Coldcard Wallet Breach Triggers $89M Bitcoin Movement
A security incident involving Coldcard's Bitcoin wallet has caused significant market movement and distorted on-chain signals. On July 30, Coinkite warned users that wallets generated with affected Coldcard firmware could be drained due to a software error that produced seed phrases with less randomness than intended.
The breach resulted in three suspected attack waves targeting 4,585 addresses and draining 1,367.05 BTC, worth approximately $89 million. The Bitcoin associated with the attacks remains in attacker-controlled addresses, according to Alex Thorn from Galaxy Digital's head of firmwide research.
The incident has pushed potentially exposed users to move their Bitcoin before attackers reach it, causing an unusual surge in activity among smaller holders and long-dormant coins. Transactions involving outputs of less than 1 BTC reached 39,600 BTC on July 31, the largest daily total for this cohort since November 2022.
CryptoQuant research head Julio Moreno noted that the increase was concentrated among sending addresses, while receiving addresses rose by a much smaller proportion. This suggests holders were moving funds out of existing wallets as a precaution. Exchange deposits involving transfers below 10 BTC climbed to 7,300 BTC, their highest level since February 6.
Meanwhile, broader market sentiment deteriorated sharply amid the heightened network activity. Blockchain analytics firm Santiment reported that Bitcoin's ratio of positive to negative commentary fell to its lowest level since modern social tracking began.