Coldcard hardware wallet security incident results in over 2,055 BTC stolen, triggering major whale activity and fund consolidation.
Security & Exploits ·
Bitcoin network activity surged to a three-month high following a security incident affecting Coldcard hardware wallets. Over the past week, 712,000 addresses were active and 61,800 transactions valued above $100,000 were recorded—a five-month peak in whale movement. Estimates place losses from the late-July attacks at above 2,055 BTC, or roughly $130 million, with affected users rushing to consolidate wallets and reduce exposure.
The exploit stemmed from weak keys generated by Coldcard devices across multiple firmware versions—Mk3, Mk4, Mk5, and Coldcard Q. Research identified that tokens were stolen from 7,300 addresses in three confirmed attack waves, with 14 smaller security incidents also uncovered. The exploits appeared to involve automated sweeps, possibly assisted by large language models. Coinkite released emergency firmware updates and confirmed destroying remaining vulnerable inventory after the issue became public on July 30.
Converting the stolen Bitcoin to fiat faces substantial obstacles. Surveillance of the movement patterns makes these UTXOs highly trackable, and regulated on-ramps are likely to refuse the coins. Options such as mixers, cross-chain bridges, and peer-to-peer channels introduce counterparty risk and extraction costs that could reduce realized value significantly over time. Whether a potential fourth attack wave occurred remains unconfirmed, and market volatility may persist as retail sellers clash with whale accumulation over coming weeks.