Summary

  • A security vulnerability in Coldcard firmware resulted in around 2,100 BTC being stolen, with total losses estimated at approximately $130 million over several attacks.
  • Data from Checkonchain reveals that 233,000 BTC exited long-term holder wallets in the aftermath of the breach.
  • According to Casa CEO Nick Neuman, discussions with customers indicate that some of the 233,000 BTC originated from Ledger and Trezor users—who shifted to multisig wallets after observing the hack—rather than from Coldcard users.

Following the significant exploit of Coldcard wallets, which occurred on July 30, Casa CEO Nick Neuman began to monitor more than just the Bitcoin being siphoned from compromised wallets.

As attackers targeted Coldcard wallets methodically, a staggering 233,000 BTC—valued at around $15 billion—was discreetly relocated to safer holdings.

Myriad: What's next for Bitcoin? Make your prediction here.

The ongoing breach has reportedly resulted in nearly $130 million worth of Bitcoin being stolen from Coldcard wallets, which are physical devices designed to store private keys offline and manufactured by Coinkite, a Canadian company.

A firmware flaw introduced in March 2021 allowed key generation to be routed through a subpar software random number generator, compromising the security of private keys. This vulnerability reduced the security level from 128 bits to about 40 bits, akin to a bank vault with a four-digit PIN.

The onchain metrics surrounding the Coldcard incident highlight the critical role of self-custody in maintaining Bitcoin's stability as an asset.
In the days surrounding the hack:
- 2.1k BTC was stolen
- 22k was transferred to exchanges
- 233k was withdrawn from long-term holder wallets… pic.twitter.com/iewr5RvG9c

— Nick Neuman (@Nneuman) August 9, 2026

Galaxy Research has monitored the impact over three confirmed attack waves, with total losses reaching approximately 1,596 BTC across over 5,200 wallets.

Neuman shared on-chain data from analyst James Check of Checkonchain to advocate for Bitcoin's resilience. He argued that self-custody, which involves holding one's own private keys instead of relying on exchanges or custodians, proved effective under duress.

"The metrics from the Coldcard situation underscore the significance of self-custody in preserving Bitcoin's status as an asset," Neuman expressed on X.

In his post, Neuman referenced Checkonchain's data, noting 2,100 BTC stolen (which exceeded Galaxy's estimates), along with 22,000 BTC moving to exchanges. Additionally, 233,000 BTC was extracted from long-term holder wallets—these wallets had been inactive for at least 155 days, which analysts regard as indicative of serious, patient investors—seeking a safer option. This amount is more than 100 times what was taken by the attackers.

The Coldcard incident led to a decrease of approximately 233k BTC in Long-Term Holder supply, marking a 1.38% drop from its recent peak.

Given the gravity of this event, an essential query arises: did the urgent relocation of coins distort the onchain metrics we utilize to evaluate Bitcoin?… pic.twitter.com/FPVLUkUlqU

— _Checkonchain (@_checkonchain) August 7, 2026

Some of the Bitcoin migration was attributed to Coldcard users transitioning to multisig wallets, which require multiple independent keys for any transaction approval, thus preventing a single compromised device from draining all funds. Others were Ledger and Trezor users who reacted to the hack by upgrading their security.

Neuman confirmed these migration trends based on discussions with customers, stating, "Somewhere between ~10x-100x the amount of Bitcoin stolen was swiftly moved to safety as people raised alarms."

Unlike centralized exchanges, where breaches can lead to widespread losses simultaneously, the Coldcard hack involved attackers breaching individual addresses, allowing the network time to respond. "This serves as a prominent illustration of the resilience self-custody brings to the network," Neuman remarked. "If all that BTC had been held by a custodian and that custodian was hacked, the outcomes would have been reversed."

Analytics firm Glassnode corroborated the magnitude of the incident, reporting a decline in long-term holder supply from nearly 15 million BTC to about 14.7 million BTC—the most significant weekly fall since December 2024. This occurred while Bitcoin was trading at roughly 50% less than its all-time high of $126,000, which was reached in October 2025.

Coinkite has advised anyone who generated a seed on firmware versions 4.0.1 to 4.1.9—spanning from March 2021 to July 2026—to consider their wallets compromised and to migrate to a new seed without delay.

Daily Debrief Newsletter

Stay updated with the latest news stories, along with original features, podcasts, videos, and more.