Coldcard hardware wallet exploit led to $130M theft and prompted $15B in Bitcoin to move to safer custody.
Security & Exploits ·
A firmware vulnerability in Coldcard hardware wallets, introduced in March 2021, enabled attackers to generate private keys from devices that were supposed to store them entirely offline. The exploit, which began on July 30, resulted in approximately $130 million in stolen Bitcoin across multiple attack waves, with onchain data tracking roughly 2,100 BTC drained from over 5,200 affected addresses. The bug had weakened cryptographic security from 128 bits to around 40 bits by routing key generation through faulty software rather than the device's hardware chip.
In the immediate aftermath, 233,000 BTC worth approximately $15 billion moved out of long-term holder wallets as investors sought safer custody arrangements. Casa CEO Nick Neuman noted that the migration included users of other hardware wallets such as Ledger and Trezor who upgraded to multisig configurations after witnessing the Coldcard breach. The onchain movement of Bitcoin—more than 100 times the amount stolen—reflected what Neuman characterized as Bitcoin's self-custody ecosystem adapting under pressure rather than failing.
Whether the large-scale repositioning of coins has distorted the onchain metrics typically used to analyze Bitcoin holder behavior remains an open question, particularly given the 1.38 percent decline in long-term holder supply from its recent peak.