Coldcard Flaw Triggers Bitcoin Address Spike
A security flaw in older Coldcard firmware led to a surge in Bitcoin on-chain activity after attackers began draining vulnerable wallets on July 30.
The issue triggered a sharp increase in active addresses, with 978,570 unique addresses involved in transactions on July 31, according to Santiment data. This figure was about 1.6 times the average for July and 43% above July's busiest day.
However, Santiment's analysis shows that this spike does not indicate selling, but rather unusually high Bitcoin transfer activity during the scare. The data also reveal that exchange inflows did not show an equivalent surge, with average inflows averaging $1.55 billion from August 1 through August 6, below the roughly $1.67 billion July average.
This distinction matters because on-chain movement is not synonymous with selling. If holders moved coins into newly generated self-custody addresses, the activity represents defensive repositioning rather than an attempt to sell. The next signal will be whether active addresses normalize as the incident fades.