creation, but it cannot change a private key already derived from a weak seed.

Galaxy Research said it had compiled victim reports and shared information with law enforcement, compliance organizations, and other investigators. Thorn, cited in the research, said the team identified about 600 suspected hacker-controlled addresses.

Some stolen funds have begun moving through methods commonly used to complicate tracing, according to blockchain-security firm Thorn. These include peel chains, where a wallet repeatedly sends smaller portions onward while retaining change; cross-chain services; and offshore gambling sites. Galaxy said the bulk of the stolen Bitcoin had not yet left attacker-linked addresses.

Emergency migration lifted transaction activity

The rush to replace affected wallets coincided with a sharp increase in smaller Bitcoin transfers. On July 31, Bitcoin transactions with outputs below 1 BTC totaled 39,600 BTC, according to the data cited in the supplied material. That was the highest daily amount in that transaction category since November 2022, when it reached 39,900 BTC.

Active Bitcoin addresses also rose sharply. CryptoQuant data showed daily active addresses climbing from about 645,000 on July 30 to nearly 1 million the following day, the highest level since Dec. 10, 2024. Moreno said the rise was concentrated among sending addresses, while receiving addresses grew much less.

That imbalance fits a migration event more closely than ordinary retail activity. Affected holders would be expected to create a secure destination wallet, then send funds away from one or more exposed addresses. The number of outgoing addresses can rise rapidly during that process even if the number of new long-term Bitcoin users does not.

Bitcoin deposits involving transfers below 10 BTC also reached 7,300 BTC, their highest level since Feb. 6, according to CryptoQuant. Some of those deposits may reflect funds temporarily placed on trading platforms while users set up replacement storage, while others may represent actual sales. The on-chain totals alone cannot reliably separate the two motives.

Bitcoin traded near $63,526 on Sunday afternoon and remained above $63,000, according to the supplied market data. The price response was comparatively contained relative to the scale of the reported theft, though short-term market activity can remain sensitive as stolen coins move and wallet migrations continue.

Older coins could distort supply indicators

Maartunn said 77,402 long-dormant Bitcoin moved after the vulnerability became public. Such movements can alter several closely watched on-chain measures, including long-term holder supply, coin days destroyed, and spent output age distribution.

Coin days destroyed measures how long Bitcoin had remained unspent before moving. When coins held for years suddenly change addresses, the metric can jump even if their owners have no intention of selling. The Coldcard response therefore creates a practical warning for analysts relying on models that treat old-coin movement as a straightforward sign of distribution.

Exchange deposit alerts may carry the same limitation. A holder who moves Bitcoin from an at-risk wallet to a platform before setting up new cold storage creates a deposit signal that resembles potential selling activity. The transfer may instead be part of an urgent security process.

Social sentiment deteriorated as news of the flaw spread. Santiment reported that bullish comments relative to bearish comments across X, Reddit, and Telegram fell to 0.58, the lowest reading in its modern social-data history. That reaction reflects concern over hardware-wallet security and the uncertainty around how much stolen Bitcoin may eventually reach liquid markets.

Investigators turn to open-weight AI tools

Thorn said U.S.-based large language models blocked some efforts to analyze attack payloads, leading Galaxy’s team to use a Chinese open-source AI model for tracing work. Security teams can encounter automated restrictions when examining malware code, exploit instructions, or command-and-control logs, even where the purpose is defensive analysis.

Hugging Face described a similar problem in a separate security incident. The company said its team needed to review more than 17,000 event records and encountered blocked queries when commercial frontier models were used to assess exploit payloads and command-and-control logs. Hugging Face said it completed local forensic work using the open-weight GLM 5.2 model, reducing a process that had taken days to a matter of hours.

For Coldcard users covered by Coinkite’s alert, the immediate response is more direct than any firmware patch: generate a new wallet with a secure recovery phrase and move funds before an attacker can derive the old private keys. The resulting transfers may keep Bitcoin’s on-chain activity unusually elevated until the affected balances have been relocated.


Protect your funds with stronger storage habits—learn key crypto wallet mistakes to avoid before your next Bitcoin move.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trading
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.