Coldcard firmware exploit leads to over 2,000 BTC stolen ($100M+) and triggers mass wallet migration, pushing Bitcoin active addresses to 8-month high.
Security & Exploits ·
A firmware vulnerability in Coldcard hardware wallets resulted in over 2,000 BTC being stolen, with total losses exceeding $100 million. The breach prompted widespread user migration to alternative wallets as a precautionary measure. On July 31, Bitcoin active addresses climbed to roughly 0.98 million daily—the highest point recorded since December 2024—as holders moved to secure their funds in response to the vulnerability.
The shift in on-chain behavior reflected prioritization of wallet security over trading activity. Exchange deposits grew by 22,135 BTC during the period, while transaction volume dropped to 607,581, suggesting users were consolidating holdings and moving them to self-custody rather than engaging in market trades. This pattern—rising address count paired with falling transaction frequency—indicated defensive positioning rather than renewed buying or selling pressure.
It remains unclear whether the addressed vulnerability has been fully patched, what timeline users face for wallet recovery, or whether additional exposure remains in circulation. The incident underscores ongoing security challenges in the hardware wallet ecosystem and the speed at which fears can reshape on-chain capital flows, even without broader market conviction driving the movement.