Coldcard Wallets Exposed to $89M Theft, Sparking Largest On-Chain Migration Since FTX
A security vulnerability in Coldcard wallets has led to an estimated $89 million theft and triggered the largest on-chain migration since the FTX collapse. According to Galaxy Research, three waves of attacks targeted 4,585 addresses, with 1,367.05 BTC stolen. The funds remain in the attackers' control, but some have been laundered through peel chains, cross-chain services, and offshore casinos.
Coldcard's firmware issue has exposed shortcomings in AI-assisted network defense systems. Coinkite issued a risk warning for users whose wallets were generated by specific versions of Coldcard firmware, as the software bug compromised mnemonic phrases' randomness. The incident has prompted users to migrate their assets to prevent theft, causing an abnormal surge in on-chain activity.
CryptoQuant's Julio Moreno noted that on July 31, transactions with outputs under 1 BTC reached 39,600 BTC, the highest single-day figure since the FTX collapse. Daily active Bitcoin addresses surged from approximately 645,000 to nearly 1 million, indicating users were transferring funds for risk-avoidance purposes.
The Coldcard mnemonic issue has distorted on-chain reference metrics, including changes in long-term holder supply and coin days destroyed. Santiment observed that the ratio of bullish to bearish Bitcoin comments has fallen to its lowest level since tracking began, indicating a sharp decline in market sentiment.