Bitcoin users moved 39,600 BTC in sub-1 BTC transfers as the Coldcard hack continued, the largest such movement since FTX, CryptoQuant data shows.
"Attack activity remains active," CryptoQuant researchers said on X, flagging the spike in small-value transfers as users rushed to migrate funds from vulnerable Coldcard devices.
The 39,600 BTC figure — roughly $2.5 billion at current prices — represents the biggest volume of sub-1 BTC transactions since the FTX collapse in November 2022, according to CryptoQuant. Bitcoin traded at $63,064 as of 18:00 UTC on Aug. 1, down 1.1 percent over 24 hours, with the migration adding to network congestion. Galaxy Research previously expanded its on-chain scope of the incident, identifying 1,196 affected addresses that lost 1,082.65 BTC, worth about $70.2 million at the time, in a 41-minute window on July 30 across blocks 960,183 to 960,191. Earlier preliminary analysis by AnchorWatch CEO Rob Hamilton had estimated 594.48 BTC, around $38 million, moved across 500 transactions in a tighter three-block window.
The Coldcard exploit stems from a firmware flaw dating to March 2021 that weakened the randomness used to generate recovery seeds on certain models. Coinkite released a hotfix to remove the software fallback path but warned the update does not protect seeds generated on vulnerable firmware. Co-founder Rodolfo Novak advised affected users to move funds to a new seed. Binance founder Changpeng Zhao weighed in Saturday, urging holders to split funds across multiple wallets. "Even hardware wallets can have bugs. Even old wallets with long history can have bugs," he said on X. "Nothing is 100%. Stay informed. Stay SAFU!"
Galaxy Research noted the initial attack transactions shared a distinctive on-chain fingerprint — identical 30 satoshis per virtual byte fees and no change outputs — but cautioned that future sweeps may not preserve the same pattern. The divergence between the AnchorWatch and Galaxy Research estimates shows the challenge of determining full scope in self-custody incidents, where attackers reuse similar logic across multiple transactions and destinations. With the attack still active, affected users who generated seeds on vulnerable firmware should prioritize migrating remaining balances to newly generated seeds on patched devices. The incident has renewed debate over the limits of self-custody, with hardware wallets long considered among the strongest options for securing Bitcoin offline.
This article is for informational purposes only and does not constitute investment advice.