Coldcard’s $89M wallet bug triggers the biggest Bitcoin movement since FTX and completely distorts market signals

fiverr
Oluwapelumi Adejumo
fiverr


Coldcard’s wallet crisis has shaken Bitcoin sentiment, blurred on-chain signals and exposed a recurring weakness in AI-assisted cyber defenses.

On July 30, hardware maker Coinkite warned users that wallets generated with affected Coldcard firmware could be drained because a software error produced seed phrases with far less randomness than intended.

This security incident, Galaxy Research said, resulted in three suspected attack waves that targeted 4,585 addresses and drained 1,367.05 BTC, worth about $89 million.

Coldcard Bitcoin Wallet Hack
Coldcard Bitcoin Wallet Hack (Source: Galaxy Research)

The Bitcoin associated with the three identified waves remains in attacker-controlled addresses, according to Alex Thorn, Galaxy Digital’s head of firmwide research.

okex

However, he said smaller opportunistic thefts were already moving through peel chains, cross-chain services and offshore casinos.

Coldcard migrations blur Bitcoin’s bearish signals

This escalating threat has pushed potentially exposed users to move their Bitcoin before attackers reach it.

Although Coinkite has released fixed firmware for affected models, existing affected seed phrases cannot be repaired through an update, leaving holders to generate new wallets and transfer their funds to secure addresses.

That migration has produced an unusual surge in activity among smaller holders and long-dormant coins.

CryptoQuant research head Julio Moreno said transactions involving outputs of less than 1 BTC reached 39,600 BTC on July 31. That was the largest daily total for the cohort since November 2022, when 39,900 BTC moved shortly after FTX collapsed.

Bitcoin’s daily active addresses also jumped from about 645,000 on July 30 to nearly 1 million the following day, their highest level since Dec. 10, 2024.

Bitcoin Daily Active AddressesBitcoin Daily Active Addresses
Bitcoin Daily Active Addresses (Source: CryptoQuant)

Moreno said the increase was concentrated among sending addresses, while receiving addresses rose by a much smaller proportion, suggesting holders were moving funds out of existing wallets as a precaution.

Exchange deposits involving transfers below 10 BTC climbed to 7,300 BTC, their highest level since Feb. 6. Some holders may have used exchanges as temporary destinations while creating replacement wallets, although the flows could also include investors preparing to sell.

Bitcoin Exchange DepositsBitcoin Exchange Deposits
Bitcoin Exchange Deposits Spiked After Coldcard Incident (Source: CryptoQuant)

CryptoQuant analyst JA Maartunn added that 77,402 BTC from older unspent-transaction-output bands had moved since the vulnerability became public.

However, Maartunn cautioned against treating the resulting movements as evidence of broad investor capitulation, saying the context pointed heavily toward users securing their wallets.

He stated:

“The Coldcard seed phrase issue may cause old coins to move as users secure their savings. That can distort LTH Supply Change, Coin Days Destroyed, Spent Output Age Bands and other related charts.”

Meanwhile, broader market sentiment deteriorated sharply amid the heightened network activity.

Blockchain analytics firm Santiment said Bitcoin’s ratio of positive to negative commentary fell to its lowest level since its modern social tracking began. The reading reached 0.58 bullish comments for every bearish one across X, Reddit, Telegram and other platforms.

Bitcoin Market Sentiment Turns BearishBitcoin Market Sentiment Turns Bearish
Bitcoin Market Sentiment Turns Bearish (Source: Santiment)

Santiment attributed the unusually severe reaction to the nature of the breach. The exploit struck cold storage, which many holders regarded as Bitcoin’s safest final line of defense after withdrawing their funds from exchanges and avoiding riskier crypto platforms.

US AI guardrails complicate Coldcard investigation

The same wallet movements that blurred Bitcoin’s market signals have increased the urgency of tracing stolen funds before they reach services where they can be converted or withdrawn.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re subscribed. Welcome aboard.

Galaxy Research has collected reports from victims, clustered suspected attacker addresses and shared its findings with law enforcement, compliance firms and other cyber investigators. Thorn said the firm had reported about 600 addresses believed to be holding Bitcoin stolen from vulnerable Coldcard wallets.

However, he said guardrails on US large language models hindered attempts to track the stolen assets and protect users, forcing investigators to turn to an open-source Chinese model.

Thorn has not identified the US models, disclosed the prompts they rejected, or explained what the alternative system contributed to the investigation.

His concerns nevertheless echo a recent problem encountered by Hugging Face during a live cyberattack.

The AI platform said its security team needed to analyze more than 17,000 recorded events after an autonomous agent compromised parts of its infrastructure. Investigators initially submitted attack commands, exploit payloads, and command-and-control artifacts to frontier models accessed through commercial application programming interfaces.

Those requests were blocked because the models’ safety systems could not distinguish the incident responders from attackers, Hugging Face said. The company instead conducted the forensic analysis with GLM 5.2, an open-weight model developed by China’s Z.ai and operated on its own infrastructure.

The model helped reconstruct the attack timeline, identify compromised credentials, extract indicators of compromise and separate genuine damage from decoy activity. Hugging Face said the AI-assisted investigation reduced work that could have taken days to a matter of hours.

The episode illustrates the asymmetry Thorn says investigators encountered during the Coldcard crisis.

Attackers can use unrestricted or modified systems without observing the safeguards imposed on commercial models. Defenders, meanwhile, may encounter refusals when submitting material that resembles malicious activity, even when their purpose is to contain an active incident.

Broadly removing those restrictions would create a separate risk. Model providers cannot grant elevated capabilities whenever someone claims to be investigating a theft, particularly when the same tools could support wallet attacks, money laundering or attempts to evade transaction-monitoring systems.

That distinction becomes especially urgent in crypto because stolen assets can pass through bridges, exchanges and gambling platforms within minutes. Delays can allow funds to leave services capable of freezing them before victims obtain police reports or investigators complete manual tracing.



Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*