After the Coldcard exploit, 233,000 BTC shifted to safer storage

After the Coldcard exploit, 233,000 BTC shifted to safer storage

N
News Editor
2026-08-12 18:16:04
The fallout from the Coldcard hardware wallet exploit has extended far beyond the Bitcoin directly stolen from vulnerable devices. According to Decrypt, Casa CEO Nick Neuman said roughly 233,000 BTC moved out of long-term holder wallets and into safer arrangements in the days around the breach, dwarfing the amount taken by attackers. The incident began on July 30 and has already been tied to nearly $130 million in stolen Bitcoin, while Galaxy Research tracked about 1,596 BTC in losses across more than 5,200 addresses in three confirmed attack waves. Neuman, citing onchain analysis from James Check of Checkonchain, said about 2,100 BTC was stolen, 22,000 BTC moved to exchanges, and 233,000 BTC left wallets that had been dormant for at least 155 days. Glassnode also recorded a sharp drop in long-term holder supply, from nearly 15 million BTC to about 14.7 million BTC, the steepest weekly decline since December 2024. Coinkite has urged users who generated a seed on firmware versions 4.0.1 through 4.1.9 between March 2021 and July 2026 to assume compromise and migrate to a new seed immediately.

In the days after the Coldcard exploit, a much larger pool of Bitcoin moved than the amount attackers actually stole. Casa CEO Nick Neuman said about 233,000 BTC, worth roughly $15 billion at current prices, shifted in search of safer storage while compromised Coldcard wallets were being drained one address at a time.

After the Coldcard exploit, 233,000 BTC shifted to safer storage 2

The breach began on July 30 and Decrypt described it as the worst hardware wallet exploit in Bitcoin’s recent history. The report said the incident has already led to close to $130 million in stolen Bitcoin from Coldcard hardware wallets, devices made by Canadian company Coinkite and designed to keep private keys fully offline.

The root cause was a firmware bug introduced in March 2021. Instead of relying on the device’s dedicated hardware chip for key generation, the affected firmware routed that process through a weaker software random number generator. As a result, private keys became guessable, with security dropping from 128 bits to about 40 bits.

Three major onchain flows appeared around the breach

Earlier this week, Neuman posted data from analyst James Check of Checkonchain to argue that self-custody held up under stress rather than failing outright. The figures he cited showed three main movements in the days around the hack:

  • about 2,100 BTC stolen
  • about 22,000 BTC sent to exchanges
  • about 233,000 BTC moved out of long-term holder wallets and into safer setups

Neuman wrote on X: 「The onchain metrics around the Coldcard incident reinforce how important self-custody is to the resilience of Bitcoin as an asset class.」

In that breakdown, long-term holder wallets refer to addresses that had been dormant for at least 155 days, a group analysts often use as a proxy for more patient investors. By that measure, the amount moved to safety was more than 100 times the amount stolen by the attackers.

Galaxy Research and Glassnode tracked the impact

Galaxy Research said the fallout could be grouped into three confirmed attack waves, with losses reaching about 1,596 BTC across more than 5,200 addresses. That tally is lower than the 2,100 BTC figure in the onchain breakdown cited by Neuman.

Checkonchain said the Coldcard incident led to a decline of about 233,000 BTC in long-term holder supply, a 1.38% drop from its recent all-time high.

After the Coldcard exploit, 233,000 BTC shifted to safer storage 3

Glassnode data pointed to a similar shift in scale. According to the report, long-term holder supply fell from nearly 15 million BTC to about 14.7 million BTC, marking the largest weekly decline since December 2024. The move came while Bitcoin was trading roughly 50% below its all-time high of $126,000, which was set in October 2025.

Some users moved to multisig, others reacted across brands

Decrypt reported that some of the emergency movement came from Coldcard users migrating to multisig wallets, which require multiple independent keys to approve a transaction. That structure reduces the chance that a single compromised device can drain an entire balance.

Some of the activity also came from holders using Ledger and Trezor devices. Those products are different hardware wallets, but Casa said the Coldcard breach still acted as a warning signal for some users. The company said both patterns were confirmed through actual conversations with customers.

Neuman wrote: 「So somewhere between ~10x-100x the amount of bitcoin stolen was moved to safety as people sounded the alarm.」

Neuman contrasted the event with a custodial breach

Neuman said the structure of self-custody changed the outcome. In a centralized exchange breach, he said, funds typically leave all at once. In the Coldcard case, the attacker had to crack addresses individually and could only extract funds gradually, leaving time for the rest of the network to react.

He wrote: 「This is a giant flashing neon sign showcasing the resilience that self-custody adds to the network. If all that BTC was held at a custodian and the custodian was hacked instead, those numbers would have been flipped.」

Coinkite’s guidance covers firmware from 2021 to 2026

Coinkite has urged anyone who generated a seed on firmware versions 4.0.1 through 4.1.9 to treat those wallets as compromised and move to a new seed immediately. The affected range covers March 2021 through July 2026.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
490

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.