After Coldcard Was Hacked, $15 Billion in Bitcoin Moved to Safety

CN
Decrypt
Follow
1 hour ago


In the days after the worst hardware wallet exploit in Bitcoin’s recent history, Casa CEO Nick Neuman began counting more than just the BTC being drained from vulnerable Coldcard wallets.


While attackers were draining Coldcard wallets one address at a time, 233,000 BTC—worth about $15 billion at today’s prices—was quietly moving in search of safety.



Myriad: Bitcoin's next move? Click to make your prediction.

The massive and ongoing breach that started on July 30 has already led to close to $130 million in stolen Bitcoin from Coldcard hardware wallets—physical gadgets that store private keys entirely offline, never connecting to the internet, and made by Canadian company Coinkite.


A firmware bug introduced in March 2021 had routed key generation through a weak software random number generator instead of the device's dedicated hardware chip. Private keys (the secret codes that prove ownership of Bitcoin and authorize any transaction) became guessable, with security collapsing from 128 bits to roughly 40—the cryptographic equivalent of a bank vault that turns out to have a four-digit PIN.



Galaxy Research tracked the fallout across three confirmed attack waves, with losses reaching approximately 1,596 BTC across more than 5,200 addresses.


Casa’s Neuman, earlier this week, posted the on-chain numbers from analyst James Check of Checkonchain to make an argument for Bitcoin’s resilience. Self-custody, holding your own private keys rather than leaving Bitcoin with an exchange or custodian, didn't buckle under pressure but instead adapted, he argued.


"The onchain metrics around the Coldcard incident reinforce how important self-custody is to the resilience of Bitcoin as an asset class," Neuman wrote on X.


The breakdown Neumann cited in his post, drawing Checkonchain’s onchain data: 2,100 BTC stolen (higher than Galaxy's own accouting), and 22,000 BTC moved to exchanges. And 233,000 BTC moved out of long-term holder wallets—addresses dormant for at least 155 days, a cohort analysts watch as a proxy for serious, patient investors—into safety. That’s more than 100 times what the attackers took.



Some of that came from Coldcard users migrating to multisig wallets (setups requiring multiple independent keys to approve any transaction, so no single compromised device can drain everything). Some came from holders on Ledger and Trezor—entirely different hardware—who used the hack as a wake-up call.


Casa confirmed both patterns from actual customer conversations. "So somewhere between ~10x-100x the amount of bitcoin stolen was moved to safety as people sounded the alarm," Neuman wrote.


When a centralized exchange gets breached, everything goes at once. Here, the attacker had to crack addresses individually, earning a trickle at a time while the rest of the network had time to respond. "This is a giant flashing neon sign showcasing the resilience that self-custody adds to the network," Neuman wrote. "If all that BTC was held at a custodian and the custodian was hacked instead, those numbers would have been flipped."





Data from analytics company Glassnode confirms the scale: long-term holder supply dropped from nearly 15 million BTC to approximately 14.7 million—the largest weekly decline since December 2024. It happened while Bitcoin traded roughly 50% below its all-time high of $126,000, set in October 2025.


Coinkite has urged anyone who generated a seed on firmware versions 4.0.1 through 4.1.9—covering March 2021 to July 2026—to treat those wallets as compromised and migrate to a new seed immediately.


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink