$130M Coldcard Crisis Spurs Massive Bitcoin Migration
A $130 million crisis is unfolding for Coldcard users after hackers exploited a firmware flaw in the hardware wallet, leading to the theft of at least 1,596 BTC from about 7,300 addresses. Galaxy Research identified three major attack waves and 14 smaller incidents, with a possible fourth wave that could increase the total to 2,055 BTC.
The vulnerability allowed attackers to reconstruct private keys without obtaining the device or owner's recovery words, as some devices generated weaker recovery seeds using a flawed software process. Coinkite, Coldcard's manufacturer, urged users to install the security update and create a new seed, but every affected wallet remains exposed until its funds are moved.
The crisis has pushed Bitcoin activity to multi-month highs, with 712,000 active addresses over the past seven days and transactions worth more than $100,000 reaching 61,800. CryptoQuant attributed this increase to the Coldcard exploit as users moved coins into newly generated wallets or transferred funds to custodial platforms.
Exchange inflows have risen as users seek an immediate destination for Bitcoin removed from vulnerable wallets, with deposits from smaller holders reaching their highest level since February 6. Binance received about 51% of the net increase, with its reserves climbing by approximately 9,000 BTC to 659,000 BTC.