Coldcard firmware exploit leads to over 2,000 BTC stolen ($100M+) and triggers mass wallet migration, pushing Bitcoin active addresses to 8-month high.
Security & Exploits ·
A vulnerability in Coldcard firmware resulted in over 2,000 BTC being stolen, with losses surpassing $100 million, according to Coinkite. The exploit triggered a wave of user migrations from vulnerable wallets to alternative storage solutions, as holders sought to secure their assets. Bitcoin active addresses reached approximately 0.98 million per day on July 31, marking the highest daily level since December 2024, reflecting the scale of wallet movement activity.
The security incident reshaped on-chain behavior in measurable ways. Exchange balances grew by 22,135 BTC as users moved funds toward centralized platforms or other custodial arrangements, while overall transaction volume declined to 607,581—a divergence that suggests users prioritized operational security over market participation. The spike in active addresses paired with lower transaction counts indicates a shift driven by defensive repositioning rather than renewed trading interest.
What remains unclear is the full scope of affected wallets, the specific timeframe during which the vulnerability was exploitable, and whether additional vulnerabilities in other hardware or software wallets may have motivated the broader migration. The extent of ongoing user remediation efforts and whether the active address surge will sustain beyond the initial panic response also remain open questions.