Written by: Oluwapelumi Adejumo
Translated by: Saoirse, Foresight News
The Coldcard wallet crisis has severely impacted Bitcoin market sentiment, confusing various on-chain reference indicators, while also exposing the long-standing shortcomings of AI-assisted network defense systems.
On July 30, hardware manufacturer Coinkite issued a risk warning to users: wallets generated under the influence of specific versions of Coldcard firmware are at risk of asset theft, stemming from a software error that caused the random generation of mnemonic phrases to be far below design standards.
Galaxy Research stated that this security incident witnessed three waves of attacks, with a total of 4,585 addresses targeted, resulting in the theft of 1,367.05 Bitcoin, valued at approximately 89 million dollars.

Coldcard Bitcoin wallet hacking event (Source: Galaxy Research)
Alex Thorn, Galaxy's global research head, mentioned that the stolen Bitcoin from the three waves of attacks still resides in the addresses controlled by the attackers. However, he added that some scattered small amounts of stolen funds have already been laundered through peel chains, cross-chain services, and foreign casinos.
Coldcard wallet migration disrupts Bitcoin bearish signals
As security risks continue to ferment, users exposed to vulnerabilities rush to transfer Bitcoin to avoid asset theft by hackers. Although Coinkite has pushed a fixed firmware version for affected models, previously generated high-risk mnemonic phrases cannot be repaired by system updates, forcing users to create entirely new wallets to transfer assets to safe addresses.
This large-scale wallet migration has caused an abnormal surge in on-chain activity from small holders and long-dormant Bitcoin. Julio Moreno, head of research at CryptoQuant, reported that on July 31, the total scale of transactions generating less than 1 Bitcoin reached 39,600 Bitcoin. This is the highest daily value for such transactions since the FTX bankruptcy in November 2022; shortly after the FTX incident, the volume of similar transactions was 39,900 Bitcoin.
The number of active Bitcoin addresses soared from around 645,000 on July 30 to nearly 1 million the next day, reaching a peak not seen since December 10, 2024. Moreno indicated that the surge in address numbers was mainly concentrated in outgoing addresses, while the increase in receiving addresses was very limited, sufficient to indicate that users were transferring funds out of their original wallets for risk avoidance reasons.

Daily active Bitcoin addresses (Data Source: CryptoQuant)
The inflow of deposits for transactions less than 10 Bitcoin increased to 7,300 Bitcoin, reaching a new high since February 6 of that year. Some users, during the transitional period of establishing secure wallets, temporarily stored their assets in exchanges; of course, this fund flow also includes investors preparing to sell and liquidate their holdings.

Surge in Bitcoin exchange deposits after Coldcard incident (Source: CryptoQuant)
CryptoQuant analyst JA Maartunn added that after the exposure of the vulnerability, 77,402 long-unused Bitcoin were transferred. However, Maartunn warned that the large-scale flow of funds should not be interpreted as evidence of panic selling by many investors; in light of the event's background, the fund movements essentially reflect users reinforcing the security of their wallets.
He stated: "The Coldcard mnemonic issue led users to transfer long-held Bitcoin for asset security. This will disrupt the accuracy of various chart data, such as changes in supply from long-term holders, Coin Days Destroyed, and the distribution of expenditure cycles."
(Note: Coin Days Destroyed (CDD) measures the scale of movement for long-held Bitcoin; this time, due to user wallet risk avoidance transferring massive old coins, the indicator surged unusually, leading to market misjudgments of large-scale selling.)
Accompanied by a significant increase in on-chain transaction activity, overall market sentiment has sharply weakened. Blockchain analysis agency Santiment pointed out that the ratio of bullish to bearish comments about Bitcoin across the network has dropped to the lowest level since the platform began modern social data tracking. On platforms like X, Reddit, and Telegram, every 1 bearish comment corresponds to only 0.58 bullish comments.

Bitcoin market sentiment turns bearish (Source: Santiment)
Santiment believes that the market's reaction is so intense because the targets of this vulnerability attack are cold storage wallets. Most holders view cold wallets as the last line of security for their Bitcoin assets after withdrawing from exchanges and distancing themselves from high-risk crypto platforms.
US AI regulatory measures complicate Coldcard case investigation
This group of wallet transfers that has caused disruptions in Bitcoin market signals has made tracking illicit funds urgent, requiring the identification of cash flow before they enter exchangeable and withdrawable platforms.
Galaxy Research compiled victim-reported information to identify a batch of suspected hacker addresses and synchronized the data with law enforcement, compliance agencies, and other cybersecurity investigators. Thorn revealed that institutions have reported approximately 600 suspected hacker addresses believed to hold stolen Bitcoin.
However, he stated that the security restrictions set by mainstream large models in the United States have hindered the tracking of stolen assets and protecting users, forcing the investigation team to use a Chinese open-source AI model. Thorn did not specify which US AI models and which queries were intercepted, nor did he detail what assistance this alternative model provided to the investigation. Even so, the dilemma he proposed is highly similar to the challenges faced by Hugging Face during its previous network attack.
This AI platform stated that an automated program had invaded part of its infrastructure, requiring its security team to analyze over 17,000 event logs. Initially, investigators used commercial interfaces to call mainstream cutting-edge large models to upload attack instructions, exploit payloads, and command and control related logs for analysis.
Hugging Face noted that these queries were all intercepted by the system. The reason is that the AI security system cannot distinguish between investigators conducting emergency responses and actual attackers. Ultimately, the team opted for the self-developed open-source weight model GLM 5.2 from Zhipu AI to complete all forensic analysis on its servers.
This model assisted staff in constructing a complete attack timeline, locating leaked credentials, extracting intrusion features, and distinguishing genuine attack traces from bait interference behaviors. Hugging Face claimed that what originally required days of forensic work was shortened to a few hours with the aid of AI.
This case confirms the asymmetry in attack and defense AI posed by Thorn regarding the Coldcard case: hackers can use unrestricted, self-modifiable AI tools, free from the constraints of commercial model security rules; while defenders often encounter refusals from AI when submitting data with malicious features for case investigation, even if their intent is to control malicious security events.
However, if AI security restrictions are broadly lifted, it will create new risks. AI service providers cannot simply release permissions based on users verbally claiming they are tracking stolen coins; such unrestricted tools can also be misused for wallet attacks, money laundering, circumventing trading supervision, and other illegal activities.
In the crypto field, this contradiction is particularly acute: stolen assets can be transferred using cross-chain bridges, exchanges, and gambling platforms within minutes. Once tracking is delayed, funds may move to freely withdrawable platforms before victims receive their report receipts and investigators complete manual tracing, completely losing the chance for freezing.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。