In the days after the Coldcard exploit, a much larger pool of Bitcoin moved than the amount attackers actually stole. Casa CEO Nick Neuman said about 233,000 BTC, worth roughly $15 billion at current prices, shifted in search of safer storage while compromised Coldcard wallets were being drained one address at a time.

The breach began on July 30 and Decrypt described it as the worst hardware wallet exploit in Bitcoin’s recent history. The report said the incident has already led to close to $130 million in stolen Bitcoin from Coldcard hardware wallets, devices made by Canadian company Coinkite and designed to keep private keys fully offline.
The root cause was a firmware bug introduced in March 2021. Instead of relying on the device’s dedicated hardware chip for key generation, the affected firmware routed that process through a weaker software random number generator. As a result, private keys became guessable, with security dropping from 128 bits to about 40 bits.
Three major onchain flows appeared around the breach
Earlier this week, Neuman posted data from analyst James Check of Checkonchain to argue that self-custody held up under stress rather than failing outright. The figures he cited showed three main movements in the days around the hack:
- about 2,100 BTC stolen
- about 22,000 BTC sent to exchanges
- about 233,000 BTC moved out of long-term holder wallets and into safer setups
Neuman wrote on X: 「The onchain metrics around the Coldcard incident reinforce how important self-custody is to the resilience of Bitcoin as an asset class.」
In that breakdown, long-term holder wallets refer to addresses that had been dormant for at least 155 days, a group analysts often use as a proxy for more patient investors. By that measure, the amount moved to safety was more than 100 times the amount stolen by the attackers.
Galaxy Research and Glassnode tracked the impact
Galaxy Research said the fallout could be grouped into three confirmed attack waves, with losses reaching about 1,596 BTC across more than 5,200 addresses. That tally is lower than the 2,100 BTC figure in the onchain breakdown cited by Neuman.
Checkonchain said the Coldcard incident led to a decline of about 233,000 BTC in long-term holder supply, a 1.38% drop from its recent all-time high.

Glassnode data pointed to a similar shift in scale. According to the report, long-term holder supply fell from nearly 15 million BTC to about 14.7 million BTC, marking the largest weekly decline since December 2024. The move came while Bitcoin was trading roughly 50% below its all-time high of $126,000, which was set in October 2025.
Some users moved to multisig, others reacted across brands
Decrypt reported that some of the emergency movement came from Coldcard users migrating to multisig wallets, which require multiple independent keys to approve a transaction. That structure reduces the chance that a single compromised device can drain an entire balance.
Some of the activity also came from holders using Ledger and Trezor devices. Those products are different hardware wallets, but Casa said the Coldcard breach still acted as a warning signal for some users. The company said both patterns were confirmed through actual conversations with customers.
Neuman wrote: 「So somewhere between ~10x-100x the amount of bitcoin stolen was moved to safety as people sounded the alarm.」
Neuman contrasted the event with a custodial breach
Neuman said the structure of self-custody changed the outcome. In a centralized exchange breach, he said, funds typically leave all at once. In the Coldcard case, the attacker had to crack addresses individually and could only extract funds gradually, leaving time for the rest of the network to react.
He wrote: 「This is a giant flashing neon sign showcasing the resilience that self-custody adds to the network. If all that BTC was held at a custodian and the custodian was hacked instead, those numbers would have been flipped.」
Coinkite’s guidance covers firmware from 2021 to 2026
Coinkite has urged anyone who generated a seed on firmware versions 4.0.1 through 4.1.9 to treat those wallets as compromised and move to a new seed immediately. The affected range covers March 2021 through July 2026.

