- Transfers of less than 1 BTC reached 39,600 BTC on July 31, the highest volume since the FTX collapse in 2022, according to CryptoQuant.
- Daily active addresses surged from 645,000 to nearly one million, the highest level since December 2024, as small holders moved funds after news of the Coldcard flaw.
- Galaxy Research flagged a likely fourth wave of thefts related to the exploit, potentially bringing total losses to roughly 1,816 BTC, or about $114 million.
Small Bitcoin holders moved coins on July 31 at a rate not seen since the collapse of FTX, according to CryptoQuant, as news spread that Coldcard hardware wallets had been generating guessable keys for five years. Transfers of less than 1 BTC totaled 39,600 BTC, worth around $2.5 billion, the firm’s Head of Research Julio Moreno tweeted.
The last comparable figure was 39,900 BTC on November 16, 2022, days after FTX failed. Daily active addresses rose from 645,000 on July 30 to almost a million on July 31, the highest since December 2024. Some funds moved to exchanges, with deposits of sub-10 BTC hitting 7,300 BTC ($459 million) on July 31, the most since February 6. Moreno linked the activity to the Coldcard breach, suggesting people were shifting holdings “looking for safety,” though he noted the connection was not certain.
Notably, Bitcoin’s price barely moved amid the wave of exchange deposits, indicating users moved coins to secure them rather than sell. The Coldcard flaw dates to a March 2021 firmware build error that left seed phrases drawn from a far too small pool. Galaxy Research logged three waves of thefts by Saturday, totaling 1,367 BTC across 4,585 addresses.
A fourth wave is likely under way, with Galaxy Research‘s Alex Thorn flagging sweeps across 15 consecutive blocks running at 45 times the normal rate. He corrected a set that included multisig addresses, putting the wave at 709 addresses and 448.73 BTC ($28 million). Thorn added a caveat that no victim has yet confirmed the fourth wave, which rests on pattern matching.
Some sweeps still sat unconfirmed in the mempool and had opted into replace-by-fee, meaning holders who act quickly may outbid the attacker. Kraken chief security officer Nick Percoco called the incident a “wake-up call for the entire hardware wallet industry.” He noted that ColdCard’s Mk4, Mk5 and Q ship with certified secure elements, yet their seeds still came out around 72 bits because the certification covered the component while nobody verified which code path ran.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
