Key Highlights
- On July 31, transfers of under 1 BTC reached 39,600 BTC, closely matching the 39,900 BTC moved shortly after the FTX collapse, according to CryptoQuant.
- Active daily addresses surged from 645,000 to nearly one million, marking the highest level since December 2024.
- Galaxy Research has indicated a potential fourth wave of thefts, which could increase total losses to approximately 1,816 BTC.
On July 31, small Bitcoin holders engaged in transactions at a pace reminiscent of the aftermath of the FTX disaster, spurred by reports of vulnerabilities in Coldcard hardware wallets that had been producing insecure keys for five years, as revealed by CryptoQuant.
That day, transfers of less than 1 BTC totaled 39,600 BTC (approximately $2.5 billion), as noted by Julio Moreno, Head of Research at CryptoQuant, in a tweet. The last time a similar amount was recorded was on November 16, 2022, shortly after the FTX incident. The number of daily active addresses increased from 645,000 on July 30 to almost a million by July 31, the peak since December 2024, with most of the increase seen in sending addresses rather than those receiving funds.
This is the highest volume of BTC moved in a single day since the FTX collapse.
On July 31, 39.6K BTC was transferred following the Coldcard breach, compared to 39.9K BTC moved on November 16, 2022, shortly after FTX's downfall.
These figures reflect Bitcoin transfers of less than 1 BTC.
It’s encouraging to witness this activity… pic.twitter.com/c7Qzx7za6M
— Julio Moreno (@jjcmoreno) August 2, 2026
Some of these transactions were directed to exchanges. Transfers below 10 BTC totaled 7,300 BTC ($459 million) on July 31, marking the highest level since February 6, according to CryptoQuant. Moreno suggested that the uptick in activity was a response to the Coldcard breach, with individuals seemingly moving their assets "to seek safety," although he acknowledged that this connection was not definitively established.
Interestingly, Bitcoin's market price showed minimal fluctuation amid this influx of exchange deposits, indicating that users were primarily securing their holdings rather than liquidating them. Currently, Bitcoin is trading at $62,724, reflecting a slight decline of 0.7% over the previous day, as per CoinGecko data.
Details of the ColdCard Vulnerability
The Coldcard issue originated from a firmware error in March 2021, which resulted in seed phrases being generated from an insufficiently small pool. Galaxy Research tracked three waves of thefts by Saturday, amounting to 1,367 BTC across 4,585 addresses, a rise from $38 million when the flaw was first reported and $70 million when Binance’s founder Changpeng Zhao alerted users.
A fourth wave appears to be underway. Alex Thorn from Galaxy Research noted unusual activity across 15 consecutive blocks on Monday, occurring at approximately 45 times the standard rate, and after adjusting a previous set that mistakenly included multisig addresses, the count was refined to 709 addresses and 448.73 BTC ($28 million). This could bring the total to around 1,816 BTC, nearing $114 million in losses. Thorn cautioned that no victims have yet validated this latest wave, which is based on observed patterns.
🚨 A LIKELY FOURTH ORGANIZED WAVE OF COLD CARD ATTACKS IS IN PROGRESS
THERE ARE SIMILAR TRANSACTIONS IN THE MEMPOOL WAITING FOR CONFIRMATION, AND PREVIOUSLY CONFIRMED TRANSACTIONS HAVE OPTED FOR REPLACE-BY-FEE, SO CHECK YOUR FUNDS AS YOU MIGHT BE ABLE TO OUTBID THE ATTACKER.
Identified pattern:
blocks…— Alex Thorn (@intangiblecoins) August 3, 2026
Some of these transactions remain unconfirmed in the mempool and have chosen replace-by-fee, indicating that holders who act swiftly and offer higher fees could potentially outbid the attackers. Notably, none of the addresses affected in the initial three waves were multisig.
A Call to Action
Nick Percoco, Chief Security Officer at Kraken, described the incident as a "wake-up call for the entire hardware wallet sector." He pointed out that ColdCard’s Mk4, Mk5, and Q models are equipped with certified secure components, yet their seed generation still produced approximately 72 bits of security because the certification only covered the hardware and not the specific code path executed.
— Nick Percoco (@c7five) August 2, 2026
Percoco advocates for independent laboratory validation of entropy sources tied to specific firmware versions, similar to what is required for payment terminals. He also mentioned that Coinkite's hotfix will now fail the build unless the proper generator is connected, a control he claims took about 48 hours to implement once the company identified the issue to address.
