Smaller Bitcoin Holders Flee as Coldcard Flaw Exposes Self-Custody Risks
A recent surge in smaller Bitcoin transfers has brought activity to levels not seen since FTX's collapse. The movement, which saw sub-1 BTC transfers reach a total of 39,600 BTC on Friday, was largely driven by defensive actions taken by users amid concerns over Coldcard's firmware flaw. This weakness allowed attackers to drain funds from affected wallets, with Galaxy Research identifying three suspected attack waves that removed a combined 1,367 BTC.
The affected addresses were linked to several Coldcard models, including the Mk2 and Mk3, which generated seeds with insufficient entropy due to a random-number-generator integration error. Coinkite released corrected firmware for every affected model and release track, advising users to generate fresh seeds after installing the updated versions.
The incident has reignited debates over self-custody risks and the merits of using exchange-traded funds (ETFs). Casa's CEO Nick Neuman argued that distributed ownership gave users time to react, estimating that self-custody protected roughly ten times more Bitcoin than attackers stole. However, others have highlighted the limitations of self-custody and the need for stronger safeguards.